CVE-2026-20349
Cisco Secure Firewall ASA and FTD contain a heap inspection vulnerability due to improper memory clearing, which is currently being exploited in the wild.
Critical vulnerabilities, curated daily for security professionals
WordPress ecosystem plugins account for the bulk of yesterday's critical disclosures, with unauthenticated file upload and access control flaws reported in Pods, ProSolution WP Client, ARForms, Link Library, and RapiSafe. The day brought 28 critical CVEs (CVSS 9.0+), up 17% from the prior day's 24, and 79 high-priority CVEs, up 52% from 52. Notable entries include CVE-2026-19598 (CVSS 9.8) in sc0ttkclark Pods, CVE-2026-16098 (CVSS 9.8) in ProSolution WP Client, and CVE-2026-64695 (CVSS 9.8) in Apple macOS, alongside three critical issues in the SiYuan note-taking application (CVE-2026-73043, CVE-2026-73046, CVE-2026-73052). Remote code execution and authentication or authorization bypass are the recurring patterns, concentrated in web-facing content management and collaboration software. Patch data is not yet recorded for any of the 107 CVEs in this set, so teams should track vendor advisories directly; three CVEs affecting Cisco ASA/FTD, Metabase, and the Windows Ancillary Function Driver for WinSock have confirmed exploitation.
Immediate action: Prioritize the actively exploited issues in Cisco Secure Firewall ASA/FTD, Metabase, and the Windows Ancillary Function Driver for WinSock, then audit WordPress installations for Pods, ProSolution WP Client, ARForms, Link Library, and RapiSafe and update or disable affected plugins. Apple macOS systems should be checked against the latest security update for CVE-2026-64695. Patch status is unconfirmed for this set, so verify fix availability against each vendor's advisory before scheduling remediation windows.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Cisco Secure Firewall ASA and FTD contain a heap inspection vulnerability due to improper memory clearing, which is currently being exploited in the wild.
Metabase contains a critical SQL injection vulnerability in the password reset endpoint that allows unauthenticated remote attackers to gain full administrative control over the instance.
A use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock is currently being exploited in the wild.
The RapiSafe WordPress plugin is vulnerable to unauthenticated arbitrary file deletion via path traversal, which may lead to remote code execution.
The Pods WordPress plugin is vulnerable to unauthenticated privilege escalation due to an authorization bypass in the AJAX router.
The ProSolution WP Client WordPress plugin is vulnerable to unauthenticated arbitrary file deletion via path traversal, potentially leading to remote code execution.
The Link Library WordPress plugin contains a path traversal vulnerability in the ll_delete_link_fields function, allowing unauthenticated attackers to delete arbitrary files on the server.
The ARForms WordPress plugin is vulnerable to PHP Object Injection via deserialization of untrusted input, potentially allowing code execution if a POP chain is present in the environment.
SiYuan versions before 3.7.4 contain a remote code execution vulnerability in the Template calculation operator, allowing execution of arbitrary code via injected malicious templates.
The SiYuan CheckAuth middleware fails to enforce rate limiting or account lockout for HTTP Basic Authentication, allowing unauthenticated attackers to brute-force the workspace access code.
A stored cross-site scripting vulnerability in SiYuan allows authenticated attackers to execute arbitrary JavaScript by injecting malicious markup into attribute-view field names.
The ProSolution WP Client WordPress plugin is vulnerable to unauthenticated arbitrary file upload due to insufficient validation of file extensions and publicly exposed nonces.
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.
A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
The Solace Extra plugin for WordPress is vulnerable to unauthorized data modification and loss due to a missing capability check on the import_zip() function.
SiYuan before v3.7.4 is vulnerable to stored Cross-site Scripting via improperly escaped database menu metadata, allowing execution of arbitrary code due to Electron's insecure configuration.
SiYuan before v3.7.4 contains a stored Cross-site Scripting vulnerability in the attribute-view select option color field, allowing arbitrary JavaScript execution.
The Frontend Admin by DynamiApps plugin for WordPress contains a privilege escalation vulnerability due to an improper authorization check, allowing unauthenticated attackers to gain administrative access.
