CVE-2026-10520
A critical OS command injection vulnerability in Ivanti Sentry allows remote unauthenticated users to achieve root-level remote code execution.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Oracle products account for the bulk of Thursday's critical disclosures, spanning WebLogic Server, Coherence, Solaris, WebCenter Enterprise Capture, and the Fusion Middleware Identity Manager Connector. The day brought 48 critical CVEs (up from 2 the prior day) and 90 high-priority CVEs (up from 26), reflecting a large batch of enterprise platform disclosures. Notable entries include CVE-2026-35292 (CVSS 10) and CVE-2026-35301 (CVSS 10) in Oracle WebLogic Server, CVE-2026-46978 (CVSS 10) in Oracle Solaris, and CVE-2026-46794 (CVSS 9.9) in the Oracle Fusion Middleware Identity Manager Connector. WordPress ecosystem plugins also feature prominently, with CVE-2025-69129 (CVSS 10) in the WooCommerce Scraper plugin and CVE-2026-25470 (CVSS 10) in the ACPT Custom Post Types plugin, alongside five vulnerabilities under active exploitation across Ivanti Sentry, Oracle PeopleSoft, Cisco Catalyst SD-WAN Manager, and others. No patches were recorded as available at disclosure time, so affected organizations should prioritize inventory and compensating controls while monitoring vendor advisories.
Immediate action: Prioritize Oracle WebLogic Server, Coherence, Solaris, and WebCenter Enterprise Capture deployments along with the affected WordPress plugins for review and isolation. With no patches yet available for these disclosures, apply network restrictions and access controls to exposed instances and patch the actively exploited Ivanti Sentry, Cisco Catalyst SD-WAN Manager, and Oracle PeopleSoft systems as vendor fixes are released.
A critical OS command injection vulnerability in Ivanti Sentry allows remote unauthenticated users to achieve root-level remote code execution.
An unauthenticated, easily exploitable vulnerability in the PeopleSoft Updates Environment Management component allows for complete system takeover via HTTP.
A symlink mishandling vulnerability in the LiteSpeed cPanel plugin allows users with limited access to escalate privileges on shared hosting environments.
An improper access control vulnerability in the Widget Factory Joomla Content Editor allows unauthorized users to perform restricted actions.
Cisco Catalyst SD-WAN Manager contains an arbitrary file write vulnerability in its web UI, allowing authenticated remote attackers to escalate privileges to root.
A critical vulnerability in the Generic Unix Connector of the Oracle Fusion Middleware Identity Manager allows for full component takeover by low-privileged attackers.
An unauthenticated arbitrary file upload vulnerability exists in the WordPress & WooCommerce Scraper Plugin, allowing attackers to upload malicious files.
A critical vulnerability in the Oracle Solaris Remote Administration Daemon allows unauthenticated attackers to modify or delete critical system data via HTTPS.
An improper code injection vulnerability in the ACPT (Pro) plugin for WordPress allows unauthenticated remote attackers to execute arbitrary code.
A critical, unauthenticated remote code execution vulnerability in the Oracle WebLogic Server Console allows complete system takeover.
An unauthenticated remote code execution vulnerability exists in the Oracle WebLogic Server Console component, allowing full system takeover via crafted HTTP requests.
A critical vulnerability in the Oracle Coherence core component allows unauthenticated attackers to compromise the application via network-accessible HTTP requests.
A critical flaw in the Oracle Coherence Centralized Third Party Jars component allows unauthenticated attackers to achieve full system compromise via network-accessible HTTP requests.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows unauthenticated remote attackers to compromise the system via RMI.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows unauthenticated remote attackers to compromise the system via RMI.
A critical, remotely exploitable vulnerability in Oracle WebCenter Sites allows unauthenticated attackers to fully compromise the application via HTTP.
An easily exploitable, unauthenticated vulnerability in Oracle WebCenter Sites allows for full remote system compromise via HTTP.
A critical security framework vulnerability in Oracle WebCenter Portal allows unauthenticated attackers to achieve full system takeover via HTTP.
A critical, unauthenticated remote exploit in Oracle WebCenter Portal's Security Framework allows for full system compromise.
A critical vulnerability in Oracle WebLogic Server allows low-privileged attackers to gain full system control via HTTP.
A critical vulnerability in Oracle Fusion Middleware Identity Manager allows low-privileged attackers to achieve a full system takeover via T3 or IIOP protocols.
A critical vulnerability in Oracle WebCenter Enterprise Capture allows low-privileged attackers to gain full control of the application via T3 or IIOP network protocols.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows low-privileged attackers to compromise the system via T3 or IIOP protocols.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows low-privileged attackers to compromise the system via T3 or IIOP protocols.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows low-privileged attackers to compromise the system via T3 or IIOP protocols.
