CVE-2021-39935
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's vulnerability disclosures center on multiple Microsoft Windows and Office flaws alongside critical smart home infrastructure weaknesses in eNet SMART HOME servers. The brief includes 4 critical-severity CVEs (up 33% from Sunday) and 10 high-priority issues (down 63%), reflecting a lighter but more concentrated disclosure day. Notable critical entries include CVE-2026-26369 and CVE-2026-26366, both CVSS 9.8 remote code execution flaws in eNet SMART HOME servers, alongside CVE-2026-1490 (CVSS 9.8) targeting WordPress installations. Microsoft dominates the actively exploited category with six Windows and Office vulnerabilities confirmed under exploitation, while legacy flaws in GitLab, FreePBX, and Notepad++ also appear on the KEV list. No patches are currently available for disclosed vulnerabilities, making compensating controls and network segmentation essential in the interim.
Immediate action: Prioritize reviewing Microsoft Windows and Office systems for exposure to the six actively exploited vulnerabilities, and isolate any eNet SMART HOME server deployments until patches are available. With 0% patch availability, apply network segmentation, restrict unnecessary access, and monitor for exploitation indicators across all affected products.
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Sangoma FreePBX OS Command Injection Vulnerability - Active in CISA KEV catalog.
Sangoma FreePBX Improper Authentication Vulnerability - Active in CISA KEV catalog.
React Native Community CLI OS Command Injection Vulnerability - Active in CISA KEV catalog.
SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
A protection mechanism failure in the MSHTML Framework allows an unauthenticated attacker to bypass security features over a network, potentially leading to unauthorized system access.
Microsoft Windows NULL Pointer Dereference Vulnerability - Active in CISA KEV catalog.
A protection mechanism failure in the Windows Shell allows an unauthenticated attacker to bypass security features over a network connection.
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate their privileges locally on the affected system.
A type confusion vulnerability in the Desktop Window Manager (DWM) allows an authorized local attacker to elevate their privileges to a higher level.
A security feature bypass vulnerability in Microsoft Office Word exists due to reliance on untrusted inputs, allowing an unauthorized local attacker to circumvent security protections.
A memory corruption vulnerability in Apple software was addressed through improved state management to prevent potential exploitation.
Microsoft Configuration Manager SQL Injection Vulnerability - Active in CISA KEV catalog.
Notepad++ Download of Code Without Integrity Check Vulnerability - Active in CISA KEV catalog.
The CleanTalk Anti-Spam plugin for WordPress allows unauthenticated attackers to install arbitrary plugins via PTR record spoofing, potentially leading to remote code execution.
A vulnerability in the Bosch Infotainment ECU's custom protocol allows an attacker with SoC code execution to execute code on the RH850 module and send arbitrary CAN messages.
A privilege escalation vulnerability in the setUserGroup JSON-RPC method allows low-privileged users to gain administrative control by sending crafted POST requests to the management endpoint.
The eNet SMART HOME server utilizes default credentials that remain active post-installation, allowing unauthenticated attackers to gain administrative access to the system.
The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to privilege escalation, which could allow unauthorized users to gain administrative access.
A vulnerability has been identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2, which could allow for unauthorized code execution or data access.
A security flaw has been identified in the Tosei Self-service Washing Machine 4, which could allow for unauthorized access or manipulation of the device's operational functions.
A security weakness has been identified in Total VPN that could allow an attacker to compromise the confidentiality or integrity of the VPN service.
A security flaw has been discovered in Flos Freeware Notepad2 that could potentially allow for unauthorized code execution or system compromise.
A security flaw exists within the Alps Alpine Bluetooth stack utilized in Bosch Infotainment ECUs, potentially allowing for remote exploitation via Bluetooth.
A vulnerability in the Alps Alpine Bluetooth stack used in Bosch Infotainment ECUs poses a risk of remote exploitation, affecting the security of the vehicle's infotainment system.
The Alps Alpine Bluetooth stack in Bosch Infotainment ECUs contains a high-severity flaw that could lead to unauthorized system access or denial of service.
The eNet SMART HOME server version 2 contains a security flaw that could allow for unauthorized access or system manipulation.
A security flaw in yued-fe LuLu UI versions up to 3 allows for potential remote exploitation of the user interface components.