CVE-2026-48172
The LiteSpeed cPanel Plugin contains an incorrect privilege assignment vulnerability (CWE-266) allowing for unauthorized root-level script execution.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Tuesday's brief is led by CVSS 10.0 vulnerabilities in CloudPirates Open Source Helm Charts (CVE-2026-45131, CVE-2026-45132) and Cloud Foundry UAA (CVE-2026-40965), exposing container deployment pipelines and identity services to compromise. Critical CVEs rose sharply to 9 from 2 the prior day (+350%), while high-priority disclosures fell to 46 from 70 (-34%). Additional critical entries include CVE-2026-25879 (CVSS 9.8) in the Langroid framework and CVE-2026-8206 (CVSS 9.8) in the WordPress Kirki plugin, both enabling remote attack paths against widely deployed software. Web application plugins, AI/ML frameworks, and CI/CD identity components dominate the day's disclosures, with remote code execution and authentication weaknesses as the recurring patterns. No patches are currently flagged as available across this set, so affected operators should prioritize compensating controls and monitor vendor advisories; six CVEs are listed in CISA KEV as actively exploited, spanning PAN-OS, Oracle WebLogic, and the LiteSpeed cPanel plugin.
Immediate action: Prioritize CloudPirates Helm Charts, Cloud Foundry UAA, and the actively exploited PAN-OS, Oracle WebLogic, and LiteSpeed cPanel deployments for immediate review and isolation. With no patches currently available for the critical set, apply vendor-recommended workarounds, restrict network exposure of affected services, and increase monitoring on identity and CI/CD systems until fixes ship.
The LiteSpeed cPanel Plugin contains an incorrect privilege assignment vulnerability (CWE-266) allowing for unauthorized root-level script execution.
A supply chain compromise of DAEMON Tools Lite resulted in the distribution of trojanized binaries signed with a legitimate certificate.
An authentication bypass vulnerability exists in Palo Alto Networks PAN-OS GlobalProtect, allowing unauthenticated attackers to forge authentication cookies and establish unauthorized VPN connections.
Oracle WebLogic Server contains an unspecified vulnerability that is currently being exploited in the wild.
A critical supply chain attack involving embedded malicious code in the Nx Console VS Code extension has been identified and is being actively exploited.
GitHub Actions OIDC was exploited to publish malicious npm packages by chaining multiple vulnerabilities, including cache poisoning and token extraction.
The Langroid framework is vulnerable to remote code execution due to insecure handling of SQL produced by large language models.
The Kirki plugin for WordPress is vulnerable to unauthenticated privilege escalation via an account takeover flaw in the password reset process.
A GitHub Actions workflow in CloudPirates Helm Charts executes attacker-controlled code from forks, exposing repository secrets.
A GitHub Actions workflow in CloudPirates Helm Charts exposes Personal Access Tokens and SSH signing keys to untrusted code.
A deserialization vulnerability in Teamwork Cloud and Magic Collaboration Studio allows unauthenticated remote code execution.
Arm Whois 3.11 is vulnerable to a stack-based buffer overflow, allowing remote attackers to execute arbitrary code.
Contest Gallery Pro for WordPress contains an incorrect privilege assignment vulnerability that allows privilege escalation.
The AIWU plugin for WordPress is vulnerable to privilege escalation due to incorrect privilege assignment.
Cloud Foundry UAA inadvertently exposes private EC keys via the public /token_keys endpoint, threatening JWT integrity.
A use-after-free vulnerability in Microsoft Office allows authorized local attackers to elevate privileges.
A deserialization vulnerability in Microsoft SharePoint Server allows authenticated attackers to execute arbitrary code.
A use-after-free vulnerability in Microsoft Office allows authorized local attackers to elevate privileges.
An improper input validation and authorization bypass vulnerability in Kron Tech Single Connect allows for privilege abuse.
Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination with Windows ShellExecuteW fallback extension resolution, leads to arbitrary code execution when a user clicks a crafted entry
A code injection vulnerability in Apache ActiveMQ allows authenticated users to execute management methods with untrusted input via the Jolokia JMX-HTTP interface.
Incorrect default permissions in Apache ActiveMQ allow low-privilege web-login accounts to perform sensitive administrative operations via Jolokia.
A security vulnerability has been identified in the Twig templating engine affecting versions 2 and potentially others.
A critical flaw in Portainer's RBAC layer allows non-admin users with Docker endpoint access to execute privileged operations directly against the Docker daemon.