A critical vulnerability in Oracle WebCenter Enterprise Capture allows a low-privileged, network-adjacent attacker to achieve full system takeover via T3 or IIOP protocols.
A critical vulnerability in Oracle WebCenter Enterprise Capture allows a low-privileged, network-adjacent attacker to achieve full system takeover via T3 or IIOP protocols.
A critical vulnerability in the Oracle Identity Manager Connector enables a low-privileged, network-adjacent attacker to achieve full system takeover via HTTP.
A critical vulnerability in the Oracle Access Manager authentication engine allows a low-privileged, network-adjacent attacker to achieve full system takeover via HTTP.
A critical vulnerability in the Oracle WebCenter Content server allows a low-privileged, network-adjacent attacker to achieve full system takeover via HTTP.
A critical vulnerability in Oracle WebCenter Content allows a low-privileged attacker to achieve full system takeover via network-based HTTP exploitation.
A critical vulnerability in Oracle WebCenter Content allows a low-privileged attacker to achieve full system takeover via network-based HTTP exploitation.
A critical vulnerability in Oracle WebCenter Portal's Composer component allows a low-privileged attacker to achieve full system takeover via HTTP.
A critical vulnerability in Oracle WebCenter Portal's Composer component allows a low-privileged attacker to achieve full system takeover via HTTP.
A critical vulnerability in Oracle WebCenter Enterprise Capture allows a low-privileged attacker to achieve full system takeover via T3 protocol exploitation.
A critical vulnerability in Oracle WebCenter Enterprise Capture allows a low-privileged, network-based attacker to achieve full system takeover via the Client Bundle component.
A critical vulnerability in the Identity Manager Connector (Generic Unix Connector) allows a low-privileged, network-based attacker to achieve full system takeover.
A critical vulnerability in the Identity Manager Connector (Database User component) allows a low-privileged, network-based attacker to achieve full system takeover.
A critical vulnerability in the Oracle WebCenter Portal Security Framework allows a low-privileged, network-based attacker to achieve full system takeover.
A critical vulnerability in the Oracle WebCenter Portal Security Framework allows a low-privileged, network-based attacker to achieve full system takeover.
A critical vulnerability in the Oracle Enterprise Manager Discovery Framework allows low-privileged network attackers to achieve full platform compromise.
A critical flaw in the Oracle WebCenter Portal Security Framework allows low-privileged attackers to compromise the application and potentially impact dependent systems.
A critical vulnerability in the Oracle WebCenter Portal Security Framework permits low-privileged attackers to perform a full system takeover.
A critical vulnerability in the Oracle WebCenter Portal Runtime Tools allows low-privileged attackers to gain full control of the application.
A vulnerability in the MySQL Shell for VS Code extension allows a low-privileged attacker to compromise the shell environment via network-accessible HTTP requests.
A critical vulnerability in the Oracle Enterprise Manager Metadata Plugin allows low-privileged attackers to compromise the platform.
A critical vulnerability in the Target Management component of Oracle Enterprise Manager allows low-privileged attackers to achieve complete platform takeover via HTTP.
A critical vulnerability in the Metadata Plugin of Oracle Enterprise Manager allows low-privileged attackers to achieve full platform takeover via HTTPS.
A critical vulnerability in the E1 Foundation of Oracle JD Edwards EnterpriseOne allows low-privileged attackers to compromise the General Ledger via SMB.
A critical vulnerability in the Core component of Oracle Enterprise Command Center Framework allows low-privileged attackers to achieve full platform takeover via HTTP.
A critical vulnerability in the Core component of Oracle Enterprise Command Center Framework allows low-privileged attackers to perform unauthorized data modifications and denial of service.
A security bypass in the picklescan library allows attackers to resolve dangerous functions through indirect calls, leading to remote code execution.
A Zip Slip vulnerability in the Streambert desktop application allows attackers to perform path traversal and write arbitrary files to the host filesystem.
The Entrepreneur Booking WordPress theme is vulnerable to PHP Object Injection, allowing low-privileged authenticated users to execute arbitrary code.
A Use-After-Free (UAF) vulnerability in Google Chrome's Digital Credentials component allows for potential remote code execution or system instability.
A use-after-free vulnerability exists in the File Input component of Google Chrome on Linux, potentially allowing for arbitrary code execution.
A use-after-free vulnerability in the password management component of Google Chrome on Android may lead to unauthorized access or system instability.
A use-after-free vulnerability in the Web Authentication component of Google Chrome allows potential attackers to compromise browser security.
A heap buffer overflow vulnerability in the WebRTC component of Google Chrome could lead to remote code execution.
A use-after-free vulnerability in the Downloads component of Google Chrome on Android allows potential memory corruption and system instability.
A heap buffer overflow vulnerability exists in the WebRTC component of Google Chrome on Windows, potentially allowing for arbitrary code execution.
