CVE-2026-84869
A missing authorization flaw in the ScreenConnect client allows unauthorized file transfer and execution during active remote sessions.
Critical vulnerabilities, curated daily for security professionals
Cisco accounts for the largest share of yesterday's critical disclosures, with Identity Services Engine, Secure Firewall Management Center, and Adaptive Security Appliance software all affected. The day brought 19 critical CVEs (down 70 percent from the prior day's 64) and 87 high-priority CVEs (up 47 percent from 59), for 106 total. CVE-2026-20130 and CVE-2026-20192 both score CVSS 10 in Cisco Identity Services Engine Software, CVE-2026-70416 scores CVSS 10 in Dell ObjectScale, and CVE-2026-20242 scores CVSS 9.8 in Cisco Secure Firewall Management Center. The pattern favors pre-authentication flaws in network access control, firewall management, and storage platforms, alongside web application issues in uvdesk community-skeleton and a WordPress file upload plugin, and eight CVEs carry confirmed active exploitation including CVE-2026-76460 in Cisco ISE. Inventory Cisco ISE, FMC, and ASA deployments first, restrict management interface access to trusted administrative networks, and verify fix status for each affected product in the vendor's own advisory.
Immediate action: Prioritize Cisco Identity Services Engine, Secure Firewall Management Center, and ASA Software, then Dell ObjectScale, JFrog Artifactory, and ConnectWise ScreenConnect where active exploitation is confirmed. Limit exposure of administrative and management interfaces to trusted networks while you work through the list. Confirm the fixed release and any interim mitigations in each vendor's own advisory before scheduling maintenance.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A missing authorization flaw in the ScreenConnect client allows unauthorized file transfer and execution during active remote sessions.
An unauthenticated path traversal vulnerability in the GitLab repository commits API allows remote attackers to read arbitrary files from the server.
A critical SQL injection vulnerability in Cisco Secure Email Gateway allows unauthenticated remote attackers to execute arbitrary commands with root privileges via crafted email messages.
A logic error in the Google Pixel cellular modem component allows for unauthenticated, adjacent privilege escalation without user interaction.
Acronis Backup plugins for cPanel and Plesk contain an insecure file permissions vulnerability that allows authenticated users to perform local privilege escalation.
An authentication bypass vulnerability in the Cisco Identity Services Engine API allows unauthenticated, remote attackers to gain unauthorized access to the management interface.
An incorrect authorization vulnerability in JFrog Artifactory allows authenticated attackers to perform unauthorized actions, potentially leading to data compromise.
An improper authentication vulnerability in JFrog Artifactory allows unauthenticated users to obtain an internal token, potentially exposing sensitive resources even when anonymous access is disabled.
Cisco Identity Services Engine (ISE) is vulnerable to remote command execution via insecure Java deserialization, allowing authenticated attackers to achieve root-level system access.
Cisco Secure Firewall Management Center is vulnerable to unauthenticated remote code execution via insecure deserialization of Java byte streams in the External Database Access feature.
Cisco Identity Services Engine (ISE) and ISE-PIC are vulnerable to injection attacks due to improper neutralization of special elements, potentially allowing for remote code execution.
Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector contain improper access control vulnerabilities discovered during internal security reviews.
Cisco Identity Services Engine (ISE) and ISE-PIC contain a vulnerability involving insufficiently protected credentials, categorized under CWE-522.
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads via the move_file function due to insufficient validation, potentially allowing remote code execution.
Dell ObjectScale versions prior to 4.4.0.0 are vulnerable to deserialization of untrusted data, allowing unauthenticated remote attackers to execute arbitrary code.
UVdesk Community Skeleton fails to authenticate wizard endpoints in the ConfigureHelpdesk controller, allowing unauthenticated attackers to create super administrator accounts and take full control.
An authentication bypass vulnerability in the Cisco ISE REST API allows unauthenticated remote attackers to gain full administrative access to the device by sending crafted HTTP requests.
Cisco Secure Firewall products contain an improper access control vulnerability (CWE-284) discovered during an internal security review, potentially allowing unauthorized system-level operations.
A flaw in the sftunnel protocol of Cisco Secure Firewall Management Center allows an authenticated remote attacker to write arbitrary files and execute commands as root.
Cisco Secure Firewall products contain vulnerabilities related to the improper handling of exceptional conditions, potentially allowing authenticated attackers to compromise the system.
Cisco Secure Firewall components contain improper neutralization vulnerabilities that were identified during an internal security review.