An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause unexpected system termination.
Pandora is vulnerable to path traversal during TAR archive extraction, allowing attackers to overwrite arbitrary files on the host system.
The Tenda AC10 router is vulnerable to an authentication bypass in the `R7WebsSecurityHandler` function, allowing unauthenticated remote attackers to gain unauthorized access.
SiYuan versions before 3.7.4 are vulnerable to stored cross-site scripting via the setAttrViewColWidth API, which can lead to arbitrary code execution within the Electron renderer.
SiYuan versions before 3.7.4 allow arbitrary code execution via malicious PDF annotations that trigger script execution in the PDF renderer with Node.js access.
SiYuan versions before 3.7.4 are susceptible to cross-site scripting in the unicode2Emoji function, allowing arbitrary code execution in the renderer.
TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has an uncontrolled recursion vulnerability publicly reported in the issue tracker. Any caller that passes untrusted TOML to from_toml risks a stack over
In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without data area") restricted the implied bcc[0] length exception to responses without
In the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read in broadcast Gap ACK blocks A broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its data area. tipc_get_gap_ack_blks() only verifies that the record's len field is self-consistent with
SQLite 3.41 has a use-after-free vulnerability exists in the expression evaluation logic. The sqlite3ReleaseTempReg function improperly releases temporary register resources, and the subsequent exprComputeOperands function continues to access the already freed register memory. By supplying a malicio
The Newsletters WordPress plugin fails to restrict classes during unserialization of form data, allowing unauthenticated attackers to inject arbitrary PHP objects.
The Templately plugin for WordPress is vulnerable to Remote Code Execution due to unrestricted file uploads, allowing authenticated attackers to execute arbitrary code.
The custom tag module in ImpressCMS contains a vulnerability that allows authenticated administrators to execute arbitrary PHP code.
The Query Wrangler plugin for WordPress is susceptible to Remote Code Execution via an unrestricted file upload vulnerability, which can be exploited by authenticated users.
A heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthenticated remote attacker to execute arbitrary code via a crafted network request.
The Object Sync for Salesforce WordPress plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter in its REST API.
The Royal Addons for Elementor plugin for WordPress is vulnerable to Server-Side Request Forgery, allowing authenticated attackers to perform unauthorized requests from the server.
A SQL injection vulnerability in Tenable Security Center allows an authenticated attacker to access unauthorized database information.
The Login & Register Forms WordPress plugin contains an improper authentication vulnerability that allows unauthenticated attackers to hijack user accounts via manipulated password reset requests.
A critical elevation of privilege vulnerability exists in the Microsoft Malware Protection Engine, allowing attackers to gain system-level administrative access.
Microsoft PowerShell is affected by a command injection vulnerability due to improper neutralization of special elements, which can allow an authorized local attacker to execute arbitrary code.
The WCPOS plugin for WooCommerce is vulnerable to code injection via the thermal template engine, allowing authenticated administrators to execute arbitrary code on the underlying server.
An incorrect authorization vulnerability in CrateDB allows an authenticated user to perform unauthorized actions within the distributed database.
The Iptanus File Upload WordPress plugin before 5.1.8 is vulnerable to unauthenticated SQL injection, allowing attackers to execute arbitrary SQL queries.
The Real Estate Manager Pro plugin for WordPress is susceptible to privilege escalation, allowing low-privileged authenticated users to gain elevated administrative permissions.
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient path validation in the create_link_item function.
The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL injection via the _gallery_order_{post_id} parameter, allowing authenticated users with high privileges to manipulate database queries.
The CubeWP Framework WordPress plugin before 1.1.31 is vulnerable to SQL injection via unvalidated AJAX parameters, allowing authenticated subscribers to access or manipulate database content.
The WP Travel Engine plugin for WordPress contains an authorization bypass vulnerability, allowing unauthenticated attackers to perform unauthorized actions via the affected plugin components.
The Infility Global plugin for WordPress is susceptible to a stored cross-site scripting (XSS) vulnerability via the /cf7_record log endpoint, allowing for arbitrary script execution.
