Critical vulnerabilities, curated daily for security professionals
๐ฏ SSCV Profile
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Risk scores will be adjusted based on your selected environment
๐
Today's Security Brief
Thursday's brief is dominated by remote code execution flaws in infrastructure management and serverless platforms, led by Roxy-WI (CVE-2026-45552, CVE-2026-45558, CVE-2026-45556, all CVSS 9.9) and the Fission Kubernetes framework (CVE-2026-50545, CVE-2026-50563, CVE-2026-50564, CVSS 9.9). The disclosures include 12 critical CVEs, down 33% from the prior day's 18, alongside 37 high-priority CVEs, up 37% from 27. Enterprise software is also affected, with CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft PeopleTools and CVE-2026-20253 (CVSS 9.8) in Splunk Enterprise and Cloud Platform. The activity centers on unauthenticated code execution against management interfaces, WordPress plugins, and container orchestration components. Patch availability is currently 0% across this set, so affected operators should prioritize access restriction and compensating controls until vendor fixes ship.
Roxy-WI management interface affected by three CVSS 9.9 RCE flaws (CVE-2026-45552, CVE-2026-45558, CVE-2026-45556)
12 critical CVEs disclosed, down 33% from the prior day (18)
37 high-priority CVEs disclosed, up 37% from the prior day (27)
Patch availability stands at 0% for this set, affecting infrastructure management, serverless, and enterprise platforms
8 CVEs carry confirmed active exploitation, including flaws in Fortinet, Check Point, SolarWinds Serv-U, and Cisco SD-WAN
Immediate action: Prioritize Roxy-WI, Fission framework, Oracle PeopleSoft, and Splunk deployments, and restrict network access to these management and serverless interfaces immediately. With no patches yet available for the critical set, apply access controls, monitoring, and segmentation while tracking vendor advisories. Separately, the actively exploited Fortinet, Check Point, SolarWinds, Arista, and Cisco issues should be remediated where fixes exist.
๐ก Tip: Swipe CVE cards left to โญ star, right to โ remove
Section Navigation
โ ๏ธ
CISA Known Exploited Vulnerabilities
โ ๏ธ CISA KEVURGENT
CVE-2025-59718
9.8๐
FortinetFortiOS
โฐ Federal Deadline:December 22, 2025(-170 days remaining)
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
CVSS Base9.8
โ
CRSSelect profile
โ ๏ธ CISA KEVURGENT
CVE-2026-24858
9.8๐
FortinetFortiAnalyzer
โฐ Federal Deadline:January 29, 2026(-132 days remaining)
An authentication bypass vulnerability in various Fortinet products allows attackers to log into devices registered to other accounts if FortiCloud SSO is enabled.
CVSS Base9.8
โ
CRSSelect profile
โ ๏ธ CISA KEV
CVE-2026-50751
9.5๐
Check PointSecurity Gateway
โฐ Federal Deadline:June 10, 2026
Check Point Security Gateway is affected by an improper authentication vulnerability that is currently being exploited in the wild.
CVSS Base9.5
โ
CRSSelect profile
โ ๏ธ CISA KEV
CVE-2026-28318
9.5๐
SolarWindsServ-U
โฐ Federal Deadline:June 18, 2026(8 days remaining)
SolarWinds Serv-U is vulnerable to an uncontrolled resource consumption flaw allowing unauthenticated attackers to crash the service via specially crafted POST requests.
CVSS Base9.5
โ
CRSSelect profile
โ ๏ธ CISA KEV
CVE-2026-42271
9.5๐
LiteLLMLiteLLM
โฐ Federal Deadline:June 21, 2026(11 days remaining)
LiteLLM contains a command injection vulnerability in its MCP server test endpoints that, when chained with a host header bypass, enables unauthenticated remote code execution.
CVSS Base9.5
โ
CRSSelect profile
โ ๏ธ CISA KEV
CVE-2026-7473
9.5๐
AristaExtensible Operating System
โฐ Federal Deadline:June 22, 2026(12 days remaining)
Arista Extensible Operating System is affected by an incomplete comparison vulnerability, currently tracked in the CISA KEV catalog.
