CVE-2026-16232
An improper authentication vulnerability in Check Point SmartConsole allows unauthenticated attackers to potentially bypass security controls.
Critical vulnerabilities, curated daily for security professionals
Web-facing application software dominated Tuesday's disclosures, with remote code execution and authentication bypass issues reported in pheditor, vBulletin, phpMyFAQ, Erlang OTP, and a broad set of WordPress plugins including Realtyna Organic IDX and FacturaONE for WooCommerce. The day brought 30 critical CVEs (CVSS 9.0+) and 91 high-priority CVEs, up from 6 and 18 the prior day, a roughly fourfold increase in both categories across 121 total records. CVE-2026-48030 (CVSS 9.9, pheditor) and CVE-2026-55579 (CVSS 9.8, pheditor) sit at the top of the range, followed by CVE-2026-61511 (CVSS 9.8, vBulletin) and CVE-2026-66398 (CVSS 9.4, phpMyFAQ). Content management platforms, e-commerce plugins, and self-hosted collaboration tools carry most of the critical weight, while five vulnerabilities have confirmed active exploitation, including CVE-2026-16812 (CVSS 10.0) in Arista VeloCloud Orchestrator On-Prem and CVE-2026-50522 in Microsoft SharePoint. No patch data was recorded for this set, so treat remediation status as unconfirmed and verify fix availability directly with each vendor before planning rollout.
Immediate action: Prioritize internet-facing WordPress installations and their plugin inventory, along with vBulletin, phpMyFAQ, and pheditor deployments, since these carry the highest-scoring remote code execution and authentication bypass issues. Separately, review exposure to the five actively exploited products (Arista VeloCloud Orchestrator On-Prem, Microsoft SharePoint, Check Point SmartConsole, WordPress Core, and Fortinet FortiOS) and apply vendor updates or mitigations promptly. No patch availability was recorded for this batch, so confirm fix status with each vendor and apply access restrictions or WAF rules where updates are not yet published.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An improper authentication vulnerability in Check Point SmartConsole allows unauthenticated attackers to potentially bypass security controls.
A deserialization vulnerability in Microsoft SharePoint allows an unauthenticated attacker to execute code over a network.
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
WordPress Core is affected by a SQL injection vulnerability that allows unauthenticated attackers to execute unauthorized database queries.
A sensitive information disclosure vulnerability exists in Fortinet FortiOS, allowing unauthenticated attackers to access restricted system data.
The Realtyna Organic IDX plugin + WPL Real Estate for WordPress contains a critical file upload vulnerability allowing unauthenticated remote code execution via hardcoded credentials.
A SQL injection vulnerability in the EasyAppointments /customers/search endpoint allows unauthenticated attackers to perform time-based queries or potentially achieve remote code execution.
Pheditor versions 2.0.1 through 2.0.3 are vulnerable to OS command injection via the terminal action handler, allowing authenticated users to achieve remote code execution.
Pheditor versions 2.0.1 through 2.0.5 contain hardcoded credentials that allow unauthenticated attackers to gain full administrative access and execute arbitrary code.
phpMyFAQ before version 4.1.6 allows authenticated administrators to achieve remote code execution via the configuration API by manipulating upgrade settings to extract malicious files.
Erlang/OTP TLS 1.2 and earlier clients fail to verify the server-selected cipher suite against the offered list, allowing on-path attackers to perform an algorithm downgrade attack.
A code injection vulnerability in FacturaONE para WooCommerce con VeriFactu allows unauthenticated attackers to write arbitrary files to the server via an unauthenticated request handler.
vBulletin contains an eval injection vulnerability in the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code via the pagenav[pagenumber] parameter.
A stored cross-site scripting vulnerability in lookyloo allows attackers to inject malicious scripts into the capture tree visualization page, executing in the context of a victim's session.
The SMS Alert plugin for WordPress is vulnerable to authentication bypass and account takeover due to an insecure OTP validation process that fails to bind verification status to specific phone numbers.
An unauthenticated SQL injection vulnerability exists in the rtMedia for WordPress plugin, allowing attackers to manipulate database queries via vulnerable parameters.
A use-after-free vulnerability in the SQLite core parsing component allows remote attackers to trigger a crash, leak sensitive memory, or achieve arbitrary code execution via crafted SQL queries.
A heap-based buffer overflow vulnerability in Apache Thrift C++ bindings allows remote attackers to execute arbitrary code or cause a crash via specially crafted input.
The MemberGlut WordPress plugin fails to validate user roles during registration, allowing unauthenticated attackers to register as administrators and compromise the site.
An improper certificate validation vulnerability in Apache Thrift c_glib bindings allows attackers to perform man-in-the-middle attacks by failing to verify hostnames.
The Masteriyo LMS WordPress plugin contains an unauthenticated AJAX action that allows attackers to terminate any user session, including administrators, leading to a forced logout.
