CVE-2026-18577
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
Critical vulnerabilities, curated daily for security professionals
A cluster of CVSS 9.8 flaws in the MSI Radix AXE6600 wireless router accounts for most of the day's critical disclosures, with N-able N-central, Apache Tomcat, JetBrains TeamCity, and Progress LoadMaster adding confirmed exploitation in enterprise management and web infrastructure. The brief covers 82 CVEs disclosed yesterday: 27 critical (up 145% from 11) and 55 high priority (down 11% from 62). Named critical issues include CVE-2026-71991 and CVE-2026-71990 (MSI Radix AXE6600, CVSS 9.8) and CVE-2026-15210 (WordPress OTP Login With Phone Number, CVSS 9.1), while CVE-2026-18577 and CVE-2026-18556 (N-able N-central, CVSS 9.5) and CVE-2026-34486 (Apache Tomcat, CVSS 9.5) carry active exploitation. Remote code execution and authentication bypass in network edge devices, remote monitoring platforms, and application servers are the recurring patterns, exposing managed service providers, hosting environments, and WordPress operators. No vendor patches are confirmed available for this set at publication, so prioritize exposure reduction, access restriction, and monitoring while tracking advisories for fixes.
Immediate action: Prioritize internet-facing N-able N-central, Apache Tomcat, JetBrains TeamCity, and Progress LoadMaster instances, restricting management interfaces to trusted networks and reviewing authentication logs for unauthorized access. MSI Radix AXE6600 routers should have remote administration disabled until a firmware update is confirmed. With no patches recorded as available for these disclosures, rely on network segmentation, access controls, and detection until vendor advisories publish fixes.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
N-able N-central is affected by an authentication bypass vulnerability using an alternate path or channel, potentially allowing unauthorized access.
Apache Tomcat contains a vulnerability involving missing encryption of sensitive data, which is currently being actively exploited in the wild.
A critical code injection vulnerability in IBM Langflow OSS allows unauthenticated attackers to gain superuser privileges and execute arbitrary code on the host system.
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
A command injection vulnerability in the TelnetSSH function of the MSI Radix AXE6600 router allows unauthenticated remote attackers to execute arbitrary system commands with root privileges.
A command injection vulnerability in the TelnetSSH function of the MSI Radix AXE6600 router allows unauthenticated remote attackers to execute arbitrary system commands via the SSH configuration interface.
The OTP Login With Phone Number, OTP Verification plugin fails to limit verification attempts, allowing unauthenticated attackers to bypass authentication and hijack accounts.
A command injection vulnerability in the macfilter function of the MSI Radix AXE6600 router allows unauthenticated remote attackers to execute arbitrary system commands with root privileges.
The MSI Radix AXE6600 router firmware contains a command injection vulnerability in the openvpn and macfilter functions, allowing unauthenticated remote attackers to execute arbitrary system commands.
The MSI Radix AXE6600 router firmware contains a command injection vulnerability in the dmz function, which allows unauthenticated remote attackers to execute arbitrary commands with root privileges.
The MSI Radix AXE6600 router firmware contains a command injection vulnerability in the alg function, allowing unauthenticated remote attackers to execute arbitrary commands on the device.
MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability in the portFw function, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.
MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability in the porTrigger function, allowing unauthenticated remote attackers to execute arbitrary commands as root.
MSI Radix AXE6600 firmware v781521 contains a command injection vulnerability in the urlfilter function, allowing unauthenticated remote attackers to execute arbitrary commands as root.
A command injection vulnerability in the MSI Radix AXE6600 router firmware allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the accesscontrol function.
MSI Radix AXE6600 router firmware contains a command injection vulnerability in the wps.cgi interface, allowing unauthenticated remote attackers to execute commands via the pin parameters.
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formLtefotaUpgradeQuectel interface allows unauthenticated remote attackers to execute arbitrary commands as root.
A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the fota_url parameter.
A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the host parameter in the ping interface.
A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the traceroute interface.
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formDebugDiagnosticRun interface allows remote unauthenticated attackers to execute arbitrary system commands with root privileges.
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formUSSDSetup interface allows remote unauthenticated attackers to execute arbitrary system commands with root privileges.