The Bookly plugin for WordPress is vulnerable to stored cross-site scripting via the bookly_speed_up_update_addons AJAX action, allowing unauthenticated attackers to execute arbitrary scripts.
The Autopay plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input, potentially allowing execution of malicious scripts.
The WPLP Cookie Consent plugin for WordPress contains a Stored Cross-Site Scripting vulnerability in the 'regionArray' parameter, which can be exploited to execute unauthorized scripts.
The Invisible Anti-Spam & CAPTCHA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter, allowing for the potential execution of malicious scripts.
The Online Booking & Scheduling Calendar for WordPress by vcita plugin is vulnerable to stored cross-site scripting via the business_id parameter in all versions up to and including 4.6.0.
The WP Directory Kit WordPress plugin contains an SQL injection vulnerability in its AJAX actions, allowing authenticated subscribers to execute arbitrary SQL commands.
The AutoNetTV Relay WordPress plugin fails to perform authentication checks during scheduled tasks, allowing unauthenticated attackers to obtain administrator session cookies.
The BricksForge WordPress plugin is vulnerable to account takeover because it fails to verify user identity when processing password change requests in specific form configurations.
An improper privilege management vulnerability exists in Dell Wyse Management Suite (WMS), allowing a local authenticated user to escalate privileges.
The JSON plugin in Apache Struts is susceptible to an uncontrolled resource consumption vulnerability that may lead to denial of service.
The WP MAPS PRO WordPress plugin is vulnerable to uncontrolled resource consumption due to a missing capability check in an AJAX action, allowing unauthenticated attackers to cause a denial of service.
Dell Wyse Management Suite (WMS) versions prior to 2605.0.2 contain an unrestricted file upload vulnerability that may allow an authenticated attacker to execute arbitrary code.
Dell Wyse Management Suite (WMS) versions prior to 2605.0.2 contain an unrestricted file upload vulnerability that may allow an authenticated attacker to execute arbitrary code.
The Solace Extra WordPress plugin before 1.6.1 lacks capability checks in AJAX actions, allowing authenticated subscribers to modify site settings and delete content.
The PAX Technology Q80 terminal contains an improper link resolution vulnerability during AIP file parsing that may allow an unauthenticated attacker to achieve remote code execution.
A signature verification bypass vulnerability exists in the PAX Technology Q80 application installer, which could allow an attacker to execute arbitrary code.
A missing authorization vulnerability in the getgrav grav-plugin-api allows authenticated users to perform unauthorized actions via the ReportsController.
An improper privilege management vulnerability in the getgrav grav-plugin-api allows high-privileged users to bypass API key scopes via the InvitationsController.
Laravel Socialite's Facebook provider is vulnerable to an authentication bypass via replay of OIDC id_tokens due to missing nonce claim validation in the getUserByOIDCToken function.
Tenable Security Center contains a privilege escalation flaw allowing users with Security Manager roles to modify users outside their assigned groups.
The Pandora analysis tool is vulnerable to a denial-of-service attack through the processing of malformed Direct Access Archive (DAA) files.
AppFlowy-Cloud contains a SQL injection vulnerability within the qcuiknote feature, allowing authenticated users to manipulate database queries.
The user-space system-call verifier in Zephyr RTOS contains a memory-safety vulnerability in the logging subsystem.
Eclipse Theia contains multiple vulnerabilities related to insecure component loading and handling, potentially leading to full system compromise.
A vulnerability in IBM Db2 Mirror for i allows an unauthenticated, remote attacker to gain control of system or configuration settings through external manipulation.
A path traversal vulnerability exists in IBM Db2 Mirror for i, allowing an unauthenticated remote attacker to perform unauthorized file operations on the system.
LB-LINK X-PRO 1.0.22-20231206 contains hard-coded credentials, allowing unauthenticated remote access to management interfaces.
LB-LINK X-PRO 1.0.22-20231206 contains hard-coded credentials, allowing unauthenticated remote access to management interfaces.