The Events Schedule plugin for WordPress contains a SQL injection vulnerability that allows authenticated subscribers to extract sensitive database information.
The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is susceptible to Remote Code Execution due to insufficient input validation.
An unspecified vulnerability exists in the Console component of Oracle WebLogic Server, which may allow for unauthorized access or system impact.
A security vulnerability in the Identity Manager component of Oracle Fusion Middleware could be exploited to compromise identity management processes.
A vulnerability in the REST WebServices component of Oracle Identity Manager may allow for unauthorized manipulation of API-based identity services.
An unspecified vulnerability in the Console component of Oracle WebLogic Server could allow for unauthorized system impact or control.
A vulnerability exists in the Oracle Fusion Middleware WebLogic Server Console component that allows low-privileged network-based attackers to compromise the server.
A vulnerability in the Core component of Oracle Fusion Middleware WebLogic Server allows low-privileged attackers to compromise the application.
A vulnerability in the Content Server component of Oracle WebCenter Content allows low-privileged attackers to compromise the application.
A vulnerability in the Content Server component of Oracle WebCenter Content allows low-privileged attackers to compromise the application.
A vulnerability in the Oracle WebCenter Sites component allows low-privileged attackers to compromise the application.
A high-severity vulnerability exists within the Content Server component of Oracle WebCenter Content that may allow for unauthorized system interaction.
A high-severity security vulnerability exists within the Content Server component of Oracle WebCenter Content that may impact system security.
A high-severity vulnerability has been identified in the Content Server component of Oracle WebCenter Content, requiring immediate remediation.
A high-severity vulnerability exists within the Core component of Oracle WebCenter Content: Imaging that could lead to unauthorized system access.
A high-severity vulnerability in the Agent Next Gen component of Oracle Enterprise Manager Base Platform could allow for unauthorized system interaction.
A high-severity vulnerability exists within the EAI component of Oracle Siebel CRM, potentially allowing for unauthorized system interaction.
A vulnerability in the Marketing component of Oracle Siebel CRM could potentially be leveraged by an attacker to compromise application integrity.
A security vulnerability in the Business Logic Infrastructure of Oracle JD Edwards EnterpriseOne Tools could allow for unauthorized system manipulation.
A vulnerability within the Quality Management Specs component of Oracle E-Business Suite could lead to unauthorized system impacts.
A vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM could allow an attacker to disrupt or compromise cloud-based application management.
A vulnerability exists in the Siebel Cloud Manager component of Oracle Siebel CRM that may allow unauthorized access or impact system integrity.
A security flaw has been identified in the Spares Management component of Oracle E-Business Suite that could be exploited to compromise internal operations.
A vulnerability in the Cost Management component of Oracle E-Business Suite could allow for unauthorized manipulation of cost planning data.
A security vulnerability in the Enterprise Asset Management component of Oracle E-Business Suite could allow for unauthorized internal operational changes.
A vulnerability in the iSetup product of Oracle E-Business Suite could allow for unauthorized data transformation or reporting manipulation.
A high-severity vulnerability exists within the Cost Planning component of Oracle E-Business Suite’s Cost Management product.
A high-severity vulnerability exists within the Internal Operations component of Oracle E-Business Suite’s Process Manufacturing Process Planning product.
A high-severity vulnerability exists within the Internal Operations component of Oracle E-Business Suite’s Advanced Outbound Telephony product.
A high-severity vulnerability exists within the Internal Operations component of Oracle E-Business Suite’s Advanced Outbound Telephony product.
A high-severity vulnerability exists within the Internal Operations component of Oracle E-Business Suite’s Quality product.
A high-severity vulnerability exists within the Internal Operations component of the Oracle E-Business Suite Quality product.
A high-severity vulnerability exists within the Internal Operations component of the Oracle E-Business Suite Project Portfolio Analysis product.
A high-severity vulnerability exists within the Internal Operations component of the Oracle E-Business Suite Project Portfolio Analysis product.
A high-severity vulnerability exists within the Work Provider Site Level Administration component of the Oracle E-Business Suite Universal Work Queue.
A high-severity vulnerability exists within the Authorization component of the Oracle E-Business Suite Public Sector Financials (International) product.
A vulnerability exists in the Internal Operations component of Oracle Outsourced Mfg for Discrete Industries within the Oracle E-Business Suite.
A vulnerability exists in the Internal Operations component of Oracle Outsourced Mfg for Discrete Industries within the Oracle E-Business Suite.
A PHP object injection vulnerability exists in the Avada theme, allowing authenticated contributors to execute arbitrary code.
An inappropriate implementation vulnerability exists in the WebView component of Google Chrome on Android versions prior to 149.
An unauthenticated Cross-Site Request Forgery (CSRF) vulnerability exists in the WordPress Dating Theme, potentially allowing unauthorized state-changing actions.
