CVE-2026-56164
Microsoft SharePoint Server contains a vulnerability involving missing authentication for critical functions, allowing unauthenticated remote access.
Critical vulnerabilities, curated daily for security professionals
Enterprise access and collaboration platforms lead the day's disclosures, with SonicWall SMA1000 appliances, Microsoft SharePoint Server, and Fortinet FortiSandbox all carrying confirmed exploitation. Yesterday's disclosures produced 10 critical CVEs, up 150% from the prior day's 4, while high-priority items dropped 70% to 18. On the critical side, CVE-2026-44359 in Meshtastic firmware scores a maximum 10.0, CVE-2026-30623 affects BerriAI LiteLLM at 9.8, and CVE-2026-16242 hits Red Hat's Logging Subsystem for OpenShift at 9.4. AI and LLM infrastructure features prominently across LiteLLM, GPT Researcher, and xszyou Fay, alongside job scheduling (XXL-Job) and Perl web framework (Mojolicious) components. No vendor patches were confirmed available at collection time for this set, so teams should prioritize exposure reduction and monitoring while tracking advisories.
Immediate action: Prioritize internet-facing SonicWall SMA1000 appliances, Microsoft SharePoint and ADFS servers, and Fortinet FortiSandbox deployments, all of which have confirmed exploitation in the wild. No patches were confirmed available for the critical set at collection time, so apply vendor mitigations, restrict external access to management interfaces, and monitor authentication logs for anomalies while updates are pending.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Microsoft SharePoint Server contains a vulnerability involving missing authentication for critical functions, allowing unauthenticated remote access.
A Server-side request forgery (SSRF) vulnerability in the SonicWall SMA1000 Work Place interface allows remote unauthenticated attackers to force the appliance to make unauthorized network requests.
SonicWall SMA1000 appliances are vulnerable to code injection, which can be exploited by an authenticated administrator to execute arbitrary code.
An unauthenticated, easily exploitable vulnerability in the Oracle Payments product of E-Business Suite allows remote attackers to compromise the service via HTTP.
A deserialization of untrusted data vulnerability in Microsoft SharePoint allows an unauthenticated, remote attacker to execute arbitrary code.
An OS command injection vulnerability in FortiSandbox allows unauthenticated attackers to execute unauthorized commands via specifically crafted HTTP requests.
Fortinet FortiSandbox is vulnerable to OS command injection, allowing unauthenticated attackers to execute unauthorized code on the appliance.
Microsoft Active Directory Federation Services is affected by a vulnerability involving insufficient granularity of access control.
The KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that is currently being exploited in the wild.
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` in
A flaw in the Konnectivity proxy-server configuration for hosted control planes allows unauthenticated remote attackers to connect as an agent and manipulate control-plane-to-node traffic.
A code injection vulnerability in the Meshtastic firmware GitHub workflow allows unauthorized execution of attacker-controlled code, leading to potential supply chain compromise.
The Fay framework version 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management interface, allowing unauthenticated attackers to execute arbitrary commands.
LiteLLM versions prior to v1.83.6-nightly and v1.83.7-stable are vulnerable to remote code execution due to improper validation of command configurations for MCP servers.
An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent m
An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go
A Cross Site Request Forgery vulnerability in the xxl-job-admin web application allows unauthenticated attackers to modify Glue IDE shell scripts.
GPT Researcher v3.3.7 is vulnerable to remote code execution when an unauthenticated user interacts with a crafted HTML page to supply a malicious Model Context Protocol configuration.
The FunnelKit WordPress plugin contains a reflected Cross-Site Scripting (XSS) vulnerability that allows unauthenticated attackers to execute malicious scripts in the context of a logged-in user.
Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.
Keras version 3.15.0 is vulnerable to unsafe deserialization of attacker-controlled PyTorch pickle data via the keras.layers.TorchModuleWrapper.from_config method.
Meshtastic firmware contains an improper input validation vulnerability that allows an unauthenticated attacker to cause a denial of service.
The fast-uri library is vulnerable to an interpretation conflict when parsing URIs, which may lead to improper integrity validation.
The SourceCodester Class and Exam Timetabling System version 1.0 is vulnerable to SQL injection, allowing unauthenticated attackers to compromise database integrity.
A SQL injection vulnerability in SourceCodester Class and Exam Timetabling System version 1.0 allows unauthenticated remote attackers to execute arbitrary database queries.
A memory corruption vulnerability in the Linux kernel IPv4 networking stack allows for potential out of bounds writes when using specific packet construction flags.
DBD::File versions before 1.
DBI::ProfileData versions before 1.
Improper authorization in the access request status endpoint in Devolutions Server 2026.
Cross Site Request Forgery vulnerability in andreimarcu linux-server v.
A memory leak vulnerability in EMQ NanoMQ version 0.24.9 allows a remote attacker to trigger a denial of service via the nni_qos_db_set function.
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.
A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.
A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.