CVE-2025-39964
A race condition in the Linux kernel crypto subsystem allows local users to cause state inconsistencies via concurrent writes to an af_alg socket.
Critical vulnerabilities, curated daily for security professionals
Wednesday's disclosures include three CVSS 10.0 vulnerabilities: CVE-2026-69399 in Microsoft Azure Arc, CVE-2026-86708 in Zohocorp ManageEngine Applications Manager, and CVE-2026-59167 in the JiHong88 SunEditor rich text editor. The brief tracks 27 critical CVEs (down 36% from 42 the prior day) and 85 high-priority CVEs (down 11% from 96). Other notable critical issues include CVE-2026-86248 (CVSS 9.8) in Apache Tomcat, CVE-2026-93352 (CVSS 9.8) in the Plank laravel-mediable package, and five separate CVSS 9.8 vulnerabilities in the Orval OpenAPI client generator (CVE-2026-96754 through CVE-2026-96759). The day's exposure spans hybrid cloud management, IT monitoring platforms, web servers, and open-source developer tooling, and 8 CVEs affecting the Linux kernel, F5 BIG-IP, Check Point Quantum, Arista VeloCloud Orchestrator, and Zyxel switches have confirmed active exploitation. Defenders should restrict network access to management interfaces such as Azure Arc, ManageEngine, BIG-IP, and Check Point management servers, and review the vendor advisory for each affected product to confirm fixed versions.
Immediate action: Prioritize Microsoft Azure Arc, Zohocorp ManageEngine Applications Manager, and Apache Tomcat, along with the actively exploited F5 BIG-IP, Check Point Quantum, and Linux kernel issues, and restrict exposure of their management interfaces until they are remediated. Confirm fix status and affected versions in each vendor's advisory, and audit projects that depend on Orval, SunEditor, or laravel-mediable for updated package releases.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A race condition in the Linux kernel crypto subsystem allows local users to cause state inconsistencies via concurrent writes to an af_alg socket.
A memory corruption vulnerability in the Linux kernel netfilter bridge component allows for out of bounds writes during ARP packet processing.
A vulnerability in the Linux kernel TLS implementation allows for improper handling of zero-length records during recvmsg processing, potentially leading to unauthorized system state manipulation.
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware allows potential remote command execution.
VeloCloud Orchestrator (VCO) on-prem is vulnerable to improper input validation, allowing unauthenticated remote attackers to access privileged functionality and compromise the host.
A heap-based buffer overflow in F5 BIG-IP APM, when configured as an OAuth Authorization Server, allows unauthenticated attackers to achieve remote code execution via malicious traffic.
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server.
An improper certificate trust validation vulnerability exists in Check Point Quantum Security Gateways during VPN negotiation, allowing unauthenticated remote code execution.
Apache Tomcat fails to properly enforce CLIENT_CERT authentication in certain configurations when soft fail is disabled, potentially allowing unauthorized access.
Laravel-Mediable contains an incomplete blocklist allowing .pht file uploads, which can lead to remote code execution on systems where Apache is configured to execute such files as PHP.
A code injection vulnerability in the orval @orval/hono generator allows attackers to execute arbitrary JavaScript by injecting apostrophes into OpenAPI path segments.
Orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability where attackers can inject arbitrary JavaScript expressions via crafted OpenAPI schema defaults.
Orval versions before 8.29.0 are vulnerable to code injection because they fail to escape media-type keys when generating Content-Type string literals in output code.
Orval contains a code injection vulnerability in its form-data serializer that fails to escape multipart property names, allowing attackers to execute arbitrary expressions.
Orval versions before 8.29.0 are vulnerable to code injection because the operationId parameter is not properly escaped when generating TanStack Query metadata objects.
Disclosed Sep 17; published with a limited analysis after repeated re-checks found no further public detail.
A critical elevation of privilege vulnerability in Microsoft Azure Arc allows unauthenticated remote attackers to compromise system confidentiality, integrity, and availability.
A stored cross-site scripting vulnerability in SunEditor versions prior to 2.47.11 allows unauthenticated attackers to execute malicious scripts via crafted HTML elements with event handlers.