A signature verification flaw in the @fastify/jwt plugin allows authenticated users to potentially bypass security controls.
Akaunting is susceptible to missing authorization and improper privilege management, allowing an authenticated user to perform unauthorized actions.
Devolutions PowerShell Universal contains a code injection vulnerability in the settings feature that can be exploited by authenticated users.
FileBrowser is affected by an authentication bypass vulnerability due to improper handling of case sensitivity, potentially allowing unauthorized access.
Compliance-trestle is vulnerable to code injection and improper template engine neutralization, allowing potential arbitrary code execution.
Datavane TIS is vulnerable to XML External Entity (XXE) injection via the doEditWorkflow endpoint, potentially leading to information disclosure.
Budibase server is affected by an authorization regression related to S3 presigned URLs, allowing unauthorized access.
SiYuan versions prior to 3.7.4 are vulnerable to a lack of proper restrictions on authentication attempts, potentially allowing attackers to conduct brute force attacks against the application.
SiYuan versions prior to 3.7.4 contain an authentication bypass vulnerability involving the websocket implementation, allowing unauthenticated remote access.
The @fastify/multipart library for Fastify is susceptible to uncontrolled resource consumption, which can lead to denial of service conditions through malicious multipart form-data requests.
The @fastify/multipart library fails to properly clean up or limit resources during multipart form data parsing, leading to potential denial of service.
A path traversal vulnerability in IBM Db2 Mirror for i allows an unauthenticated remote attacker to read sensitive files from the underlying system.
IBM Db2 Mirror for i contains an improper authentication vulnerability that may allow unauthenticated remote attackers to gain unauthorized access to sensitive information.
IBM Db2 Mirror for i is susceptible to an uncontrolled recursion vulnerability, which could allow an unauthenticated remote attacker to cause a denial of service.
IBM Db2 Mirror for i contains a path traversal vulnerability that could allow an unauthenticated remote attacker to access sensitive files outside of the intended directory.
Netatalk contains an integer underflow vulnerability in its file server suite that can be exploited by authenticated users to achieve arbitrary code execution or cause service crashes.
The golang.org/x/image/vp8l library is vulnerable to a memory allocation error when processing VP8L encoded images, which can lead to a denial of service via memory exhaustion.
ZeroBrew versions 0 through 0.3.1 are vulnerable to remote code execution due to a lack of integrity verification during the download process.
Evergreen contains a SQL injection vulnerability that may allow unauthenticated attackers to execute unauthorized database queries.
The Online Shopping System by code-projects is vulnerable to SQL injection, which may allow unauthenticated attackers to manipulate database queries.
Jinher OA version 1.0 contains a vulnerability involving SQL injection and improper neutralization of special elements, allowing unauthenticated attackers to query the database.
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System version 1.0, which allows unauthenticated attackers to execute arbitrary database queries.
An out of bounds write vulnerability exists in the process-image management functionality of KUNBUS piControl versions 0 through 2.6.2, which may allow local authenticated attackers to corrupt memory.
A race condition vulnerability in the configuration and process-image management of KUNBUS piControl versions 0 through 2.6.2 may allow local authenticated attackers to disrupt system operations.
SourceCodester Simple Client Management System 1.0 is vulnerable to SQL injection, allowing unauthenticated remote attackers to compromise database integrity.
The alldatacenter alldata application is vulnerable to insecure deserialization, which could allow unauthenticated remote attackers to execute unauthorized operations.
Tenable Security Center versions prior to 6.9.0 contain an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands on the underlying host.
The PAX Technology Q80 XCB Daemon contains a missing authentication vulnerability, allowing unauthenticated adjacent attackers to access critical functions.
The Cortex MCP server (neuro-cortex-memory) prior to version 3.17.1 is vulnerable to the inclusion of functionality from an untrusted control sphere.
Johnson Controls Airwall is susceptible to an external control of file name or path vulnerability, potentially allowing unauthorized file manipulation.
A hard-coded cryptographic key vulnerability in Johnson Controls Airwall enables local cryptanalytic attacks, potentially compromising data confidentiality.