A vulnerability exists in the Console component of the WebLogic Server product within Oracle Fusion Middleware.
A vulnerability exists in the WebLogic component of Oracle PeopleSoft Enterprise PT PeopleTools.
A security vulnerability exists within the Content Server component of Oracle WebCenter Content, potentially allowing for unauthorized system impact.
A security flaw has been identified in the Content Server component of Oracle WebCenter Content, requiring urgent attention to prevent unauthorized access.
A vulnerability in the OUD Core component of Oracle Unified Directory may allow for unauthorized system impact.
An unauthenticated broken access control vulnerability in the WordPress Dating Theme allows unauthorized users to access restricted functions or data.
A high-severity vulnerability exists in the MySQL Shell component for VS Code, potentially allowing unauthorized access or impact to the development environment.
A vulnerability within the Production component of Oracle Complex Maintenance, Repair and Overhaul poses a risk to system integrity.
A memory-related vulnerability exists within the `mfc_core_get_dec_metadata_sei_nal` function of the Samsung MFC core, potentially allowing for system-level impact.
The Contest Gallery WordPress plugin is vulnerable to privilege escalation, allowing authenticated attackers to elevate their access level within the application.
A memory-related vulnerability exists within the `__mfc_core_nal_q_get_dec_metadata_sei_nal` function of the MFC (Multi-Function Codec) core, potentially allowing for memory corruption.
A vulnerability in the `ParsePayloads` function of the `AudioSdpParser` component could allow for improper handling of SDP payloads.
The E2Pdf – Export Pdf Tool for WordPress plugin is vulnerable to a missing authorization flaw, potentially exposing sensitive PDF generation functions to unauthorized users.
Citrix Cloud contains an authorization flaw where read-only accounts can initiate sensitive workflow processes, leading to unauthorized write operations.
Dell PowerFlex Manager is affected by a missing authentication vulnerability that allows unauthenticated attackers to perform critical functions.
A critical security vulnerability has been identified in the Cotonti content management system, requiring immediate attention to prevent potential system compromise.
A subscriber-level SQL Injection vulnerability exists in the WooCommerce Frontend Manager – Ultimate plugin, allowing for potential database manipulation.
A broken authentication vulnerability exists in PowerPack Pro for Elementor, allowing unauthenticated attackers to bypass security controls.
A heap-based buffer overflow vulnerability in the modem firmware allows for a possible out-of-bounds write, potentially leading to code execution.
A heap-based buffer overflow in `RtpSession::rtpSendRtcpPacket` allows for an out-of-bounds write, potentially enabling remote code execution.
A privilege escalation vulnerability in the Sonaar plugin allows authenticated subscribers to perform unauthorized actions with elevated permissions.
A privilege escalation vulnerability in the Genemy plugin allows authenticated subscribers to gain unauthorized elevated permissions.
A privilege escalation vulnerability in the Falang multilanguage plugin allows authenticated subscribers to gain unauthorized elevated permissions.
A stack-based buffer overflow exists in the raw_to_header() function of the microtar library, which may allow arbitrary code execution.
A SQL injection vulnerability in the Geo Mashup plugin allows authenticated subscribers to execute arbitrary database commands.
A blind SQL injection vulnerability in the wpWax Directorist Booking plugin allows authenticated users to exfiltrate database information.
A SQL injection vulnerability in the Cornerstone page builder allows authenticated subscribers to manipulate database queries.
A blind SQL injection vulnerability in the Brainstorm Force SureDash plugin allows authenticated users to perform unauthorized database queries.
A blind SQL injection vulnerability in the VeronaLabs Slimstat Analytics plugin allows authenticated users to extract database information.
A missing bounds check in the Modem firmware leads to a potential out-of-bounds write vulnerability.
Multiple functions within the VideoRtpPayloadDecoderNode component are susceptible to memory-related vulnerabilities.
A vulnerability in the IntfGraphCreate function within the intfgraph component may lead to critical memory corruption.
A memory corruption flaw in the Modem firmware allows for a device crash when processing a malicious SIP REFER request.
The DecodeT140 function in the TextRtpPayloadDecoderNode is vulnerable to memory corruption due to improper processing.
A memory safety vulnerability exists in the RtpSession component of the Android telephony stack, specifically within the numberOfReportBlocks function.
A missing bounds check in the device modem firmware allows for an out-of-bounds write, potentially leading to memory corruption.
PickleScan contains an unspecified vulnerability prior to version 0.
Car Zone versions 3 and earlier are vulnerable to unauthenticated arbitrary file deletion.
BookPro versions 1 and earlier contain an unauthenticated arbitrary file deletion vulnerability.
The EMV JobCareer software contains a path traversal vulnerability due to improper limitation of a pathname to a restricted directory.
Cornerstone versions prior to 7 allow arbitrary code execution for authenticated subscribers.