CVE-2026-18577
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
Critical vulnerabilities, curated daily for security professionals
Yesterday's disclosures were dominated by unauthenticated flaws in WordPress commercial plugins and two high-severity Google Chrome vulnerabilities, alongside data platform and AI tooling components including DataLinkDC Dinky and FlowiseAI Flowise. The set totals 52 CVEs: 20 critical (CVSS 9.0+), down 68% from the prior day's 63, and 32 high-priority (CVSS 7.0-8.9), down 61% from 83. Notable entries include CVE-2026-14812 (CVSS 10) in Premium SEO, CVE-2026-11976 (CVSS 10) in MonsterInsights Pro, CVE-2026-67622 (CVSS 9.9) in FlowiseAI Flowise, and CVE-2026-17726 and CVE-2026-17727 (CVSS 9.6) in Google Chrome. Attack patterns skew toward unauthenticated remote code execution and access control failures in web application plugins and appointment booking software, with five vulnerabilities carrying confirmed active exploitation across N-able N-central, Apache Tomcat, IBM Langflow OSS, and JetBrains TeamCity. Patch availability across the set is currently recorded at 0%, so teams should verify vendor advisories directly and apply compensating controls where fixes have not yet shipped.
Immediate action: Prioritize the actively exploited platforms first: N-able N-central, Apache Tomcat, IBM Langflow OSS, and JetBrains TeamCity, all of which are commonly internet-facing management or build systems. Next, audit WordPress installations for the affected Premium SEO, MonsterInsights Pro, Supsystic Pro, and TrueBooker plugins, and update Chrome to the current stable channel. Patch availability is recorded at 0% for this set, so confirm fix status directly with each vendor and restrict external access to affected services until updates are confirmed.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
N-able N-central is affected by an authentication bypass vulnerability using an alternate path or channel, potentially allowing unauthorized access.
Apache Tomcat contains a vulnerability involving missing encryption of sensitive data, which is currently being actively exploited in the wild.
A critical code injection vulnerability in IBM Langflow OSS allows unauthenticated attackers to gain superuser privileges and execute arbitrary code on the host system.
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
Dinky contains an unrestricted file upload vulnerability due to insufficient path validation and a hardcoded, default authentication token, allowing unauthenticated remote code execution.
The Premium SEO WordPress plugin contains a malicious backdoor that enables unauthenticated attackers to create admin accounts, execute code, and inject arbitrary content into the site.
An integer overflow vulnerability in WebGL within Google Chrome on Android enables remote attackers to perform a sandbox escape through a specially crafted HTML page.
An out of bounds write vulnerability in WebGL for Google Chrome on Android permits remote attackers to escape the browser sandbox via a crafted HTML page.
The official MonsterInsights Pro update distribution bucket was compromised, resulting in the delivery of a malicious file that grants an attacker persistent write access and control.
Flowise through 3.1.4 contains an insecure direct object reference vulnerability in its OpenAI Assistants integration that allows authenticated attackers to access data across different workspaces.
Multiple Supsystic Pro plugins were distributed with malicious code via a compromised update server, allowing unauthenticated attackers to steal sensitive data and gain control of affected sites.
The TrueBooker WordPress plugin is vulnerable to account takeover due to improper password reset validation, allowing unauthenticated attackers to reset passwords for arbitrary user accounts.
The TrueBooker WordPress plugin is vulnerable to authorization bypass, allowing unauthenticated attackers to perform unauthorized actions such as changing user passwords.
An improper authentication vulnerability in the OpenReception registration handler allows unauthenticated attackers to hijack user passkeys and gain unauthorized account access.
An improper privilege management vulnerability exists where tenant administrators can escalate their own privileges to platform-wide global administrator status.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE The FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the destination file's data via vfs_clone_file_range() with neither the share-level KSMBD_TREE_CON
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: IPIP tunnel hardware offload is not yet support No driver supports for IPIP tunnels yet, give up early on setting up the hardware offload for this scenario. This patch adds a stub that can be enhanced to add
In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - filter out async aead implementations at alloc krb5_aead_encrypt(), krb5_aead_decrypt() in rfc3961_simplified.c and rfc8009_encrypt(), rfc8009_decrypt() in rfc8009_aes2.c set a NULL completion callback and treat any
In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace period in tcp_ao_destroy_sock Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU") removed the call_rcu() callback from tcp_ao_destroy_sock(), arguing that "the destruction of info/keys is
Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header checks the header scalars and region layout against the file size, but does not validate the array conten
Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries
Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it th
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close Delete-on-close can be completed by deferred or durable handle teardown, where no request work is available. Both the base-file unlink and the ADS xattr removal consequently run wi
A missing authorization vulnerability in the OpenReception setup handler allows unauthenticated attackers to create new global administrator accounts on already configured instances.