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formSmsManage interface allows remote unauthenticated attackers to execute arbitrary system commands with root privileges.
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formIMEISetup interface allows unauthenticated remote attackers to execute arbitrary commands with root privileges.
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formPinManageSetup interface allows unauthenticated remote attackers to execute arbitrary commands with root privileges.
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formNtp interface allows unauthenticated remote attackers to execute arbitrary commands with root privileges.
D-Link DWR-M961 routers contain a command injection vulnerability in the L2TPv3 configuration interface allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.
D-Link DWR-M961 routers are susceptible to a buffer overflow in the app.cgi interface, which allows unauthenticated remote attackers to execute arbitrary commands or crash the device.
D-Link DWR-M961 routers contain a buffer overflow vulnerability in the quicksetup.cgi interface, allowing unauthenticated attackers to execute arbitrary code via crafted input.
D-Link DWR-M961 routers contain a command injection vulnerability in the app.cgi interface, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.
D-Link DWR-M961 routers are vulnerable to command injection in the /boafrm/formWsc interface, enabling unauthenticated remote attackers to execute arbitrary commands as root.
The zportals WordPress plugin lacks proper file validation, allowing authenticated users to upload arbitrary PHP files and achieve remote code execution.
Dell OpenManage Server Administrator contains an improper authentication vulnerability that may allow unauthorized access to the managed node.
HAPI FHIR is vulnerable to uncontrolled resource consumption and recursion, which can lead to a denial of service condition.
HAPI FHIR is vulnerable to improper input validation, which can lead to uncontrolled resource consumption and denial of service.
Home Assistant core is affected by a missing authorization vulnerability that allows unauthorized parties to perform unauthorized actions.
A missing authorization vulnerability in Home Assistant core permits unauthorized users to execute restricted actions within the platform.
The YayPricing WordPress plugin fails to perform capability checks on REST API routes, allowing authenticated users to modify pricing configurations and disclose private coupon codes.
A buffer overflow vulnerability in the zip archive parser of ClamAV, utilized by Cisco Secure Endpoint, allows unauthenticated remote attackers to cause a denial of service condition.
A double free vulnerability in the ClamAV zip archive parser within Cisco Secure Endpoint allows an unauthenticated, remote attacker to trigger a denial of service condition.
An integer overflow vulnerability in the ClamAV PESpin file parser within Cisco Secure Endpoint allows an unauthenticated, remote attacker to trigger memory corruption and denial of service.
A stack-based buffer overflow in the ClamAV GPT file parser within Cisco Secure Endpoint allows an unauthenticated, remote attacker to trigger memory corruption and denial of service.
A memory corruption vulnerability in the ClamAV PDF parser within Cisco Secure Endpoint allows unauthenticated remote attackers to trigger a denial of service condition.
A memory corruption vulnerability in the ClamAV Mach-O parser within Cisco Secure Endpoint allows unauthenticated remote attackers to trigger a denial of service condition.
A buffer overflow vulnerability in the ClamAV XAR parser within Cisco Secure Endpoint allows unauthenticated remote attackers to trigger a denial of service condition.
The Simply Schedule Appointments WordPress plugin fails to restrict bulk appointment operations, allowing unauthenticated users to retrieve or delete appointment data.
The Theme Demo Import WordPress plugin fails to validate file types during import, allowing administrators to upload executable PHP scripts leading to remote code execution.
The Everest Toolkit WordPress plugin lacks proper file validation during demo-content import, enabling authenticated administrators to upload and execute malicious PHP files.
The INQUIRELAB mcp-bridge-api is vulnerable to command injection, allowing unauthenticated attackers to execute arbitrary system commands.
A vulnerability in the Nexus Repository internal configuration API allows an authenticated user with specific permissions to submit arbitrary realm identifiers via unsafe input handling.
A heap-based buffer overflow vulnerability exists in the GIMP DirectDraw Surface file parser, which could allow for code execution when processing malicious files.
An SQL injection vulnerability exists in Plesk Obsidian, potentially allowing an authenticated user to perform unauthorized database operations.
A stack-based buffer overflow vulnerability in UTT HiPER 1200GW allows authenticated attackers to potentially execute arbitrary code through memory corruption.
An authentication bypass vulnerability in the Grav CMS scheduler-webhook plugin allows unauthenticated attackers to manipulate webhook token checks.