A security bypass in Portainer allows non-admin users with access to a Docker Swarm endpoint to create or update services with elevated privileges.
A security vulnerability exists in FreePBX, an open-source IP PBX platform, regarding file-based operations.
A vulnerability in the Linux kernel's ksmbd module causes an improper state change during failed multichannel SMB2_SESSION_SETUP requests.
A security vulnerability exists in the Vertex management tool used for tracking and streaming media.
An improper access control vulnerability in Ivanti Neurons for ITSM allows authenticated attackers to escalate privileges to administrative levels.
An SQL injection vulnerability in the Infor E1 Informatics web application allows attackers to execute arbitrary SQL commands.
A security vulnerability has been identified in the D-Link DI-7001 MINI router series.
A use-after-free vulnerability in the Linux kernel's KVM x86 MMIO emulation subsystem allows local privilege escalation.
A heap buffer overflow in the Linux kernel's NFC digital protocol subsystem allows for potential arbitrary code execution.
A use-after-free vulnerability in the Linux kernel's NFC LLCP subsystem results from missing return statements after socket state checks.
An authentication bypass in the Linux kernel's ksmbd SMB3 server allows attackers to hijack durable file handles.
A buffer overflow vulnerability in the Linux kernel's brcmfmac Wi-Fi driver allows out-of-bounds memory access via malformed IF events from the firmware.
An out-of-bounds read vulnerability in the Linux kernel's CIFS client allows a system crash when processing empty or malformed path strings.
A buffer overflow vulnerability in the Linux kernel's wl1251 Wi-Fi driver exists due to missing bounds validation on firmware-supplied packet IDs.
An authentication logic vulnerability in TP-Link range extenders allows unauthenticated attackers on an adjacent network to reset administrator passwords.
An out-of-bounds read vulnerability in the Linux kernel's ksmbd component allows unauthorized memory access via malicious SID structures.
A remote, unauthenticated denial-of-service vulnerability in Klever-Go's Batch.Decompress function allows attackers to trigger massive heap allocations using small payloads.
A deserialization vulnerability in IBM WebSphere Application Server allows remote code execution via crafted HTTP requests.
A memory corruption vulnerability due to a buffer overflow in the Strongbox application may allow for system instability or arbitrary code execution.
An authorization bypass vulnerability in Vadi Corporate Information Systems DigiKent allows attackers to abuse authentication mechanisms.
An SQL injection vulnerability in the Agito Computer Life4All application allows attackers to execute unauthorized database queries.
An SQL injection vulnerability in Agito Computer's Health4All application allows attackers to inject malicious SQL code into database queries.
Megatek Communication Azora Wireless Network Management contains an SQL injection vulnerability due to improper neutralization of special elements in SQL commands.
A security vulnerability has been detected in the H3C Magic B0 router series.
A stack-based buffer overflow in the microtar library's raw_to_header() function can be triggered by crafted TAR archives containing non-null-terminated name or linkname fields.
A security vulnerability has been identified in the IBM i Access Family suite.
A vulnerability has been identified in the UTT HiPER 1200GW router that could allow an attacker to compromise the device.
A vulnerability in the UTT HiPER 1200GW is circulating in security chatter, suspected to be a parser-class TLS flaw affecting the device's communication stack.
Strongbox contains a memory corruption vulnerability due to a missing bounds check.
A Cross-Site Request Forgery (CSRF) vulnerability in Gosoft Software Proticaret E-Commerce allows attackers to perform unauthorized actions on behalf of authenticated users.
An authenticated command injection vulnerability in the SMB server function of the AVTECH DGM1104 allows remote attackers to execute arbitrary system commands.
A flaw in Tauri's URL validation incorrectly classifies remote URLs as trusted local origins.
A high-severity security vulnerability has been identified in the FreePBX open-source IP PBX system.
A stored Cross-Site Scripting (XSS) vulnerability in Process Experience Studio within DELMIA Service Process Engineer allows authenticated, low-privilege users to execute arbitrary scripts in other users' sessions.
A vulnerability in Vegagrup Software Vega Master allows directory indexing, leading to the exposure of sensitive system information to unauthorized users.
A vulnerability in Fastify proxy plugins allows attackers to strip proxy-added headers by manipulating the Connection header.
The PTT Inc. HGS Mobile App contains an "Exposed Dangerous Method or Function" vulnerability, allowing attackers to manipulate user-controlled variables.