CVSS Base9.5
โ
CRSSelect profile
โ ๏ธ CISA KEV
CVE-2026-20245
9.5๐
CiscoCatalyst SD-WAN Manager
โฐ Federal Deadline:June 22, 2026(12 days remaining)
A command injection and privilege escalation vulnerability exists in the CLI of Cisco Catalyst SD-WAN Manager due to insufficient input validation.
CVSS Base9.5
โ
CRSSelect profile
โ ๏ธ CISA KEV
CVE-2026-11645
8.8๐
GoogleChrome
โฐ Federal Deadline:June 22, 2026(12 days remaining)
An out-of-bounds read and write vulnerability in the V8 JavaScript engine allows remote attackers to execute arbitrary code via a crafted HTML page.
CVSS Base8.8
โ
CRSSelect profile
๐จ
Critical Vulnerabilities
CVE-2026-45552
9.9๐
Roxy-WIRoxy-WI (Management Interface for Haproxy, Nginx, Apache, Keepalived)
Roxy-WI 8.2.6.4 and prior contains an authentication bypass vulnerability where multiple administrative endpoints lack proper role and group checks.
CVSS Base9.9
โ
CRSSelect profile
CVE-2026-45558
9.9๐
Roxy-WIRoxy-WI (Management Interface for Haproxy, Nginx, Apache, Keepalived)
Roxy-WI 8.2.6.4 and prior allows authenticated users to inject arbitrary HAProxy directives, leading to remote code execution on load balancers.
CVSS Base9.9
โ
CRSSelect profile
CVE-2026-45556
9.9๐
Roxy-WIRoxy-WI
Roxy-WI contains an authenticated arbitrary file write vulnerability in its WAF rule saving functionality, allowing for Remote Code Execution on managed load balancers.
CVSS Base9.9
โ
CRSSelect profile
CVE-2025-6254
9.8๐
DoctreatDoctreat Core Plugin for WordPress
The Doctreat Core plugin for WordPress contains an unauthenticated privilege escalation vulnerability allowing attackers to register as administrators.
CVSS Base9.8
โ
CRSSelect profile
CVE-2026-35273
9.8๐
OraclePeopleSoft Enterprise PeopleTools
An unauthenticated, easily exploitable vulnerability in the PeopleSoft Updates Environment Management component allows for complete system takeover via HTTP.
CVSS Base9.8
โ
CRSSelect profile
CVE-2026-20253
9.8๐
SplunkEnterprise and Cloud Platform
Splunk Enterprise and Cloud Platform contain an authentication bypass vulnerability in a PostgreSQL sidecar service, allowing unauthenticated users to create or truncate arbitrary files.
CVSS Base9.8
โ
CRSSelect profile
CVE-2026-46614
9.8๐
FissionFission Router
A route authorization bypass in the Fission router allows unauthorized callers to invoke functions by guessing their metadata, bypassing defined HTTPTrigger restrictions.
CVSS Base9.8
โ
CRSSelect profile
CVE-2026-50545
9.9๐
FissionFission Framework
A validation flaw in Fissionโs pod specification handling allows for the propagation of dangerous fields, leading to unauthorized control over generated pods.
CVSS Base9.9
โ
CRSSelect profile
CVE-2026-50563
9.9๐
FissionFission Framework
A privilege management flaw in Fissionโs Container Executor allows tenants to supply arbitrary pod specifications, creating potential for unauthorized privilege escalation.
CVSS Base9.9
โ
CRSSelect profile
CVE-2026-50564
9.9๐
FissionFission (Kubernetes Framework)
Fission prior to 1.24.0 contains a vulnerability in its Environment CRD that allows for privilege escalation by propagating insecure podspec fields without validation.
CVSS Base9.9
โ
CRSSelect profile
CVE-2026-50566
9.9๐
FissionFission Framework
An RBAC flaw in Fission allows tenants to run privileged containers under high-privilege service accounts, enabling container-sandbox escape and cluster-level compromise.