Cisco Nexus Dashboard contains an improper access control vulnerability that could allow an authenticated remote attacker to gain unauthorized access to system resources.
Cisco Nexus Dashboard contains a command injection vulnerability (CWE-77) that allows authenticated users to execute arbitrary commands on the underlying system.
An unauthenticated SSRF vulnerability in the UnifiedLogin service allows attackers to access internal services, retrieve credentials, and gain administrative control of the Altium Enterprise Server.
A critical code injection vulnerability in Arista EOS allows an unauthenticated attacker to execute arbitrary code via the gRPC Network Packet Sampling Interface (gNPSI), leading to full system control.
An unauthenticated remote attacker can achieve arbitrary code execution on Arista EOS switches by sending a malicious packet to the P4Runtime interface.
Feast fails to verify JWT token signatures before establishing user identity, allowing unauthenticated attackers to bypass role-based access control and gain full read and write access.
Craft CMS versions 5.10.0 through 5.10.12 are vulnerable to server-side template injection and arbitrary PHP code execution via an incomplete patch for a previous security issue.
Cisco Secure FMC contains a SQL injection vulnerability in its web interface, allowing an authenticated attacker with administrative-level roles to execute arbitrary database queries.
A tenant boundary authorization bypass in TinaCMS allows attackers to perform unauthorized content and media operations by supplying a malicious clientID.
A memory management flaw in the Linux kernel nouveau driver causes an IOMMU/IOVA mapping leak, potentially leading to system instability or unauthorized memory access.
Scada-LTS 2.8.1 contains a remote code execution vulnerability in the DataSourceEditDwr class, allowing authenticated users to bypass scripting sandbox protections via the validateScript method.
A buffer overflow vulnerability exists in the Linux kernel hid-rmi driver due to improper validation of report descriptor sizes, allowing for potential out of bounds memory access.
A use after free vulnerability in the Google Chrome Input component allows a remote attacker to execute arbitrary code via a crafted HTML page.
A use after free vulnerability in the PDF component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
A use after free vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
The CloneSite plugin in AVideo through 29.0 is vulnerable to stored OS command injection via unescaped SSH password fields, allowing remote attackers to execute arbitrary shell commands.
A buffer overflow vulnerability exists in the Linux kernel staging driver rtl8723bs due to insufficient validation of wireless management frame attributes, allowing potential code execution.
An out of bounds write vulnerability in the Google Chrome ServiceWorker component allows a remote attacker to execute arbitrary code within the browser sandbox via a crafted HTML page.
A type confusion vulnerability in the ServiceWorker component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
The Contest Gallery plugin for WordPress is vulnerable to an arbitrary file overwrite due to insufficient validation of the baseUrlForFacebook parameter, potentially allowing remote code execution.
Craft CMS allows authenticated users to execute arbitrary operating system commands via an improper HMAC signature validation in the license-shun and redirect parameters.
Coze Studio versions up to 0.5.1 fail to validate workspace boundaries for table names in workflow SQL nodes, allowing authenticated users to perform cross-tenant database operations.
Manticore Search fails to validate permissions for subsequent statements in multi-statement SQL requests, allowing authenticated users to bypass authorization and access sensitive internal tables.
A deserialization vulnerability in Cisco Secure Firewall Management Center allows an authenticated remote attacker to execute arbitrary commands with root privileges.
HP Advance software is vulnerable to elevation of privilege, remote code execution, and arbitrary file write, potentially compromising the host server.
A vulnerability in the Avast sandbox minifilter driver allows local, low-privileged attackers to escape isolation and escalate privileges to SYSTEM by manipulating virtualized file security descriptors.
The Jenkins Robot Framework Plugin fails to validate archive directory paths, enabling authenticated attackers to perform arbitrary file writes and achieve remote code execution on the controller.
A memory corruption vulnerability in the Linux kernel LoongArch KVM implementation allows local attackers to trigger out of bounds memory access via unvalidated MSI data.
A use-after-free vulnerability exists in the Linux kernel HID sony driver due to improper cleanup of the device list during probe failures.
A use-after-free vulnerability exists in the Linux kernel vfio/pci driver due to improper memory handling during initialization failures, potentially allowing local privilege escalation.
Cisco Secure Firewall products contain an incorrect comparison vulnerability that may allow an authenticated remote attacker to compromise system integrity and availability.
