CVE-2026-20316
A hard-coded password vulnerability in Cisco Secure Firewall Management Center allows unauthenticated attackers to potentially bypass security controls.
Critical vulnerabilities, curated daily for security professionals
Bouncy Castle's BC-JAVA cryptographic library accounts for four of the day's critical entries, alongside a 9.6-rated flaw in FreeRDP that affects remote desktop deployments across Linux and embedded platforms. The brief covers 16 critical CVEs, down 30 percent from the prior day's 23, and 55 high-priority CVEs, up 28 percent from 43. Notable critical items include CVE-2026-68579 (FreeRDP, CVSS 9.6), CVE-2026-58062 and CVE-2026-59638 (Legion of the Bouncy Castle BC-JAVA, CVSS 9.3 each), and a cluster of Mozilla Firefox memory safety issues at CVSS 9.1 including CVE-2026-16364 and CVE-2026-16370. Attack patterns skew toward remote code execution in client-side and protocol handling code, with browser, RDP client, and WordPress plugin components carrying the bulk of the risk, plus two actively exploited network security appliance flaws in Cisco Secure Firewall Management Center and Fortinet FortiOS. Patch availability data was not published for any of the 71 CVEs at collection time, so teams should treat vendor advisories as the authoritative source for fix status and prioritize inventory checks over patch deployment assumptions.
Immediate action: Prioritize the two actively exploited appliance flaws first: audit Cisco Secure Firewall Management Center and Fortinet FortiOS instances for the affected versions and apply vendor fixes or mitigations promptly. Next, inventory Java applications bundling Bouncy Castle, FreeRDP clients and gateways, and Firefox deployments, since these carry the highest-rated non-exploited issues. No patch availability was recorded for this batch, so check vendor advisories directly to confirm whether fixed builds have shipped before scheduling remediation windows.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A hard-coded password vulnerability in Cisco Secure Firewall Management Center allows unauthenticated attackers to potentially bypass security controls.
A sensitive information disclosure vulnerability exists in Fortinet FortiOS, allowing unauthenticated attackers to access restricted system data.
Bouncy Castle for Java fails to properly bind stapled OCSP responses to the checked certificate, allowing for potential validation bypasses.
Bouncy Castle for Java has an insecure default configuration for the JSSE hostname verifier, which incorrectly enables CN-fallback.
FreeRDP contains a heap-based buffer overflow in the Windows clipboard client, which can be triggered by a malicious RDP server sending an oversized response.
Bouncy Castle for Java and Java LTS versions contain an improper input validation vulnerability where peer values are exponentiated without validation during Diffie-Hellman key agreement.
Bouncy Castle for Java, Java LTS, and FIPS versions are vulnerable to a Name Constraints bypass via trailing dots in rfc822Name and URI fields during certificate validation.
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 153.
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153.
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153.
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Trac
The Wavlink WL-NU516U1 router contains a stack-based buffer overflow vulnerability in the nas.cgi file, which can be triggered by manipulating the CONTENT_LENGTH argument.
A stack-based buffer overflow in the nas.cgi component of Wavlink WL-NU516U1 allows remote unauthenticated attackers to execute arbitrary code via the User1Passwd argument.
An SQL injection vulnerability in PyAthena versions prior to 3.35.4 allows unauthenticated attackers to execute arbitrary SQL commands due to improper quote-escaping in the DefaultParameterFormatter.
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism
Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thorough about the header and layout (magic, version, section offsets, total_size, count and arena_used) but
A vulnerability in Bouncy Castle Java libraries allows for the improper validation of integrity check values, potentially leading to unauthorized operations.
Bouncy Castle for Java contains an improper validation of integrity check values, which could lead to integrity compromise.
Bouncy Castle for Java is susceptible to an improper validation of integrity check values, which may permit unauthorized modification of protected data.
Multiple Bouncy Castle for Java components are affected by an improper validation of integrity check values, potentially impacting data security.
A memory allocation vulnerability exists in the Bouncy Castle BC-JAVA library, allowing unauthenticated attackers to cause a denial of service via excessive memory consumption.
An improper cryptographic signature verification flaw exists in Bouncy Castle BC-JAVA and BC-LTS-JAVA, potentially allowing unauthenticated attackers to bypass signature validation checks.
An uncontrolled recursion vulnerability exists in Bouncy Castle libraries, allowing unauthenticated attackers to trigger stack exhaustion and cause a denial of service.
Bouncy Castle for Java contains a memory allocation vulnerability due to an excessive size value being processed, which can lead to a denial of service.
Bouncy Castle for Java contains an algorithmic complexity vulnerability that can be leveraged by an unauthenticated attacker to cause a denial of service.
Bouncy Castle for Java is vulnerable to memory allocation errors involving excessive size values, which may be exploited by unauthenticated attackers to cause a denial of service.
A vulnerability in Bouncy Castle for Java allows for improper validation of integrity check values, potentially leading to unauthorized data modification.
A vulnerability in Bouncy Castle for Java involving improper verification of cryptographic signatures allows attackers to potentially bypass security controls.
A side-channel vulnerability in Bouncy Castle for Java, specifically an observable discrepancy, allows unauthenticated attackers to potentially leak sensitive information.