CVSS Base9.9
โ
CRSSelect profile
CVE-2026-46695
10๐
BoxliteBoxlite
Boxlite prior to 0.9.0 fails to restrict kernel capabilities, allowing malicious code to remount directories as read-write and perform arbitrary write operations.
CVSS Base10
โ
CRSSelect profile
โ ๏ธ
High Priority Updates
CVE-2026-52758
8.8๐
GhidraGhidra
A high-severity vulnerability exists in Ghidra versions prior to 12.0, potentially impacting the security of the database management component.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-4447
8.8๐
GoogleChrome
Google Chrome contains an inappropriate implementation in the V8 JavaScript engine that allows remote code execution via a crafted HTML page.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-11191
8.8๐
GoogleChrome
An out-of-bounds memory access vulnerability exists in the ANGLE graphics engine of Google Chrome, potentially allowing remote memory corruption.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-11272
8.8๐
GoogleChrome on iOS
Insufficient input validation in the Reading List feature of Google Chrome on iOS allows for privilege escalation via malicious UI gestures.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-28367
8.7๐
UndertowUndertow
A high-severity security flaw has been discovered in Undertow, a flexible performant web server used in many Java-based applications.
CVSS Base8.7
โ
CRSSelect profile
CVE-2026-46491
8.6๐
SimpleSAMLphpcasserver
A path traversal vulnerability in the SimpleSAMLphp-casserver allows attackers to read and potentially execute arbitrary code via malicious file-based ticket manipulation.
CVSS Base8.6
โ
CRSSelect profile
CVE-2026-3326
8.6๐
8ThemeXstore WordPress theme
The Xstore WordPress theme is vulnerable to an unauthenticated SQL injection via an AJAX action due to improper input sanitization.
CVSS Base8.6
โ
CRSSelect profile
CVE-2026-45564
8.8๐
Roxy-WIRoxy-WI
Roxy-WI versions 8.2.6.4 and prior contain an authentication bypass vulnerability triggered by specific URL patterns, potentially allowing unauthenticated access to the API.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-45549
8.5๐
Roxy-WIRoxy-WI
A critical authorization flaw in Roxy-WI allows authenticated users to execute unauthorized systemd operations, leading to potential privilege escalation.
CVSS Base8.5
โ
CRSSelect profile
CVE-2026-8071
8.8๐
CleanTalkAnti-Spam by CleanTalk plugin
The Anti-Spam by CleanTalk plugin for WordPress contains an undisclosed vulnerability with a CVSS score of 8.8.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-44693
8.8๐
Pi-holePi-hole FTL
Pi-hole FTL, the core engine of the Pi-hole network blocker, is affected by a high-severity vulnerability.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-49498
8.8๐
National Security Agency (NSA)Ghidra
Ghidra 11 is affected by a high-severity vulnerability related to superuser privilege handling.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-53435
8.8๐
JenkinsJenkins
Jenkins 2 is subject to a high-severity vulnerability involving the deserialization of arbitrary data.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-20251
8.8๐
SplunkSplunk Enterprise / Cloud / Secure Gateway
A remote code execution vulnerability in Splunk products arises from unsafe deserialization of data, allowing low-privileged users to execute arbitrary code.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-46612
8.8๐
FissionFission
Fission, a Kubernetes-native serverless framework, contains a vulnerability that requires immediate attention from users of the platform.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-42305
8.8๐
Jelmer Vernooij (Dulwich)Dulwich
Dulwich contains an arbitrary file write vulnerability via NTFS-hostile tree entries, enabling remote code execution when checking out malicious Git repositories.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-24187
8.8๐
NVIDIADisplay Driver for Linux
A use-after-free vulnerability in the NVIDIA Display Driver for Linux may allow a local attacker to cause a system crash or potentially execute arbitrary code.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-46166
8.8๐
LinuxKernel
A slab-use-after-free vulnerability exists in the Linux kernel's mac80211 subsystem during radar detection work.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-46174