The 微信二维码登陆 WordPress plugin fails to validate WeChat webhook signatures, allowing unauthenticated attackers to forge login events and impersonate any user, including administrators.
The Net::DNS Perl module contains an eval injection vulnerability in the EDNS EXTENDED-ERROR parsing logic, allowing remote code execution via crafted EXTRA-TEXT fields.
A deserialization of untrusted data vulnerability in the 3DEXPERIENCE Station Launcher App allows unauthenticated remote code execution.
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
An authenticated SQL injection vulnerability in the Arista VeloCloud Orchestrator API allows for unauthorized data access and unintended outbound network connections.
A critical SQL injection vulnerability in the MapSVG plugin for WordPress allows unauthenticated attackers to execute arbitrary SQL commands.
An unauthenticated SQL injection vulnerability in the Relevanssi Light WordPress plugin allows remote attackers to compromise the database.
A critical, unauthenticated SQL injection vulnerability exists in the GamiPress plugin, enabling remote attackers to manipulate database queries.
An unauthenticated SQL injection vulnerability in AWP Classifieds allows remote attackers to execute arbitrary SQL commands via the plugin, potentially leading to unauthorized database access.
The SP Page Builder extension for Joomla contains an unauthenticated SQL injection vulnerability in the Dynamic Content endpoint due to improper validation of order parameters.
The SP Page Builder extension for Joomla contains an unauthenticated SQL injection vulnerability in the loadMoreArticles endpoint due to improper validation of catid parameters.
A reflected cross-site scripting vulnerability in SiYuan desktop allows attackers to achieve remote code execution through malicious deep links that leverage insecure Electron renderer configurations.
The Page Builder CK extension for Joomla contains an improper access control vulnerability that permits unauthenticated users to view or interact with restricted frontend page list data.
The Tenda TX9 router firmware version V22.03.02.20 contains a stack-based buffer overflow vulnerability in the /goform/SetVirtualServerCfg endpoint.
An infinite loop vulnerability in Apache Thrift allows unauthenticated remote attackers to cause a denial of service via specifically crafted input across multiple language bindings.
A data amplification vulnerability in Apache Thrift allows unauthenticated remote attackers to trigger excessive resource consumption through the processing of highly compressed data.
A Server-Side Request Forgery vulnerability in the cloud-healthcare-fhir-fetch-page tool of the Google MCP Toolbox allows for credential exfiltration and unauthorized internal requests.
A SQL injection vulnerability in the rtMedia for WordPress plugin allows authenticated subscribers to execute arbitrary database queries.
The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin contains an improper authentication vulnerability that allows unauthenticated attackers to manipulate payment processes.
A buffer overflow vulnerability in Apple operating systems may allow for arbitrary code execution when processing maliciously crafted files.
A SQL injection vulnerability in the WP Google Review Slider plugin allows authenticated administrators to execute arbitrary database queries.
Pheditor is susceptible to OS command injection, allowing an authenticated user with low privileges to execute arbitrary system commands on the host server.
Pheditor is susceptible to OS command injection, allowing an authenticated user with low privileges to execute arbitrary system commands on the host server.
An integer overflow or wraparound vulnerability in Apache Thrift allows unauthenticated remote attackers to cause instability or denial of service across multiple language bindings.
The Apache Thrift Rust bindings are vulnerable to an Allocation of Resources Without Limits or Throttling issue, which can lead to application denial of service.
The Apache Thrift C++ bindings are susceptible to an out-of-bounds read vulnerability due to improper validation of specified quantities in input data.
phpMyFAQ is susceptible to path traversal, allowing an authenticated administrator to delete arbitrary files on the server via the category image deletion function.
The Printcart Web to Print Product Designer for WooCommerce WordPress plugin is vulnerable to Server-Side Request Forgery, allowing unauthenticated attackers to probe internal network resources.
Ericsson Packet Core Controller (PCC) is vulnerable to OS command injection due to improper neutralization of special elements, allowing an authenticated user to execute arbitrary commands.
The Bouncy Castle for Java library is susceptible to a timing discrepancy vulnerability during cryptographic operations, potentially allowing for side-channel information leakage.
A certificate validation flaw in Apache Thrift C++ bindings allows for host mismatch conditions, potentially facilitating man-in-the-middle attacks.
The Custom Fields Account Registration For Woocommerce WordPress plugin contains an improper privilege management vulnerability that could allow unauthorized escalation of user account permissions.
A permissions vulnerability in macOS allows a malicious application to potentially gain root privileges through restricted system access.
A permissions vulnerability in macOS allows a malicious application to potentially gain root privileges through restricted system access.
An injection vulnerability in macOS allows a malicious application to potentially gain root privileges due to insufficient input validation.
