CVE-2026-9082
Drupal Core SQL Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Thursday's disclosures center on free5GC's open-source 5G core, with three CVSS 10 vulnerabilities affecting the SMF and core components, alongside critical flaws in IBM Aspera, IBM Langflow, and Synology BeeStation OS. Critical CVEs rose to 19 (up 19% from 16), while high-priority disclosures dropped sharply to 30 (down 68% from 95). Notable issues include CVE-2026-44329 (free5GC SMF, CVSS 10), CVE-2026-45087 (Dalfox, CVSS 10), and CVE-2026-46425 (Budibase, CVSS 9.9). Network function virtualization, low-code platforms, and file transfer infrastructure dominate today's attack surface, with authentication bypass and remote code execution as recurring patterns. Patch availability sits at 0% across yesterday's disclosures, warranting compensating controls and exposure reduction until vendor fixes ship.
Immediate action: Prioritize isolation of free5GC deployments, IBM Aspera transfer nodes, and Synology BeeStation devices until vendor patches are released, and audit Pi.Alert and Budibase instances exposed to untrusted networks. With 0% patch availability across yesterday's critical disclosures, defenders should apply network-layer restrictions, monitor for exploitation indicators on the seven KEV-listed products, and track vendor advisories for incoming fixes.
Drupal Core SQL Injection Vulnerability - Active in CISA KEV catalog.
LiteSpeed cPanel Plugin Privilege Escalation Vulnerability - Active in CISA KEV catalog.
A supply chain compromise of DAEMON Tools Lite resulted in the distribution of trojanized binaries signed with a legitimate certificate.
Langflow Origin Validation Error Vulnerability - Active in CISA KEV catalog.
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability - Active in CISA KEV catalog.
GitHub Actions OIDC was exploited to publish malicious npm packages by chaining multiple vulnerabilities, including cache poisoning and token extraction.
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
The free5GC SMF component improperly manages UPI route groups, allowing unauthenticated attackers to perform unauthorized read, write, and delete operations.
Budibase contains an authorization bypass vulnerability in the SCIM API, allowing authenticated users to perform unauthorized CRUD operations on all users and groups.
The free5GC NEF component fails to enforce authentication on the OAM route group, allowing unauthenticated network attackers to access OAM-related functions.
The free5GC NEF component suffers from an authentication bypass on the PFD management route group, allowing unauthenticated attackers to manipulate application data and subscriptions.
Pi.Alert is vulnerable to unauthenticated remote code execution due to improper validation of configuration files, allowing arbitrary Python code execution.
A classic buffer overflow in Synology BeeStation OS AdminCenter allows remote attackers to execute arbitrary code via unspecified vectors.
IBM Langflow OSS is vulnerable to remote code execution during archive extraction due to improper validation of symbolic links.
A buffer overflow in the IBM Aspera High-Speed Transfer component could lead to denial of service, authentication bypass, or remote code execution.
Dalfox contains an unauthenticated remote code execution vulnerability in its REST API server mode due to insecure deserialization of scan options.
Pi.Alert is vulnerable to unauthenticated remote code execution through the configuration save endpoint, allowing arbitrary Python code injection.
An unrestricted file upload vulnerability in the WPify Woo Czech plugin allows unauthenticated attackers to upload and execute a web shell on the server.
OneUptime is vulnerable to a sandbox escape in its Node.js environment due to the improper use of the vm module.
The Gladinet Triofox Cloud Server Agent exposes multiple sensitive endpoints on TCP port 7878, potentially facilitating remote exploitation.
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through <= 5.4.9.
Incorrect Privilege Assignment vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Privilege Escalation.This issue affects WebinarIgnition: from n/a through < 4.08.253.
A stack-based buffer overflow in WOSDefaultHttpModule.dll allows for potential arbitrary code execution when processing long URL paths.
A stack-based buffer overflow exists in WOSDeviceDropFolder.dll when processing long URL paths, potentially allowing remote code execution.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly quickwebp allows Path Traversal.This issue affects QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly: from n/a through <= 3.2.7.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition allows Path Traversal.This issue affects WebinarIgnition: from n/a through < 4.08.253.
Use after free in Codecs in Google Chrome prior to 147
Heap buffer overflow in PDFium in Google Chrome prior to 147
Use after free in Forms in Google Chrome prior to 147
Use after free in Codecs in Google Chrome prior to 147
Use after free in XR in Google Chrome on Android prior to 147
The Crawlomatic Multipage Scraper Post Generator plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2
BentoML is a Python library for building online serving systems optimized for AI apps and model inference
BentoML is a Python library for building online serving systems optimized for AI apps and model inference
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI
Microsoft UFO open-source framework for intelligent automation across devices and platforms
The Active Template Library (ATL) in Microsoft Visual Studio
The Active Template Library (ATL) in Microsoft Visual Studio
Type Confusion in V8 in Google Chrome prior to 147
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3
The GutenBee β Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2
Memory safety bugs present in Firefox 150
Memory safety bugs present in Firefox ESR 140
Memory safety bugs present in Firefox ESR 115
Jenkins Email Extension Plugin 1933
Budibase is an open-source low-code platform
IBM Controller 11
IBM Aspera High-Speed Transfer Endpoint 3
pam_usb provides hardware authentication for Linux using ordinary removable media
Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bulk actions and device update API
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content, media, configuration, users, and system management
@pensar/apex <= 0
LibVNCClient is a library for easy implementation of a VNC client
Budibase is an open-source low-code platform
Tanium addressed an unauthorized code execution vulnerability in Connect
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers