CVE-2026-20045
Cisco Unified Communications Products Code Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Yesterday's disclosures included 7 critical-severity CVEs (CVSS 9.0+), a 40% increase from the prior day's 5 critical issues. High-priority vulnerabilities (CVSS 7.0-8.9) totaled 72, reflecting an 8% decrease from the previous 78. Sixteen actively exploited vulnerabilities remain on the CISA KEV catalog, spanning Cisco Unified Communications Manager, Zimbra Collaboration Suite, VMware vCenter Server, Microsoft Office, and multiple SmarterTools SmarterMail instances. Notable critical disclosures include CVE-2026-1868 (CVSS 9.9) affecting GitLab, CVE-2026-22903 (CVSS 9.8) in lighttpd, and CVE-2025-15027 (CVSS 9.8) targeting WordPress installations. Patch availability stands at 0%, requiring organizations to prioritize compensating controls and monitoring until vendor remediations are released.
Immediate action: Organizations running Cisco Unified Communications Manager, Zimbra, VMware vCenter, Microsoft Office, SmarterMail, GitLab, lighttpd, or WordPress should review exposure to the listed CVEs and apply network-level mitigations. With no patches currently available, implement compensating controls such as access restrictions, enhanced monitoring, and WAF rules for affected systems.
Cisco Unified Communications Products Code Injection Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability - Active in CISA KEV catalog.
Versa Concerto Improper Authentication Vulnerability - Active in CISA KEV catalog.
Vite Vitejs Improper Access Control Vulnerability - Active in CISA KEV catalog.
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability - Active in CISA KEV catalog.
Linux Kernel Integer Overflow Vulnerability - Active in CISA KEV catalog.
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability - Active in CISA KEV catalog.
GNU InetUtils Argument Injection Vulnerability - Active in CISA KEV catalog.
Microsoft Office Security Feature Bypass Vulnerability - Active in CISA KEV catalog.
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Sangoma FreePBX OS Command Injection Vulnerability - Active in CISA KEV catalog.
Sangoma FreePBX Improper Authentication Vulnerability - Active in CISA KEV catalog.
React Native Community CLI OS Command Injection Vulnerability - Active in CISA KEV catalog.
SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
All versions of the jsonpath library are vulnerable to arbitrary code injection via unsafe evaluation of user-supplied JSON Path expressions.
The JAY Login & Register plugin for WordPress allows unauthenticated privilege escalation to administrator by exploiting the 'jay_login_register_ajax_create_final_user' function.
Insecure template expansion in GitLab AI Gateway allows attackers to cause a denial-of-service or execute arbitrary code via crafted Duo Agent definitions.
A stack buffer overflow in modified lighttpd servers allows unauthenticated remote code execution via a crafted SESSIONID cookie.
Improper length handling of cookie fields, including TRACKID, allows unauthenticated remote attackers to trigger a stack buffer overflow and execute arbitrary code.
User credentials are stored using weak AES-ECB encryption with a hardcoded key, allowing unauthenticated attackers to recover plaintext passwords.
A missing authentication vulnerability in HGiga C&Cm@il allows unauthenticated attackers to read and modify any user's email content.
A SQL Injection vulnerability in HGiga C&Cm@il allows unauthenticated remote attackers to inject arbitrary commands and read database contents.
The JAY Login & Register plugin for WordPress is vulnerable to privilege escalation. All versions up to and including version 2 are affected by this flaw.
A security vulnerability exists in PHPGurukul Beauty Parlour Management System 1, which could allow attackers to compromise the application's integrity and access sensitive data.
A security vulnerability has been detected in yuan1994 tpadmin up to 1
A weakness has been identified in detronetdip E-commerce 1
A security vulnerability has been detected in code-projects Online Reviewer System 1
A vulnerability was found in code-projects Online Student Management System 1
A vulnerability was determined in code-projects Online Application System for Admission 1
A security flaw has been discovered in code-projects Online Reviewer System 1
A flaw has been found in itsourcecode News Portal Project 1
A vulnerability has been found in D-Link DIR-615 4
A vulnerability was found in D-Link DIR-615 4
A security flaw has been discovered in code-projects Social Networking Site 1, potentially enabling unauthorized actions or data exposure within the platform.