ManageEngine Applications Manager installer contains a hardcoded Google Cloud service account private key, allowing unauthenticated attackers to compromise cloud resources.
The Paytium WordPress plugin allows unauthenticated attackers to perform privilege escalation by injecting unauthorized user roles during the payment flow, leading to full site administrator takeover.
Disclosed Sep 18; published with a limited analysis after repeated re-checks found no further public detail.
The Dictionary WordPress plugin through version 1.0 is vulnerable to stored Cross-Site Scripting (XSS) due to insufficient input validation, allowing unauthenticated attackers to execute arbitrary scripts.
OpenC3 COSMOS allows authenticated non-administrator users to perform code injection via malicious file uploads, leading to arbitrary code execution within multiple microservices.
A flaw in Red Hat Ansible Automation Platform allows remote attackers to bypass security controls, leading to privilege escalation and remote code execution on managed hosts.
ManageEngine OpManager contains an OS command injection vulnerability in the Notification Profile module, allowing remote code execution by an authenticated user.
IBM Concert versions 1.0.0 through 3.0.0 are vulnerable to OS command injection, allowing unauthenticated remote attackers to execute arbitrary code on the underlying system.
LightLLM versions through 1.2.0 contain a remote code execution vulnerability in the KV-transfer worker, which exposes an unauthenticated RPyC control channel susceptible to insecure deserialization.
A command injection vulnerability in the Red Hat Ansible Automation Platform allows authenticated users to execute arbitrary commands via the Project scm_url field.
D-Link DIR-825 is vulnerable to an out-of-bounds write via the peer_hostname argument in the rp-l2tp component, allowing remote unauthenticated attackers to potentially corrupt system memory.
An improper authentication vulnerability in Deltaww DIAEnergie allows remote, unauthenticated attackers to bypass authentication mechanisms.
IBM Concert versions 1.0.0 through 3.0.0 contain a buffer overflow vulnerability due to improper bounds checking, which could allow for arbitrary code execution.
A double free vulnerability in GitLab CI/CD configuration parsing allows authenticated users to execute arbitrary code on the server.
An integer overflow vulnerability in GitLab CI/CD configuration regex compilation allows authenticated users to achieve remote code execution.
A missing authorization flaw in the Ansible Automation Platform allows authenticated users to bypass instance group permission boundaries when copying workflow job templates.
IBM Concert versions 1.0.0 through 3.0.0 contain a use after free vulnerability that allows unauthenticated attackers to corrupt memory, crash the application, or execute arbitrary code.
A path traversal vulnerability in Flatpak allows unauthenticated attackers to write arbitrary files outside the intended directory when a developer uses a malicious SDK container.
A SQL injection vulnerability in the Moodle Socialwall plugin (v3.0-v3.3) allows unauthenticated attackers to execute arbitrary code via crafted HTTP requests.
The Import and export users and customers WordPress plugin is vulnerable to privilege escalation in versions up to 2.4.17 due to a CSV escape character mismatch during the import and export workflow.
A hardcoded configuration path vulnerability in the Apache Lounge Windows distribution of Apache HTTP Server allows for local code execution.
IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains an unauthenticated remote code execution vulnerability via unsafe Java native deserialization.
A format string vulnerability in Red Hat Ansible Automation Platform allows an authenticated administrator to exfiltrate sensitive secrets including Django keys and database passwords.
A remote code execution vulnerability exists in Microsoft Outlook that may allow an attacker to execute arbitrary code on the host system.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A memory safety vulnerability in the Linux kernel hp-bioscfg driver allows for out-of-bounds reads during ACPI package parsing, potentially leading to information disclosure or system instability.
OpenC3 COSMOS is vulnerable to OS command injection via the pypi_url setting, allowing authenticated users to execute arbitrary commands on the host system.
The Easy Store extension for Joomla contains a broken access control vulnerability in the ApiController, allowing authenticated backend users to edit records regardless of their assigned permissions.