In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix report_work leak on backbone_gw purge batadv_bla_purge_backbone_gw() removes stale backbone gateway entries, but fails to properly handle their associated report_work: - If report_work is running, the purge m.
A Server-Side Request Forgery (SSRF) vulnerability in Flowise through 3.1.4 allows an authenticated attacker to perform unauthorized requests via the fetch links endpoint.
Tobit TeamDavid Webbox contains a Server-Side Request Forgery vulnerability in the search functionality, allowing unauthenticated attackers to supply UNC paths via the pathnameroot parameter.
A path traversal vulnerability in parisneo lollms allows unauthenticated remote attackers to access arbitrary files on the host filesystem.
The Klever-Go blockchain protocol implementation is susceptible to a denial-of-service attack due to improper resource management, allowing unauthenticated attackers to trigger excessive resource consumption.
Klever-Go is susceptible to a NULL pointer dereference vulnerability that may lead to a denial of service.
Klever-Go is vulnerable to uncontrolled resource consumption, which can be triggered by unauthenticated actors to cause a denial of service.
Klever-Go contains an uncontrolled resource consumption vulnerability that can be exploited by unauthenticated remote attackers to cause a denial of service.
HashiCorp Consul is vulnerable to an uncontrolled resource consumption issue due to inadequate limits on resource allocation, potentially leading to denial of service.
The gopacket library is susceptible to out-of-bounds read and uncontrolled resource consumption vulnerabilities during packet processing.
The TONYC Imager library is vulnerable to an out-of-bounds read, potentially allowing an attacker to access unauthorized memory information.
A command injection vulnerability exists within the dracut component of Red Hat Enterprise Linux, potentially allowing arbitrary command execution.
A SQL injection vulnerability in code-projects Task Management System version 1.0 allows for unauthorized database queries and data manipulation.
An improper authentication vulnerability in code-projects Task Management System version 1.0 allows attackers to bypass security controls.
NexTOR_IP_CHANGER is vulnerable to OS Command Injection and execution with unnecessary privileges, allowing local attackers to execute arbitrary system commands.
SourceCodester Simple Doctors Appointment System 1.0 is vulnerable to SQL injection, allowing unauthenticated attackers to manipulate database queries.
SourceCodester Photo Share Website 1.0 contains SQL injection vulnerabilities, enabling unauthenticated remote attackers to manipulate backend database queries.
Klever-Go contains vulnerabilities related to insufficient verification of data authenticity and improper cryptographic signature validation, potentially allowing unauthorized data manipulation.
OpenBao contains an authorization vulnerability that could allow authenticated users to cause a denial of service.
The ATN-B1 CPDLC protocol lacks authentication for data link messages, allowing rogue ground stations to inject misleading clearances and cause pilot confusion.
A vulnerability in ATN-B1 CPDLC allows for the injection of false emergency or status messages, potentially leading to critical operational confusion and improper responses by flight crews.
A link following vulnerability in the go-git library allows attackers to perform unauthorized file operations by exploiting improper link resolution during file access.
A Server-Side Request Forgery (SSRF) vulnerability in the SmartCenter component of the Telefunken TE24553B45V2DZ Smart TV allows local network attackers to trigger unauthorized internal requests.
In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled When init (zeroing) on allocation is requested, for kmalloc() we generally have to zero the full object size even if a smaller size is requested, in order.
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB write in HT_caps_handler() HT_caps_handler() iterates pIE->length bytes and writes into HT_caps.
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() Two IE parsing loops are missing the header bounds checks before they dereference pIE->length: - issue_assocreq() walks pmlmeinfo->network.
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop The IE parsing loop in update_beacon_info() advances by (pIE->length + 2) each iteration but only guards on i < len.
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop The IE parsing loop in OnAssocRsp() advances by (pIE->length + 2) each iteration but only guards on i < pkt_len.
In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping.
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter() Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills pages[], then those pages don't get included in the iterator constructed at the end of the function.
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path In scx_root_enable_workfn(), put_task_struct(p) is called before scx_error() dereferences p->comm and p->pid.
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues fuse_uring_async_stop_queues() might run when the last reference on ring->queue_refs was already dropped.