A vulnerability in the Bouncy Castle library allows unauthenticated attackers to bypass data authenticity verification due to insufficient checks.
A vulnerability in the Bouncy Castle library allows unauthenticated attackers to bypass integrity checks due to improper validation of integrity check values.
A vulnerability in the Bouncy Castle library allows unauthenticated attackers to bypass cryptographic signature verification.
Bouncy Castle for Java contains an excessive iteration vulnerability that can lead to denial of service conditions.
Bouncy Castle libraries contain an uncontrolled recursion vulnerability that can cause stack overflow errors and denial of service.
Bouncy Castle libraries are susceptible to memory allocation with excessive size values, potentially leading to memory exhaustion and denial of service.
Bouncy Castle libraries are susceptible to a memory allocation vulnerability due to excessive size values, which may lead to denial of service conditions.
Privilege escalation in WebExtensions.
Bouncy Castle for Java contains a memory allocation vulnerability that can be triggered by a remote attacker via user interaction, potentially causing a denial of service.
Bouncy Castle for Java exhibits inadequate encryption strength, which may allow an attacker to compromise the integrity of the data being processed.
A vulnerability in the Linux kernel perf_core component allows local attackers to cause system instability or denial of service by improperly detaching event groups during remove_on_exec.
Use-after-free in the WebRTC: Audio/Video component.
A code signing bypass vulnerability in multiple Apple operating systems allows a maliciously crafted application to execute unsigned or unauthorized code.
A use-after-free vulnerability in the Linux kernel `ksmbd` module occurs when handling deferred file locks during an `SMB2_CLOSE` followed by an `SMB2_CANCEL`.
The better-auth library contains an improper input validation vulnerability due to its reliance on the rou3 router library, which may allow for path normalization bypasses.
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
A deserialization of untrusted data vulnerability exists in Canon Production Printing PRISMAproduction version 6.5 and earlier.
A privilege management vulnerability in ArcadeDB allows authenticated users to perform unauthorized actions due to improper capability checks.
An authorization bypass vulnerability in Vikunja allows authenticated users to access or manipulate data belonging to other principals due to an ID collision flaw.
A vulnerability in the Unisoc NR modem firmware allows for potential denial of service via improper input validation of network traffic.
A vulnerability in the Unisoc modem firmware allows for improper input validation, potentially leading to a denial of service condition.
A vulnerability in the Unisoc modem firmware allows for improper input validation, potentially leading to a denial of service condition.
A vulnerability in the Unisoc modem firmware allows for improper input validation, potentially leading to a denial of service condition.
An improper input validation vulnerability exists in the Unisoc modem firmware, potentially allowing for denial of service conditions.
A vulnerability in the Unisoc modem firmware allows for improper input validation, which may lead to system instability or denial of service.
An improper input validation vulnerability within the Unisoc UDX710 modem firmware could lead to denial of service conditions.
The Unisoc UDX710 modem contains an improper input validation vulnerability that may allow an unauthenticated remote attacker to cause a denial of service condition.
The Wavlink WL-NU516U1 device is susceptible to OS command injection, which could allow an unauthenticated attacker to execute arbitrary commands with high privileges.
ArcadeDB versions prior to 26.7.3 contain an information disclosure vulnerability that allows authenticated users to access sensitive server settings.
ArcadeDB is vulnerable to a missing authentication flaw for critical functions, allowing an authenticated attacker to bypass security controls via the MCP transport.
A heap-based buffer overflow vulnerability exists in FreeRDP due to improper handling of the audio input channel, potentially leading to remote code execution.
Synology Assistant contains an incorrect default permissions vulnerability that could allow a local user to gain elevated privileges or compromise system integrity.
BaserCMS is susceptible to a CSV file injection vulnerability, allowing attackers to inject malicious formula elements into exported CSV files.
The huggingface/transformers library is vulnerable to path traversal, which could allow an attacker to access or manipulate files outside of the intended directory.
An authorization bypass vulnerability in better-auth/passkey allows authenticated users to perform unauthorized actions due to improper validation of user-controlled keys.
The Linux kernel usbnet driver contains an out-of-bounds read vulnerability in the genelink_rx_fixup function due to improper validation of device-supplied packet lengths.
The Linux kernel net1080 USB network driver contains an out-of-bounds read vulnerability in the rx_fixup function due to insufficient validation of packet lengths.
A memory bounds error in the OCPP 1 implementation within Zephyr RTOS allows for potential out-of-bounds read or write operations, which may lead to system instability or service disruption.
The Linux kernel `rtl8723bs` Wi-Fi driver contains a WEP length underflow and out-of-bounds read vulnerability in the `OnAuth()` function.
A buffer overflow vulnerability in the Linux kernel NTFS3 filesystem driver allows for out-of-bounds memory access, potentially leading to privilege escalation or system instability.
A stack-based out-of-bounds write vulnerability in the Linux kernel Bluetooth subsystem allows local attackers to cause memory corruption or privilege escalation.
The Linux kernel `af_key` module fails to initialize the `alg_key_len` field for IPComp states, causing an out-of-bounds read during state cloning.