A stored cross-site scripting vulnerability in Red Hat Ansible Automation Platform allows low-privileged users to execute arbitrary JavaScript in the sessions of higher-privileged users.
A denial of service vulnerability exists in the Moquette MQTT broker due to improper input validation of shared subscription filters, allowing remote unauthenticated attackers to crash session loops.
A recursion depth flaw in the Moquette MQTT broker allows unauthenticated remote attackers to trigger a StackOverflowError, resulting in a denial of service for connected clients.
The Moquette MQTT broker fails to enforce limits on pending message queues, allowing unauthenticated remote attackers to trigger a denial of service via memory and storage exhaustion.
The jet-form-builder-stripe-gateway WordPress plugin is vulnerable to unauthenticated SQL injection, allowing attackers to extract sensitive database information, including password hashes.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A memory overread vulnerability exists in the Linux kernel sensorhub ring handler, which can be triggered by a malfunctioning EC firmware to cause information disclosure or system instability.
Disclosed Sep 18; published with a limited analysis after repeated re-checks found no further public detail.
A sandbox bypass vulnerability in the Jenkins Script Security Plugin allows authenticated attackers to execute arbitrary code within the Jenkins controller JVM.
The YOP Poll WordPress plugin is vulnerable to an origin validation error that allows unauthenticated attackers to steal REST nonces and perform a full account takeover of an administrator.
A resource injection vulnerability in the Moquette MQTT broker allows message map collisions, leading to data corruption and unauthorized message exposure between sessions.
An uncaught exception in the Moquette MQTT broker allows unauthenticated attackers to cause a denial of service by terminating event loops and disrupting client session processing.
A missing authorization vulnerability in the Moquette MQTT broker allows unauthenticated attackers to inject unauthorized messages into restricted topics via malicious Last-Will configurations.
Disclosed Sep 18; published with a limited analysis after repeated re-checks found no further public detail.
The To Do List Member WordPress plugin versions 1.4 through 1.6 allow unauthenticated file uploads, enabling attackers to store malicious content and manipulate existing files.
A vulnerability in Klever-Go allows authenticated attackers to perform injection attacks against Elasticsearch via improper escaping of account names within the indexing process.
Disclosed Sep 18; published with a limited analysis after repeated re-checks found no further public detail.
Cisco Nexus Dashboard contains multiple vulnerabilities involving information exposure and insecure handling, categorized as CWE-200.
Disclosed Sep 18; published with a limited analysis after repeated re-checks found no further public detail.
Cisco Nexus Dashboard is affected by a path traversal vulnerability (CWE-22) that could allow an authenticated attacker to access or manipulate restricted files on the system.
Disclosed Sep 18; published with a limited analysis after repeated re-checks found no further public detail.
The Jenkins Script Security Plugin fails to properly intercept null receiver operations, allowing authenticated users to bypass sandbox protections and execute arbitrary code on the Jenkins controller.
Disclosed Sep 18; published with a limited analysis after repeated re-checks found no further public detail.
The Jenkins Script Security Plugin fails to block the @GroovyASTTransformationClass annotation, enabling authenticated attackers to bypass sandbox protections and execute arbitrary code on the controller.
Disclosed Sep 17 without a CVSS score; scored Sep 19, analysis completed Sep 23.
A privilege management vulnerability in the Choose User Role at Registration plugin allows unauthenticated users to register with unauthorized roles.
MLflow versions 2.1.0 to 3.14.0 are vulnerable to remote code execution due to improper deserialization of untrusted data in the statsmodel flavor.
MLflow versions 2.0 and later are vulnerable to remote code execution due to improper deserialization control in the dspy flavor when handling crafted MLmodel artifacts.
A SQL injection vulnerability in ZohoCorp ManageEngine Applications Manager allows authenticated users with low privileges to execute arbitrary SQL commands, leading to potential remote code execution.
ZohoCorp ManageEngine OpManager and Firewall Analyzer are affected by an SQL injection vulnerability in the Rule Management Search Reports feature, allowing potential database compromise.
The Reachy Mini daemon contains an unauthenticated API endpoint that allows remote attackers to install and execute arbitrary code on the robot.