A path handling vulnerability in multiple Apple operating systems allows local applications to potentially escalate privileges to root.
A directory path parsing flaw in macOS allows local applications to potentially escalate privileges to root via improved validation failure.
An unauthenticated vulnerability in the Falcon WordPress plugin allows for potential denial of service due to improper input validation.
The Apache Thrift Ruby bindings are susceptible to a data amplification vulnerability due to improper handling of highly compressed data.
The WP Fast Total Search plugin for WordPress contains an SQL Injection vulnerability in the form_data[s] parameter, allowing unauthenticated attackers to query the database.
The BookingPress Appointment Booking Pro WordPress plugin is vulnerable to improper authentication, allowing unauthenticated attackers to potentially bypass security controls.
The MainWP Child plugin for WordPress is vulnerable to an authentication bypass issue, potentially allowing unauthorized access to the affected site.
The Apache Thrift Node implementation suffers from inefficient algorithmic complexity and resource allocation vulnerabilities that allow for denial of service.
The Demi plugin for WordPress is vulnerable to path traversal, allowing unauthenticated attackers to delete arbitrary directories on the host server.
The Download Manager WordPress plugin is susceptible to improper access control, allowing unauthenticated attackers to potentially bypass security restrictions.
The Better Messages plugin for WordPress is vulnerable to arbitrary file deletion via insufficient path validation in the delete_sticker function, requiring administrative privileges.
The Erlang/OTP SSL application fails to detect cycles during peer certificate chain reconstruction, leading to uncontrolled recursion and potential denial of service.
A buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to cause a denial of service or potentially execute arbitrary code via a crafted message.
React Router is susceptible to uncontrolled resource consumption, allowing an unauthenticated remote attacker to cause a denial of service via inefficient algorithmic complexity.
The Erlang/OTP public_key certificate path validation component lacks proper resource limits, allowing an unauthenticated attacker to cause a denial of service via crafted X.509 data.
A missing authorization vulnerability in various Progress Software products allows authenticated attackers with low privileges to perform unauthorized administrative actions via the REST API.
A deserialization vulnerability in JFrog Artifactory package handling allows low-privileged users to impact system confidentiality, integrity, and availability under specific repository conditions.
PostCSS is susceptible to a path traversal vulnerability that could allow unauthorized actors to expose sensitive information by manipulating CSS file processing.
A recursion depth vulnerability in Net::DNS for Perl allows unauthenticated attackers to cause a Denial of Service via crafted DNS compression pointer chains.
An SQL injection vulnerability in the Sender WordPress plugin allows authenticated administrators to execute arbitrary SQL commands via improper input neutralization.
A flaw in JFrog Artifactory event handling can expose sensitive authorization material to users with lower privileges under specific conditions.
A code injection vulnerability in the JSON Pointer-to-accessor compiler within Cribl Stream allows authenticated users to execute arbitrary code.
Cribl Stream is vulnerable to improper symbolic link validation within its Pack Git import feature, which may allow attackers to perform unauthorized file operations.
JFrog Artifactory contains an authorization flaw in its refresh token signature validation, enabling authenticated users to escalate privileges by obtaining an administrator token.
JFrog Artifactory is susceptible to path traversal during archive extraction, allowing attackers to write files outside of designated directories.
JFrog Artifactory contains an authentication handling vulnerability in internal request processing that may allow an authenticated attacker to escalate privileges.
SiYuan is vulnerable to stored and reflected cross-site scripting (XSS) due to an improper neutralization of input during web page generation via a bypass in the SVG sanitizer.
The Ghost Robotics Vision 60 mobile application (APK version 5.5.0) suffers from a lack of authentication for critical functions, allowing unauthorized access via the local network.
The Ghost Robotics Vision 60 robot, version 5.5.0, lacks cryptographic integrity and authenticity mechanisms, enabling potential man-in-the-middle attacks on local networks.
A stored Cross-site Scripting vulnerability in the email module of Roskus Prospero Flow CRM allows attackers to inject malicious scripts, potentially leading to administrator account takeover.
A Server-Side Request Forgery vulnerability in the Arista VeloCloud Orchestrator allows authenticated tenant accounts to access restricted internal services.
A stored cross-site scripting vulnerability in SiYuan allows high-privileged attackers to achieve remote code execution via malicious title, image, or IAL inputs.
An OS command injection vulnerability exists in multiple Progress Software appliances, allowing authenticated, high-privileged attackers to execute arbitrary commands via the management interface.
An OS command injection vulnerability in the Geo Location management interface of several Progress Software products allows authenticated, high-privileged attackers to execute arbitrary OS commands.
An OS command injection vulnerability exists in several Progress Software appliances that allows high privileged users to execute arbitrary commands via the backup restore functionality.
A server-side request forgery (SSRF) vulnerability in the Vercel Next.js framework allows unauthenticated attackers to potentially access sensitive resources.
