CVE-2026-16812
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
Critical vulnerabilities, curated daily for security professionals
Google Chrome accounted for the largest single cluster of critical vulnerabilities disclosed yesterday, alongside remote code execution flaws in the CodeIgniter4 PHP framework and several third-party web applications. The brief covers 41 critical vulnerabilities (up 21% from 34) and 74 high-priority vulnerabilities (up 21% from 61), for a total of 115 tracked CVEs. Notable entries include CVE-2026-17656 and CVE-2026-17670 (CVSS 9.6) in Google Chrome, CVE-2026-63223 (CVSS 9.8) in codeigniter4 CodeIgniter4, and CVE-2026-67208 (CVSS 9.8) in somta Juggle. Network security infrastructure also features prominently, with confirmed exploitation reported against Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS. Vendor patch data was unavailable for the tracked set at publication, so teams should verify fixed versions directly against vendor advisories before scheduling remediation.
Immediate action: Prioritize the three network edge and management products with confirmed exploitation (Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS), then push Chrome and Chrome for iOS updates through managed browser channels. Web application teams should review CodeIgniter4 deployments for CVE-2026-63223. Patch availability is reported at 0% for this set, so confirm fixed builds against vendor advisories and apply documented mitigations where no update exists yet.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
A hard-coded password vulnerability in Cisco Secure Firewall Management Center allows unauthenticated attackers to potentially bypass security controls.
A sensitive information disclosure vulnerability exists in Fortinet FortiOS, allowing unauthenticated attackers to access restricted system data.
An unauthenticated remote code execution vulnerability exists in somta Juggle through 1.6.0 due to exposed H2 database consoles with default credentials.
A use after free vulnerability in Ozone in Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
A use after free vulnerability in the Views component of Google Chrome allows a remote attacker to perform a sandbox escape after compromising the renderer process.
CodeIgniter4 versions prior to 4.7.4 fail to properly validate file extensions during upload, potentially allowing remote attackers to execute arbitrary code.
Spikster contains a missing authentication vulnerability in its API routing, allowing unauthenticated remote attackers to access approximately 50 sensitive endpoints.
Insufficient validation of untrusted input in the Dawn component of Google Chrome on Android allows a remote attacker to perform a sandbox escape via a crafted HTML page.
Insufficient input validation in the ANGLE component of Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
An inappropriate implementation in Google Chrome for iOS allows a remote attacker to perform a sandbox escape via a crafted HTML page.
Insufficient input validation in the ANGLE component of Google Chrome allows an attacker who has already compromised the renderer process to perform a sandbox escape.
Google Chrome contains an input validation flaw in Chromecast that allows a remote attacker to achieve a sandbox escape through a crafted HTML page after compromising the renderer process.
An integer overflow vulnerability in the QUIC implementation of Google Chrome allows a remote attacker to perform a sandbox escape if they have previously compromised the renderer process.
Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
The Realtyna Organic IDX plugin + WPL Real Estate for WordPress is vulnerable to unauthenticated arbitrary file uploads due to missing validation and static API credentials.
Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153.
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
The LazyOwn C2 framework contains default credentials in its source code, allowing unauthenticated remote attackers to gain operator level access to the dashboard.
Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
Incorrect boundary conditions in the Audio/Video: cubeb component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service, allowing unauthenticated attackers with network access to gain unauthorized system access.
In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) is enabled in Tenant A, an attacker can reuse the registration flow by changing the hostname or tenant identifier to Tenant B, even when Tenant B has signup disabled at the UI leve
VMware vCenter contains a directory traversal vulnerability in the Syslog server, which may allow an unauthenticated attacker with network access to execute arbitrary code on the system.
IBM Langflow OSS contains an improper input validation vulnerability in its PythonREPL sandbox implementation, allowing authenticated attackers to perform code injection.
A missing authentication flaw in the LazyOwn Socket.IO event handler allows unauthenticated remote attackers to execute arbitrary commands within the C2 process.
IBM webMethods Integration is vulnerable to unauthenticated remote code execution via deserialization of untrusted data in the WmServiceMock package.
IBM Langflow OSS is susceptible to unauthenticated remote code execution due to an incomplete blocklist of dangerous environment variables in the MCP stdio launcher.
DMS+ (Non-Mobile) contains hardcoded credentials that allow unauthenticated remote attackers to gain full administrative control over the device.
IBM Langflow OSS is vulnerable to code injection, allowing an authenticated remote attacker to execute arbitrary code due to improper control of user-supplied input.
IBM App Connect Enterprise is vulnerable to path traversal, allowing unauthenticated remote attackers to write arbitrary files to the system via specially crafted URL requests.
SolarWinds Web Help Desk contains a SAML authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access if SAML 2.0 is enabled.
A critical SQL injection vulnerability in UMAI Vision Traffic Analysis System allows unauthenticated attackers to execute arbitrary SQL commands via the application.
IBM HMC management systems are vulnerable to OS command injection, allowing unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of the header but never caps elem_size against the destination s
An SQL injection vulnerability in the Crocus DeviceInfoMapper.xml file allows remote, unauthenticated attackers to execute arbitrary SQL commands and escalate privileges.
An SQL injection vulnerability in the Crocus RecordStateMapper.xml file allows remote, unauthenticated attackers to execute arbitrary SQL commands and escalate privileges.
A SQL injection vulnerability in Wgcloud 3.6.4 allows unauthenticated remote attackers to escalate privileges via the PortInfoMapper.xml file.
A heap-based buffer overflow in the schreibfaul1 ESP32-audioI2S library allows for potential code execution or denial of service via malformed input during character encoding conversion.
A use-after-free vulnerability in the jsonCacheInsert function of SQLite 3.41 may lead to application crashes or arbitrary code execution.
Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value
A vulnerability in bytebot-ai allows an unauthenticated attacker to execute arbitrary code via a crafted path provided to the computer_write_file function.
A stack buffer overflow in the Google Chrome V8 engine allows remote attackers to execute arbitrary code within the sandbox via a crafted HTML page.
A use after free vulnerability in the V8 engine of Google Chrome allows remote attackers to perform unauthorized operations via a crafted HTML page.
A use after free vulnerability in the Loader component of Google Chrome allows remote attackers to perform unauthorized operations via a crafted web page.
A use after free vulnerability exists in the V8 engine of Google Chrome, potentially allowing an unauthenticated remote attacker to execute arbitrary code.
A use after free vulnerability exists in the Autofill component of Google Chrome, which may allow an unauthenticated remote attacker to execute arbitrary code.
A use after free vulnerability exists in the Document Object Model (DOM) implementation of Google Chrome, potentially allowing an unauthenticated remote attacker to execute arbitrary code.
A use after free vulnerability exists in the Input component of Google Chrome, potentially allowing for arbitrary code execution.
A use after free vulnerability in the Views component of Google Chrome on Mac could lead to arbitrary code execution.
A use after free vulnerability in the Extensions component of Google Chrome may allow for arbitrary code execution.
A use after free vulnerability exists in the V8 engine of Google Chrome, potentially allowing for arbitrary code execution.
A use after free vulnerability exists in the V8 engine of Google Chrome, potentially allowing for arbitrary code execution.
A use after free vulnerability exists in the PDFium component of Google Chrome, potentially allowing for arbitrary code execution.
A use after free vulnerability exists in the Enterprise component of Google Chrome, potentially allowing for arbitrary code execution.
A use after free vulnerability exists in the Views component of Google Chrome on Linux, potentially allowing for arbitrary code execution.
A use after free vulnerability exists in the Sync component of Google Chrome, potentially allowing for arbitrary code execution.
A use after free vulnerability exists in the V8 engine of Google Chrome, potentially allowing for arbitrary code execution.
A heap buffer overflow vulnerability in the Codecs component of Google Chrome may allow for arbitrary code execution.
A heap buffer overflow vulnerability exists in the WebRTC component of Google Chrome, potentially facilitating arbitrary code execution.
A use after free vulnerability exists in Google Chrome for iOS, which may allow a remote attacker to execute arbitrary code via a crafted web page.
A use after free vulnerability exists in the PDFium component of Google Chrome, which may allow a remote attacker to execute arbitrary code.
A use after free vulnerability exists in the Dawn component of Google Chrome, potentially allowing a remote attacker to execute arbitrary code.
A use after free vulnerability exists in the Views component of Google Chrome, which could allow a local attacker to execute arbitrary code.
A use after free vulnerability exists in the Updater component of Google Chrome on macOS, potentially allowing for arbitrary code execution.
A use after free vulnerability in the Compositing component of Google Chrome may permit arbitrary code execution when processing malicious content.
A type confusion vulnerability in the WebAudio component of Google Chrome allows a remote attacker to execute arbitrary code via a crafted HTML page.
An inappropriate implementation in the WebAudio component of Google Chrome allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page.
An inappropriate implementation flaw exists in the ANGLE graphics engine component of Google Chrome on Android, potentially allowing for unauthorized system impacts.
An out of bounds read vulnerability exists in the ANGLE graphics engine of Google Chrome, which could be leveraged to cause memory access errors or potential system impact.
An integer overflow vulnerability in the libxml library used by Google Chrome allows remote attackers to potentially cause memory corruption via specially crafted web content.
A race condition exists in the Skia graphics library within Google Chrome on Mac, which could allow a remote attacker to perform unauthorized actions via a specially crafted web page.
A type confusion vulnerability in the V8 JavaScript engine of Google Chrome allows a remote attacker to trigger memory corruption via a specially crafted web page.
An inappropriate implementation flaw in the AdFilter component of Google Chrome allows a remote attacker to bypass security controls via a specially crafted web page.
Google Chrome DevTools contains an input validation vulnerability that may allow an unauthenticated, remote attacker to execute arbitrary code via a crafted interaction.
Google Chrome contains an insufficient policy enforcement vulnerability in its USB handling component, which may be exploited by an unauthenticated, remote attacker.
Google Chrome WebXR contains a use-after-free vulnerability that may allow an unauthenticated, remote attacker to execute arbitrary code.
An object lifecycle vulnerability exists in the WebRTC component of Google Chrome prior to version 151, which may allow for memory corruption and arbitrary code execution.
Insufficient policy enforcement in the DevTools component of Google Chrome prior to version 151 could lead to a security bypass or unintended access.
An inappropriate implementation in the Enterprise component of Google Chrome prior to version 151 can lead to security policy bypasses or unintended system behavior.
An inappropriate implementation vulnerability exists within the Safebrowsing component of Google Chrome on Mac, potentially allowing a policy bypass.
An inappropriate implementation vulnerability exists within the Scheduling component of Google Chrome, which could result in a total technical impact.
An inappropriate implementation vulnerability exists within the Passwords component of Google Chrome, which could lead to significant security impacts.
An inappropriate implementation vulnerability exists within the Frame component of Google Chrome, potentially allowing for unauthorized actions.
A type confusion vulnerability in the V8 engine of Google Chrome allows an attacker to cause memory corruption or execute arbitrary code.
An inappropriate implementation vulnerability in the Chromoting component of Google Chrome on Linux could lead to unauthorized system access.
The Realtyna Organic IDX plugin for WordPress contains an arbitrary file upload vulnerability that allows authenticated users to execute malicious code on the server.
The Online Scheduling and Appointment Booking System WordPress plugin contains a SQL injection vulnerability that allows unauthenticated attackers to access sensitive database information.