IBM DataStage on Cloud Pak for Data is vulnerable to remote OS command injection, which allows an authenticated attacker to execute arbitrary code on the underlying system.
IBM DataStage on Cloud Pak for Data allows a remote authenticated attacker to access sensitive namespace-wide secrets through improperly configured file mounts.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, allowing an authenticated remote attacker to execute arbitrary commands on the underlying system.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection due to improper escaping of connector property values during OSH script generation.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, allowing remote authenticated attackers to execute arbitrary system commands.
A low-privileged user can obtain an administrator API key in ManageEngine Applications Manager, leading to a full authorization bypass and unauthorized administrative actions.
A command injection vulnerability in the Diagnose Settings feature of ManageEngine OpManager and Firewall Analyzer allows authenticated users to execute arbitrary system commands.
An untrusted search path vulnerability in the Plesk RESTful API extension allows authenticated remote users to execute arbitrary code with root privileges.
A broken access control vulnerability in InvoiceShelf multi-company installations allows authenticated owners to read or overwrite user accounts across different company tenants.
Brocade SANnav is vulnerable to unauthenticated remote command injection in its HTTP service, allowing network-adjacent attackers to execute arbitrary CLI commands and container management instructions.
A missing authorization flaw in the Formie plugin for Craft CMS allows authenticated attackers to perform server-side request forgery by manipulating integration settings.
A SQL injection vulnerability in Deltaww DIAEnergie allows authenticated attackers to execute arbitrary SQL commands.
A SQL injection vulnerability exists in Deltaww DIAEnergie software, allowing authenticated attackers to execute arbitrary SQL commands.
ZohoCorp ManageEngine OpManager contains an authentication bypass vulnerability within the Application Manager Plugin, allowing authenticated users to perform unauthorized actions.
The Easy Store extension for Joomla is vulnerable to an unauthenticated information disclosure flaw, allowing attackers to harvest sensitive customer PII via the checkout.searchGuestUser endpoint.
A SQL injection vulnerability in the Live Copy Paste for Elementor WordPress plugin allows authenticated contributors to execute malicious database queries.
The Mollie Forms WordPress plugin is vulnerable to SQL injection, allowing authenticated users with contributor privileges to execute unauthorized database queries.
A SQL injection vulnerability in the WP EasyCart WordPress plugin allows authenticated contributors to execute arbitrary database queries.
Nanomsg contains a heap-based buffer overflow in the WebSocket transport layer, triggered by an unchecked copy of the Sec-WebSocket-Version header, allowing for potential remote code execution.
A server-side template injection (SSTI) vulnerability in web.py version 0.76 allows authenticated attackers to bypass sandbox restrictions and achieve arbitrary code execution.
Frictionless-py contains an OS command injection vulnerability in the explore console command, allowing attackers to execute arbitrary commands via a malicious Data Package descriptor.
A path traversal vulnerability in Flatpak allows attackers to write files to arbitrary locations on a host filesystem during the extraction of extra data, potentially leading to root-level access.
Brocade SANnav before 3.0.1a contains an insecure access control flaw allowing local users to execute commands on connected Fabric OS switches with the privileges of the SANnav management user.
Brocade SANnav contains an OS command injection vulnerability in its CLI scripting component, allowing authenticated users to bypass restricted execution contexts and gain administrative switch access.
Mammoth.js before 1.12.2 is vulnerable to prototype pollution via crafted .docx files, potentially leading to local file disclosure in specific configurations.
Tauri's Content Security Policy (CSP) hardening fails to protect applications that include data: or blob: in their script-src directive, allowing for potential arbitrary script execution.
Klever-Go contains an unauthenticated WebSocket vulnerability allowing remote attackers to intercept sensitive log data and modify global logging configurations.
A missing authorization vulnerability in the CopyAPIView component of Red Hat Ansible Automation Platform allows authenticated users to bypass object level access controls.
Microweber Administration panel 2.0.19 contains an arbitrary file upload vulnerability that allows authenticated attackers to execute malicious code remotely.