A use after free vulnerability exists in the Translate component of Google Chrome, which could allow a remote attacker to execute arbitrary code.
A use after free vulnerability in the V8 JavaScript engine of Google Chrome may permit a remote attacker to execute arbitrary code.
A use after free vulnerability in the WebGL implementation of Google Chrome on Android allows a remote attacker to execute arbitrary code.
A heap buffer overflow vulnerability exists in the CrashReporting component of Google Chrome, potentially allowing remote code execution under specific conditions.
A use after free vulnerability in the GPU component of Google Chrome may allow a remote attacker to execute arbitrary code via a crafted webpage.
A use after free vulnerability in the Skia graphics library within Google Chrome on Android allows for potential remote code execution.
A use after free vulnerability exists in the Payments component of Google Chrome, which could allow a remote attacker to achieve arbitrary code execution via a specially crafted web page.
A use after free vulnerability in the Media component of Google Chrome on Windows could allow a remote attacker to trigger memory corruption and potentially execute arbitrary code.
A use after free vulnerability in the Views component of Google Chrome may allow a remote attacker to cause memory corruption and execute arbitrary code through a specifically crafted website.
Google Chrome contains an inappropriate implementation in the V8 JavaScript engine that could lead to unauthorized system actions.
An out of bounds write vulnerability exists in the V8 engine within Google Chrome, potentially allowing for memory corruption or arbitrary code execution.
An inappropriate implementation vulnerability exists in the V8 engine of Google Chrome, which could allow a remote attacker to compromise the application.
Insufficient validation of untrusted input in the Contextual Tasks component of Google Chrome may allow for remote exploitation.
An integer overflow vulnerability in the V8 JavaScript engine within Google Chrome allows for potential remote code execution.
A use-after-free object lifecycle issue in WebView for Google Chrome on Android allows remote attackers to bypass sandbox protections via a crafted HTML page.
Dgraph is vulnerable to an improper neutralization of special elements in data query logic, potentially allowing unauthenticated attackers to manipulate database queries.
Insufficient validation of untrusted input in the Google Chrome user interface allows for potential remote code execution via a crafted web page.
A sandbox escape vulnerability in Google Chrome for Android exists due to insufficient validation of untrusted input in WebView, which could allow a remote attacker to compromise the browser sandbox.
The Amazon Strands Agents Tools package contains an insecure direct object reference vulnerability that permits authenticated users to bypass authorization controls.
OpenZeppelin Contracts Wizard is susceptible to a code injection vulnerability, which could allow an attacker to influence generated contract components.
WSO2 API Manager contains an XML External Entity (XXE) style vulnerability within its SchemaValidator Mediator due to improper handling of XML document type declarations.
The Frappe framework contains an origin validation error that could allow unauthorized actions through cross-site request forgery or similar origin-based attacks.
The LUCID Vision Labs Arena SDK is vulnerable to DLL search order hijacking, which may allow local attackers to execute arbitrary code with elevated privileges.
The Fedify library is susceptible to server-side request forgery (SSRF) due to improper validation of user-supplied input, allowing unauthorized network requests.
The Nx monorepo solution contains path traversal and link following vulnerabilities, which could allow remote attackers to access or manipulate files outside of intended directories.
A Server-Side Request Forgery vulnerability exists in Efstratios Goudelis Ground Station, allowing unauthenticated attackers to perform unauthorized requests.
The Phoca Commander extension for Joomla contains a path traversal vulnerability that allows an authenticated administrator to access restricted files.
A reflected cross-site scripting vulnerability in the AIL Framework /tag/add_tags endpoint allows authenticated attackers to execute arbitrary scripts in a user session.
Multiple vulnerabilities, including out-of-bounds write and integer overflow, exist in ggml-org llama.cpp, potentially allowing for remote code execution.
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers Three BA session handlers use ffs(ba_data->sta_mask) - 1 to derive a station ID without checking that sta_mask is non-zero.
In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag calculation fails when r01.
Decidim contains an authorization bypass vulnerability allowing authenticated users to access restricted resources via user-controlled keys.