CVE-2026-8037
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
Critical vulnerabilities, curated daily for security professionals
Yesterday's disclosures centered on unauthenticated remote code execution and authentication bypass flaws in WordPress commerce plugins, Joomla extensions, and enterprise infrastructure from Red Hat and Microsoft. The brief covers 31 critical CVEs (up 29% from the prior day) and 42 high-priority CVEs (down 52%), for 73 total. CVE-2026-15413 in Link Factory and CVE-2026-73299 in Microsoft Prompty both carry CVSS 10, while CVE-2026-73263 in prowler-cloud prowler and CVE-2026-72526 in Red Hat Advanced Cluster Management for Kubernetes score 9.9 and put cloud security tooling and container orchestration at risk. WordPress plugin flaws dominate the critical set, with CVE-2026-18391 (WooCommerce Subscriptions), CVE-2026-16051 (WPMU DEV wpmudev-updates), and CVE-2026-18366 (Events Manager) all at CVSS 9.8, exposing e-commerce and membership sites to pre-authentication compromise. Four CVEs have confirmed active exploitation, including Progress LoadMaster, Cisco Secure Firewall ASA and FTD, Metabase, and the Windows Ancillary Function Driver for WinSock. Vendor patch data was unavailable for this set at publication, so verify fixed versions directly with each vendor and prioritize internet-facing systems.
Immediate action: Prioritize the actively exploited set first: Progress LoadMaster, Cisco Secure Firewall ASA and FTD, Metabase, and the Windows Ancillary Function Driver for WinSock, all internet-facing or privilege-escalation paths. Next, audit WordPress and Joomla installations for the affected plugins and extensions, and review Red Hat Advanced Cluster Management and prowler deployments. Patch availability is reported at 0% for this batch, so confirm fixed versions with each vendor and apply available mitigations or access restrictions in the interim.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
Cisco Secure Firewall ASA and FTD contain a heap inspection vulnerability due to improper memory clearing, which is currently being exploited in the wild.
Metabase contains a critical SQL injection vulnerability in the password reset endpoint that allows unauthenticated remote attackers to gain full administrative control over the instance.
A use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock is currently being exploited in the wild.
The WooCommerce Subscriptions plugin is vulnerable to PHP Object Injection due to insecure unserialization of user input, enabling unauthenticated remote code execution.
The giftware WordPress plugin contains an unrestricted file upload vulnerability, allowing unauthenticated users to upload malicious files and execute arbitrary code.
Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configu
Prowler is vulnerable to OS command injection via the Kubernetes provider connection test, allowing authenticated users to execute arbitrary commands on the worker.
The wpmudev-updates WordPress plugin fails to verify the integrity of installed packages and lacks replay protection, enabling unauthenticated remote code execution via valid signed requests.
The Link Factory WordPress plugin is a malicious backdoor that exposes a hardcoded REST API, allowing unauthorized operators to interact with the site using a specific Ed25519 signature.
WolfStack contains a hard-coded authentication secret, allowing unauthenticated remote attackers to bypass authentication and execute arbitrary commands as root inside containers.
A flaw in the multicloud-integrations component allows authenticated tenants to perform arbitrary code execution or privilege escalation on managed clusters via improper annotation validation.
Microsoft Prompty is vulnerable to code injection due to improper template evaluation, allowing unauthenticated attackers to execute arbitrary JavaScript in the host Node.js process.
The Events Manager WordPress plugin fails to properly scope capability checks, allowing unauthenticated users to perform privileged account actions if their ID matches a post ID.
The MongoDB BI Connector ODBC Driver is susceptible to a buffer overflow during metadata retrieval, which may lead to process termination or arbitrary code execution.
The Fabrik extension for Joomla contains an unauthenticated remote code execution vulnerability within its frontend listfilter model.
UpSnap is vulnerable to a missing authentication flaw that allows unauthenticated attackers to register an initial superuser account and subsequently execute arbitrary system commands.
IBM i versions 7.3 through 7.6 are affected by a stack-based buffer overflow vulnerability that allows remote, unauthenticated attackers to execute arbitrary code.
IBM i versions 7.3 through 7.6 contain an uncontrolled search path element vulnerability that allows authenticated attackers to execute arbitrary code.
IBM Db2 Mirror for i is susceptible to a remote OS command injection vulnerability, allowing unauthenticated attackers to execute arbitrary commands on the underlying system.
IBM i versions 7.3 through 7.6 are affected by an out-of-bounds write vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.
IBM DOORS Next contains an authentication bypass vulnerability, allowing an attacker to perform unauthorized activities within the system.
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations, potentially leading to unauthorized file access or overwriting.
A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system by providing a crafted image archive with a symlinked metadata file.
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system by providing a malicious archive with a symlinked backup configuration file.
An authorization bypass in Canonical LXD allows authenticated users to move instances into restricted projects while bypassing enforced configuration security controls during migration.
A time-of-check to time-of-use race condition in Canonical LXD allows authenticated users to bypass project security restrictions during cross-project instance copies.
ScadaLTS 2.7.8.1 contains an authorization bypass vulnerability that allows authenticated users with low privileges to execute arbitrary operating system commands as root.
An authorization bypass in Canonical LXD allows authenticated attackers to skip project security checks during cross-project migrations by masquerading as internal cluster notifications.
LXD fails to validate instance configurations during migration, allowing an authenticated attacker to bypass project-level security restrictions and escalate privileges.
Semaphore UI is vulnerable to OS command injection via improper handling of git_url parameters in the API, allowing authenticated project managers or owners to execute arbitrary commands.
A use-after-free vulnerability in the Linux kernel SCTP implementation, known as SCTPhantom, allows local privilege escalation and potential container escapes.
An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memor
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received and the retry then fails before cifs_send_recv() stores a re
Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access.
A use-after-free vulnerability exists in the V8 JavaScript engine of Google Chrome, which could allow a remote attacker to execute arbitrary code via a specially crafted webpage.
A use after free vulnerability in the HTML component of Google Chrome allows remote attackers to trigger memory corruption via a crafted web page.
A use after free vulnerability exists in the Blink rendering engine of Google Chrome, potentially allowing remote attackers to achieve arbitrary code execution.
The Pimcore Admin Classic Bundle contains a SQL injection vulnerability that allows authenticated users to execute arbitrary SQL commands via the backend interface.
Insufficient verification of data authenticity in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.
A Server-Side Request Forgery (SSRF) vulnerability in the Meeting Room Booking System (MRBS) allows unauthenticated attackers to send unauthorized requests to internal or external resources.
The KiviCare WordPress plugin is vulnerable to SQL injection, which may allow an authenticated attacker to execute arbitrary database queries.
Fortinet FortiWeb contains an improper authentication vulnerability that allows unauthenticated remote attackers to bypass security controls.
The archived Cloudflare pages-action repository contains a remote code execution vulnerability originating from improper neutralization of inputs in the src/index file.
A symlink following vulnerability in KubeVirt's virt-handler migration proxy allows an attacker with specific permissions to achieve full node compromise.
Zohocorp ManageEngine Password Manager Pro and PAM360 are vulnerable to an authenticated SQL injection flaw, which could allow an attacker to execute arbitrary SQL commands.
A cross-site scripting vulnerability in IBM i allows authenticated remote attackers to inject malicious scripts into web pages viewed by other users.
A stored cross-site scripting vulnerability exists in Cal.com Self-Hosted, allowing authenticated users to execute malicious scripts via the analytics tracking ID parameter.
An interpretation conflict and authorization flaw in the @cedar-policy/authorization-for-expressjs package allows authenticated users to bypass intended security controls.
IBM i Access Client Solutions contains a path traversal vulnerability that allows attackers to access restricted directories on the host system.