A flaw in SourceCodester Online Class Record System 1 allows for potential exploitation and unauthorized interaction with academic records and system data.
A secondary vulnerability has been discovered in SourceCodester Online Class Record System 1, further increasing the potential for unauthorized system access and data manipulation.
A security vulnerability in itsourcecode Society Management System 1 could allow for unauthorized access or the compromise of sensitive organizational data.
A flaw has been found in itsourcecode Society Management System 1
A vulnerability has been found in itsourcecode Society Management System 1
A vulnerability was found in itsourcecode Society Management System 1
A security flaw has been discovered in code-projects Online Music Site 1
A weakness has been identified in code-projects Online Music Site 1
A flaw has been found in projectworlds Online Food Ordering System 1
A vulnerability was detected in code-projects Student Web Portal 1
A vulnerability was found in itsourcecode Directory Management System 1
A security flaw has been discovered in detronetdip E-commerce 1
A vulnerability was identified in code-projects Online Examination System 1
A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3cffb73
A vulnerability was identified in itsourcecode School Management System 1
A security flaw has been discovered in itsourcecode School Management System 1
A vulnerability has been found in code-projects Online Reviewer System 1
A vulnerability was found in code-projects Online Reviewer System 1
A vulnerability was determined in code-projects Online Reviewer System 1
A vulnerability was identified in code-projects Online Reviewer System 1
A security flaw has been discovered in code-projects Online Reviewer System 1
A vulnerability was determined in code-projects Online Music Site 1
A vulnerability was identified in code-projects Online Music Site 1
A vulnerability was found in itsourcecode Event Management System 1
A vulnerability was identified in code-projects Online Reviewer System 1
A security vulnerability has been detected in code-projects Online Reviewer System 1
MacroHub developed by GIGABYTE has a Local Privilege Escalation vulnerability
A vulnerability has been found in Tenda TX3 up to 16
A vulnerability was found in Tenda TX9 up to 22
A vulnerability was determined in Tenda TX9 up to 22
A vulnerability was identified in Tenda TX9 up to 22
A vulnerability was identified in Tenda RX3 16
A security flaw has been discovered in Tenda RX3 16
A flaw has been found in Tenda RX3 16
A vulnerability has been found in Tenda RX3 16
A vulnerability was found in Tenda RX3 16
A vulnerability was detected in Tenda AC8 16
A flaw has been found in Tenda AC8 16
A weakness has been identified in D-Link DIR-823X 250416
A security vulnerability has been detected in D-Link DWR-M921 1
A vulnerability was identified in D-Link DIR-823X 250416
A vulnerability was found in D-Link DIR-823X 250416
A weakness has been identified in D-Link DIR-823X 250416
A security flaw has been discovered in D-Link DIR-823X 250416
A security vulnerability has been detected in D-Link DIR-823X 250416
A weakness has been identified in D-Link DIR-823X 250416
A weakness has been identified in Tenda AC9 15
A security vulnerability has been detected in Tenda AC9 15
A vulnerability has been found in D-Link DIR-823X 250416
Insufficient URI validation and path traversal sequences allow unauthenticated remote attackers to bypass authentication on the affected system.
A vulnerability was detected in UTT HiPER 810G up to 1
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc
A vulnerability was determined in SourceCodester Online Class Record System 1
A security flaw has been discovered in code-projects Contact Management System 1
A vulnerability has been found in SourceCodester Prison Management System 1
A vulnerability was determined in UTT HiPER 810 1
A security vulnerability has been detected in D-Link DIR-823X 250416
A security weakness has been identified in the UTT θΏε 521G 3 router that could compromise the device's security posture.
A vulnerability in the UTT θΏε 521G 3 router allows for potential compromise of the device by remote attackers.