Cisco Secure Firewall software contains vulnerabilities related to improper control of resources through their lifecycle, which may allow for unauthorized system impact.
The zlt2000 microservices-platform contains a missing authorization vulnerability where the default configuration disables permission checks, allowing authenticated users to access administrative APIs.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A race condition in the Linux kernel ring buffer allows local attackers to potentially achieve arbitrary memory access through improper synchronization during sub-buffer resizing operations.
Cisco Nexus Dashboard contains multiple SQL injection vulnerabilities due to improper neutralization of special elements in SQL commands, potentially allowing unauthorized database manipulation.
Disclosed Sep 13; held until the analysis firmed up on Sep 17.
The SAMO Forms WordPress plugin through 1.0.0 contains multiple SQL injection vulnerabilities in unauthenticated actions due to insufficient input sanitization.
A numeric conversion error in the RabbitMQ amqp091-go client allows a malicious broker to trigger a runtime panic, resulting in a denial of service of the client process.
A sandbox bypass vulnerability in the Jenkins Script Security Plugin allows authenticated users to execute arbitrary code within the Jenkins controller JVM.
A race condition in the Linux kernel DRM amdkfd driver allows for improper TLB invalidation, potentially leading to memory corruption or GPU queue hangs during SVM page migration.
WebVirtCloud contains a missing authorization vulnerability where read-only users can perform privileged actions on virtual machines due to improper permission validation in the get_instance gate.
The TechDocs plugin in Backstage fails to validate mkdocs.yml files, allowing authenticated users to trigger code execution within the documentation generator environment.
Pelican Panel versions before 1.0.0-beta35 contain an authorization bypass vulnerability allowing authenticated users with read-only permissions to execute arbitrary commands within the container.
KnowStreaming versions through 3.4.1 fail to enforce role-based access control on REST API endpoints, allowing authenticated users to perform unauthorized administrative actions.
A missing authentication vulnerability in the Advantech EKI-1242 series allows unauthenticated remote attackers to execute critical management functions via TCP port 5058.
Tanium Asset contains a SQL injection vulnerability that allows authenticated users to execute unauthorized database commands.
Tanium Threat Response contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands.
A SQL injection vulnerability in the OpenMeter meters API allows unauthenticated remote attackers to manipulate metering data or cause a denial of service.
The djust framework for Django is vulnerable to unsafe module importation via unauthenticated WebSocket frames, allowing remote attackers to trigger arbitrary Python module execution.
BC Security Empire before 6.7.1 is vulnerable to path traversal during file uploads, allowing authenticated operators to write files to arbitrary locations on the C2 server for code execution.
The cc-connect application fails to enforce per-user allowlist filtering in the onCardAction handler, allowing authenticated attackers to bypass access controls and dispatch unauthorized commands.
SIMAC MyPHR 1.1 contains an IDOR vulnerability allowing authenticated users to access arbitrary employee records and perform account takeovers by manipulating resource identifiers in API requests.
A path traversal and link following vulnerability in oras-go allows unauthenticated attackers to overwrite arbitrary files and potentially achieve remote code execution during artifact extraction.
A race condition exists in the Linux kernel qla2xxx scsi driver, where improper locking during host map updates can lead to btree corruption.
A wild pointer dereference vulnerability exists in the Linux kernel qla2xxx driver, potentially leading to system crashes or arbitrary code execution via crafted firmware responses.
A race condition in the Linux kernel qla2xxx SCSI driver allows for workqueue list corruption, potentially leading to system crashes or denial of service.
A buffer overflow vulnerability exists in the Linux kernel media subsystem within the Extron DA HD 4K Plus driver due to insufficient input validation of malformed data.
A memory management flaw in the Linux kernel KVM subsystem on LoongArch allows local authenticated users to trigger improper memory mapping, potentially leading to unauthorized host memory access.
A race condition in the Linux kernel KVM arm64 vgic-v3 subsystem allows local attackers to trigger a use-after-free, potentially leading to privilege escalation or system instability.
A use-after-free vulnerability in the Linux kernel KVM subsystem allows local users to potentially trigger memory corruption during lockless rmap walks.
A flaw in the Linux kernel KVM subsystem allows for improper TLB invalidation during nested virtualization, potentially leading to unauthorized data access or integrity compromise between virtual machines.
A flaw in the Linux kernel KVM subsystem allows for potential stale TLB entry usage due to improper VPID flushing during nested VMX transitions.
A use-after-free vulnerability exists in the Linux kernel batman-adv component due to improper handling of stale receive device metadata during fragment reassembly.