A stack-based buffer overflow in IBM Informix Dynamic Server allows remote, authenticated attackers to execute arbitrary code via an unchecked SQL interface length field.
IBM i 7 contains a privilege management vulnerability that could allow an authenticated user to gain elevated permissions on the system.
IBM i is susceptible to an OS Command Injection vulnerability, allowing an authenticated user to execute arbitrary commands on the underlying operating system.
IBM i contains an OS Command Injection vulnerability, which permits an authenticated user to execute arbitrary commands at the operating system level.
IBM i is affected by an OS Command Injection vulnerability, which allows an authenticated user to execute arbitrary commands on the host operating system.
IBM i 7 contains an OS command injection vulnerability, allowing an authenticated attacker to execute arbitrary system commands.
IBM i 7 contains a vulnerability involving execution with unnecessary privileges, which may allow an authenticated user to perform actions outside their intended authorization scope.
IBM i 7 contains a vulnerability involving execution with unnecessary privileges, potentially allowing authenticated users to perform unauthorized operations.
A vulnerability in JFrog Artifactory allows low-privileged users to poison cached artifact metadata, potentially causing consumers to retrieve untrusted content.
IBM i 7.3 through 7.6 contains an improper privilege management vulnerability that could allow an authenticated user to gain unauthorized elevated access.
Pingvin Share X contains authentication vulnerabilities involving incorrect implementation and missing critical steps in the authentication algorithm.
IBM i 7.3 through 7.6 is susceptible to OS command injection, which may allow an authenticated attacker to execute arbitrary system commands.
IBM i 7.3 through 7.6 contains an origin validation error that could allow an attacker to bypass security controls via a malicious request.
Semaphore UI contains a privilege management vulnerability that allows authenticated users to perform unauthorized actions.
Progress WhatsUp Gold contains multiple critical vulnerabilities, including missing authentication and server-side request forgery, allowing potential system compromise.
RustFS contains an improper privilege management vulnerability that could allow an authenticated attacker to perform unauthorized actions.
Vulnerability-Lookup is susceptible to an authentication bypass via a capture-replay attack during the account activation and password recovery processes.
The etcd distributed key-value store is vulnerable to a resource exhaustion attack due to improper limitation of resource allocation.
A use-after-free vulnerability in the Linux kernel KVM x86 shadow MMU allows local attackers to potentially trigger a guest-to-host escape and gain root privileges on the host system.
A race condition in the Linux kernel KVM nVMX code during nested virtualization allows a use-after-free scenario when freeing the shadow VMCS, potentially leading to host memory corruption.
A use-after-free vulnerability in the Linux kernel rhashtable implementation allows local attackers to trigger memory corruption or information disclosure by dereferencing stale pointers.
In the Linux kernel, the following vulnerability has been resolved: net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes Reject invalid `net.
In the Linux kernel, the following vulnerability has been resolved: 6lowpan: fix NHC entry use-after-free on error path lowpan_nhc_do_uncompression() looks up an NHC descriptor while holding lowpan_nhc_lock.
In the Linux kernel, the following vulnerability has been resolved: iio: event: Fix event FIFO reset race `iio_event_getfd()` creates the event file descriptor with `anon_inode_getfd()`, which allocates a new fd, creates the anonymous file and installs it in the process fd table before returning t.
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad_sigma_delta: fix CS held asserted and state leaks In ad_sigma_delta_single_conversion(), set_mode(AD_SD_MODE_IDLE) and disable_one() were called from the out: block while keep_cs_asserted was still true.
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async [Why&How] dc_process_dmub_aux_transfer_async() copies payload->length bytes into a 16-byte stack buffer (dpaux.
In the Linux kernel, the following vulnerability has been resolved: crypto: caam - use print_hex_dump_devel to guard key hex dumps Use print_hex_dump_devel() for dumping sensitive key material in *_setkey() to avoid leaking secrets at runtime when CONFIG_DYNAMIC_DEBUG is enabled.