An improper authorization vulnerability in the Next.js framework allows unauthenticated attackers to bypass security checks and potentially access restricted application features.
Next.js is vulnerable to Server-Side Request Forgery and Open Redirect attacks due to improper input validation, allowing unauthenticated attackers to potentially access internal resources or redirect users.
The SP Page Builder extension for Joomla is vulnerable to path traversal, allowing an authenticated administrator to manipulate file paths and potentially impact system integrity.
Next.js contains an excessive iteration vulnerability that can lead to Denial of Service conditions by exhausting system resources through unauthenticated requests.
Erlang OTP contains integer underflow and memory allocation vulnerabilities in its erts modules, which could allow remote attackers to cause excessive memory consumption or system instability.
The SP Page Builder extension for Joomla contains an SQL injection vulnerability that allows an authenticated administrator to execute arbitrary database commands.
An incorrect authorization vulnerability in JFrog Artifactory allows authenticated attackers to perform unauthorized actions, potentially leading to data compromise.
An incorrect authorization vulnerability in several Progress Software appliances allows authenticated attackers to escalate privileges to root, resulting in full system compromise.
An integer overflow vulnerability in the GIMP file-fits plugin can be triggered by processing a malicious file, potentially leading to arbitrary code execution.
NVIDIA NeMo Framework for Linux contains an OS command injection vulnerability allowing local authenticated attackers to execute arbitrary commands.
An expired pointer dereference flaw exists in the Linux kernel across multiple versions of Red Hat Enterprise Linux, potentially allowing local privilege escalation.
An access control vulnerability in the Ghost Robotics Vision 60 mobile application (version 5.5.0) could allow unauthorized parties to interact with the device.
An authorization bypass vulnerability exists in the Containerized Data Importer (CDI) component of Red Hat OpenShift Virtualization 4.
The zip-lib package is vulnerable to directory traversal via path validation caching during the extraction process, allowing attackers to bypass security checks.
The Xendit Payment plugin for WordPress contains an unauthenticated broken access control vulnerability that allows unauthorized actions within the plugin.
A vulnerability in the facil.io MIME parser allows for an out-of-bounds read, potentially leading to a denial of service via server crash.
An infinite loop vulnerability in the facil.io MIME parser allows unauthenticated attackers to trigger a denial of service condition.
An out-of-bounds read vulnerability in the facil.io HTTP chunked transfer encoding parser can lead to memory corruption and a server crash.
The ShipTime: Discounted Shipping Rates WordPress plugin is vulnerable to sensitive data exposure due to a lack of proper authorization checks.
The Ebook Store WordPress plugin is susceptible to unauthenticated sensitive data exposure due to missing authorization checks in its handling of requests.
The Stripe For WooCommerce plugin is vulnerable to broken access control, allowing unauthenticated attackers to perform unauthorized actions.
A price manipulation vulnerability exists in the Booking and Rental Manager plugin for WordPress, allowing unauthenticated attackers to modify booking costs via improper input validation.
A broken access control vulnerability in the Post My CF7 Form plugin for WordPress allows unauthenticated attackers to perform unauthorized actions due to missing authorization checks.
A broken access control vulnerability in the CoCart plugin for WordPress allows unauthenticated attackers to perform unauthorized actions due to missing authorization checks.
The Paid Member Subscriptions plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) flaw, allowing unauthenticated attackers to manipulate user-controlled keys.
The Byteflows Travel & Hotel Booking plugin for WordPress is susceptible to an unauthenticated sensitive data exposure vulnerability, allowing unauthorized access to restricted system information.
NitroShare Desktop is vulnerable to path traversal, which allows an unauthenticated remote attacker to perform unauthorized file operations via the LAN file transfer server.
A broken authentication vulnerability in the Hide My WP Ghost WordPress plugin allows unauthorized access due to improper user-controlled key validation.
A broken access control vulnerability in the Thrive Product Manager WordPress plugin allows unauthenticated users to perform unauthorized actions due to missing capability checks.
A Server Side Request Forgery (SSRF) vulnerability exists in the Simple Link Directory Pro WordPress plugin, allowing unauthenticated attackers to perform unauthorized requests.
A Server Side Request Forgery (SSRF) vulnerability exists in the FormCraft plugin for WordPress, allowing unauthenticated attackers to perform unauthorized requests.
An authenticated privilege escalation vulnerability exists in JFrog Artifactory, allowing users with administrative provisioning to escalate their privileges.
LibRaw version 0.21 contains buffer overflow vulnerabilities in the stretch and fuji_rotate functions that could lead to memory corruption or arbitrary code execution.
SQLite 3.41 contains a use-after-free vulnerability in the JSON parsing logic that can be triggered by malicious payloads to cause crashes or code execution.