A logic error in the Linux kernel s390 vfio-ap driver causes hot-unplug events to be skipped, potentially allowing a guest to retain unauthorized access to removed hardware.
A logic error in the Linux kernel s390 vfio-ap driver fails to properly remove control domains during mdev configuration, allowing stale domains to persist in KVM guests.
A use-after-free vulnerability in the Linux kernel s390 vfio-ap driver allows a local attacker with low privileges to potentially trigger memory corruption and achieve system compromise.
A memory management flaw in the Linux kernel dma-direct subsystem allows for improper allocation handling, potentially leading to memory corruption or system instability.
A Use-After-Free vulnerability in the Linux kernel Bluetooth SCO implementation allows potential local or adjacent attackers to trigger memory corruption and system instability.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel interconnect framework allows local attackers to trigger memory corruption and potentially achieve system compromise.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
An out-of-bounds write vulnerability in the Linux kernel AppArmor component allows an authenticated local user to potentially achieve memory corruption.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability exists in the Linux kernel Smack security module, specifically within the smack_file_send_sigiotask function, due to incorrect credential handling.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A vulnerability in the Linux kernel sysctl implementation allows local authenticated users to modify global system variables by manipulating pid/user namespaces.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A buffer overflow vulnerability exists in the Linux kernel DS28E17 1-Wire to I2C bridge driver, allowing an attacker to trigger an out-of-bounds read via a crafted I2C block read length.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A buffer over-read vulnerability exists in the Linux kernel mt7996 Wi-Fi driver due to improper validation of EEPROM firmware file sizes.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A race condition in the Linux kernel mt7925 Wi-Fi driver allows a use-after-free scenario when a device is torn down before a scheduled multi-link power-save work item completes.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A stack corruption vulnerability in the mwifiex Wi-Fi driver allows local attackers to trigger kernel panics or potentially execute arbitrary code by interrupting synchronous command processing.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability exists in the Linux kernel wifi driver rtl8xxxu due to a race condition during device teardown, potentially allowing local attackers to execute arbitrary code.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A race condition in the Renesas I3C driver for the Linux kernel allows local attackers to trigger a use-after-free by accessing memory after a transfer timeout, potentially leading to system crashes.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free and information leak vulnerability exists in the Linux kernel I3C subsystem device unregister path, allowing local attackers to potentially compromise kernel memory.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A race condition in the I3C subsystem of the Linux kernel allows for an unlocked dereference of device descriptors, leading to potential memory corruption or system instability.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel dm-pcache driver allows for potential memory corruption during kset_replay operations.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A memory safety vulnerability in the Linux kernel dm-pcache component allows an attacker with CAP_SYS_ADMIN privileges to perform out-of-bounds reads.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A buffer handling flaw in the Linux kernel dm-pcache driver allows authenticated local users to trigger out-of-bounds memory access via maliciously crafted on-disk cache metadata.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A memory corruption vulnerability in the QNAP MCU driver allows a local, authenticated attacker to trigger stack corruption via late-arriving messages or command timeouts.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel net/smc subsystem allows a local attacker to trigger memory corruption or arbitrary code execution via race conditions in connection teardown.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A null pointer dereference vulnerability in the Linux kernel ravb network driver allows local attackers to potentially achieve code execution or system instability.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel Open vSwitch module allows local attackers to potentially crash the system or execute arbitrary code via a race condition during flow deletion.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel MCTP implementation allows local, unprivileged users to trigger memory corruption and potential system instability.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
An integer underflow in the Linux kernel TUN/TAP driver allows local attackers to cause memory corruption by triggering an oversized headroom request.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel SLIP driver allows local attackers to potentially achieve arbitrary code execution, privilege escalation, or system crashes.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A resource management flaw in the Linux kernel IPMI driver causes sysfs files to persist after registration failure, potentially leading to a use-after-free or system instability.
A resource exhaustion vulnerability in the RabbitMQ amqp091-go client allows a malicious broker to cause excessive CPU consumption and service stalling by advertising an invalidly small FrameMax value.
A memory allocation vulnerability in the RabbitMQ amqp091-go client allows a malicious broker to crash the client process via excessive memory requests.
Disclosed Sep 10; published with a limited analysis after repeated re-checks found no further public detail.
Docmost v0.21.0 contains a path traversal vulnerability in avatar attachments that allows unauthenticated attackers to disclose local files via a POST request.