8.8๐
AMDZen2 Kernel
A flaw in the AMD Zen2 op cache management allows for improper resource sharing, which may lead to instruction corruption.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-46198
8.8๐
LinuxKernel
An integer overflow in the Linux kernel's batman-adv component can lead to out-of-bounds memory access.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-46212
8.8๐
Linuxkernel
A use-after-free vulnerability exists in the Linux kernel's batman-adv module during the deletion of backbone claims.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-46238
8.8๐
Linuxkernel
The Linux kernel's batman-adv module is vulnerable to an issue involving the incorrect caching of unowned originator pointers in BAT IV.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-36723
8.8๐
BookcarsBookcars
An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows for directory traversal and potential arbitrary file manipulation.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-1784
8.8๐
Red HatOpenShift Container Platform
A vulnerability in the OpenShift Route resource allows low-privileged users to inject malicious HAProxy configurations, potentially leading to cross-tenant traffic hijacking.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-21837
8.8๐
HCLDigital Experience
HCL Digital Experience is affected by an OS command injection vulnerability within its Digital Asset Management API.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-52751
8.8๐
National Security Agency (NSA)Ghidra
Ghidra versions prior to 12 are affected by a security vulnerability requiring immediate attention.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-52754
8.8๐
National Security Agency (NSA)Ghidra
Ghidra versions prior to 12 are affected by a security vulnerability requiring immediate attention.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-6893
8.8๐
Red Hatdracut
A command injection vulnerability in dracut's legacy DHCP path allows remote attackers on an adjacent network to execute code as root within the initramfs.
CVSS Base8.8
โ
CRSSelect profile
CVE-2020-18171
8.8๐๐ Late Disclosure
TechSmithSnagit
TechSmith Snagit 19 is affected by a security vulnerability that has been subject to late disclosure.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-46444
8.8๐
FlowiseFlowise
Flowise versions prior to 3.1.2 lack authentication middleware on CRUD endpoints for OpenAI Assistants Vector Store, enabling unauthorized data modification.
CVSS Base8.8
โ
CRSSelect profile
CVE-2026-41031
8.7๐
VinnaProcess Monitor
A stored cross-site scripting (XSS) vulnerability in Vinna Process Monitor allows authenticated attackers to inject malicious scripts, potentially compromising session credentials.
CVSS Base8.7
โ
CRSSelect profile
CVE-2026-28368
8.7๐
Red HatUndertow
A technical flaw in the Undertow web server component could allow for remote exploitation, potentially impacting application stability and security.
CVSS Base8.7
โ
CRSSelect profile
CVE-2026-28369
8.7๐
Red HatUndertow (JBoss EAP / Apache Camel / Data Grid / Fuse / Process Automation / SSO)
A request smuggling vulnerability in Red Hat Undertow allows attackers to bypass authentication and access restricted information by exploiting inconsistent HTTP header processing.
CVSS Base8.7
โ
CRSSelect profile
CVE-2026-47906
8.6๐
AdobeDreamweaver
Adobe Dreamweaver contains a vulnerability in a third-party component that could allow arbitrary code execution if a user opens a malicious file.
CVSS Base8.6
โ
CRSSelect profile
CVE-2026-50131
8.6๐
FedifyFedify (TypeScript library)
A Server-Side Request Forgery (SSRF) vulnerability in the Fedify TypeScript library allows attackers to bypass IP validation and interact with internal or restricted network resources.
CVSS Base8.6
โ
CRSSelect profile
CVE-2026-40999
8.6๐
SpringSpring WS
Spring WS is vulnerable to Server-Side Request Forgery (SSRF) when processing WS-Addressing headers, allowing attackers to force outbound connections to arbitrary destinations.
CVSS Base8.6
โ
CRSSelect profile
CVE-2026-46273
8.6๐
IBMLinux kernel ibmveth driver
A denial-of-service vulnerability in the Linux kernel ibmveth driver on IBM Power systems can cause network traffic to halt due to improper GSO handling.