Disclosed Sep 18; published with a limited analysis after repeated re-checks found no further public detail.
A stack-based buffer overflow vulnerability exists in various Qualcomm Snapdragon components due to improper memory handling when copying unverified data.
Disclosed Sep 18; published with a limited analysis after repeated re-checks found no further public detail.
Scada-LTS 2.8.1 is vulnerable to an authorization bypass where authenticated users can invoke restricted Direct Web Remoting (DWR) methods by manipulating POST body parameters.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A memory management flaw in the Linux kernel IOMMU dma allocation path allows local attackers to potentially trigger memory corruption due to improper validation of atomic pool allocation results.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A memory addressing vulnerability in the Linux kernel DAX subsystem allows for incorrect kernel virtual address calculation, potentially leading to memory corruption or system instability.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A heap out-of-bounds write vulnerability in the Linux kernel CXL subsystem allows a local user to trigger memory corruption via the FWCTL_RPC interface by providing an oversized feature count.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A buffer overflow vulnerability exists in the Linux kernel HFS+ filesystem implementation, allowing local attackers to potentially execute arbitrary code via a corrupted HFS+ image.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A reference counting vulnerability in the Linux kernel esp_ssg_unref function allows local attackers to trigger page underflows and memory corruption during AEAD operations.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A buffer overflow vulnerability in the Linux kernel USB gadget subsystem allows local users to trigger memory corruption via excessive sampling rates in UAC1 and UAC2 configfs attributes.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A flaw in the Linux kernel BPF subsystem allows local attackers to trigger out-of-bounds memory access due to improper handling of scalar IDs during sign-extending narrowing stack fills.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A use-after-free vulnerability exists in the Linux kernel BPF subsystem within bpf_find_vma, potentially allowing local attackers to achieve privilege escalation or system crashes.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A race condition in the Linux kernel BPF subsystem allows local users to potentially achieve unauthorized memory access due to improper synchronization during vmlinux BTF parsing.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A vulnerability in the Linux kernel eBPF subsystem allows unauthorized writes through untrusted BTF pointers, bypassing read-only memory protections.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A memory handling flaw in the Linux kernel s390 BPF subsystem allows potential data corruption or unauthorized access due to improper register clearing during 32-bit to 64-bit value loading.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
The Linux kernel BPF subsystem fails to properly enforce object bounds during BTF struct walks, allowing out-of-bounds memory access.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A reference counting flaw in the Linux kernel RDMA/irdma driver allows local users to trigger a use-after-free by deregistering memory regions associated with active hardware rings.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A race condition in the Linux kernel Xilinx DMA driver allows local users to trigger memory corruption or spurious transfers during interrupt handling.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A dangling pointer vulnerability exists in the Linux kernel amdgpu display driver, specifically within the CRTC reset function, which could lead to memory corruption and potential system instability.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A dangling pointer vulnerability in the Linux kernel v3d driver allows for potential memory corruption due to improper cleanup during a failed fence creation process.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
The Linux kernel libceph component fails to validate banner payload lengths in the messenger v2 protocol, allowing a zero-length read that triggers a kernel warning and potential service disruption.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A null pointer dereference in the Linux kernel NFSv4/pnfs implementation allows for potential denial of service via mismatched version caching.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A buffer exhaustion vulnerability in the Linux kernel NFSv4.2 implementation allows a malicious server to trigger a denial of service via memory corruption or kernel lockups.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A NULL pointer dereference vulnerability exists in the Linux kernel NFSv4/flexfiles implementation, which can be triggered by unauthenticated attackers during I/O operations to NFSv4.0 data servers.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A resource leak vulnerability exists in the Linux kernel nvmet-rdma driver, allowing unauthenticated attackers to trigger a denial of service via memory exhaustion during queue teardown.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A memory management flaw in the Linux kernel ASoC meson driver causes a use-after-free and double-free condition during failed memory reallocation, potentially leading to system instability or compromise.
Klever-Go contains an authorization bypass vulnerability in the KleverUpdateAccountPermission function that allows an authenticated attacker to perform unauthorized account permission changes.