Kamaji, a hosted control plane manager for Kubernetes, contains vulnerabilities involving improper access control and isolation that could lead to unauthorized system access.
An integer overflow in the open62541 UA_Variant arrayDimensions computation allows a remote attacker to trigger an out of bounds write.
Improper input validation in the authentication component of Eaton Tripp Lite series PADM firmware allows unauthenticated remote attackers to bypass authentication and gain privileged access.
A cross site websocket hijacking vulnerability due to origin validation errors in openclaw-dashboard allows remote attackers to compromise the application.
The Toptech RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface, allowing for unauthorized root-level access to the underlying embedded system.
Wolf CMS versions up to 0.8.3.1 contain an unrestricted file upload vulnerability in the FilemanagerController, which allows authenticated users to execute arbitrary code on the server.
Wolf CMS versions through 0.8.3.1 are susceptible to an authorization bypass vulnerability in the BackupRestoreController due to an incorrect comparison, allowing unauthorized administrative actions.
A Cross-Site Request Forgery vulnerability in Leantime allows unauthenticated attackers to perform unauthorized actions due to missing middleware protection.
A security flaw in the Samba Active Directory Domain Controller within Red Hat Enterprise Linux allows authenticated users to perform LDAP filter injection and bypass authorization checks.
IBM App Connect Enterprise is vulnerable to OS Command Injection, allowing an adjacent attacker to execute arbitrary commands on the underlying host.
An authentication bypass vulnerability in Serendipity allows an authenticated user to impersonate other accounts via username collision, leading to unauthorized access.
CentreStack is affected by an SQL injection vulnerability via the X-Glad-Filter header, allowing low-privileged authenticated attackers to compromise the database.
Eaton Tripp Lite series PADM firmware contains an OS command injection vulnerability in the session management interface, allowing authenticated users to escalate privileges.
The RO CSVI extension for Joomla is susceptible to Cross-Site Request Forgery (CSRF), which could allow an attacker to perform unauthorized actions on behalf of an authenticated administrator.
GoAccess is vulnerable to memory allocation errors and numeric conversion issues, which can be triggered by a remote attacker to cause a denial of service.
The dssrf-js package by HackingRepo is vulnerable to an improper neutralization of equivalent special elements, allowing for potential security bypasses in Node applications.
The swarms package by kyegomez is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied inputs, which can be exploited by unauthenticated network attackers.
CentreStack by Gladinet is vulnerable to an authentication bypass in its API, allowing unauthenticated attackers to perform unauthorized actions on critical functions.
IBM WebSphere Application Server is vulnerable to a deserialization of untrusted data attack, which could allow an authenticated user to perform remote code execution.
Leantime is vulnerable to a Server-Side Request Forgery (SSRF) flaw, allowing an authenticated attacker to perform unauthorized requests.
Kanboard is affected by a Server-Side Request Forgery (SSRF) vulnerability caused by improper filtering of input using hexadecimal IP notation.
IBM Db2 is vulnerable to a stack-based buffer overflow, which could allow a local attacker to execute arbitrary code or cause a system crash.
A buffer overflow vulnerability exists in the IBM PowerVM Hypervisor, potentially allowing an authenticated local attacker to cause a denial of service or impact system integrity.
IBM WebSphere Application Server Liberty is susceptible to improper privilege management, which could allow a remote attacker to gain unauthorized access via a crafted request.
The malach-it boruta library for Elixir contains an improper isolation vulnerability, potentially allowing unauthorized access or privilege escalation.
A Cross-Site Request Forgery (CSRF) vulnerability exists in Softtr Information E-Commerce Pack, allowing unauthorized actions on behalf of a victim.
Improper input validation in the session management interface of Eaton PADM firmware allows an authenticated administrator to execute arbitrary OS commands.
A directory traversal vulnerability in knowns-dev/knowns allows unauthenticated attackers to access unauthorized files via crafted path values in the get_doc and update_doc tools.