CVE-2026-58704
A logic error in the Google Pixel cellular modem component allows for unauthenticated, adjacent privilege escalation without user interaction.
Critical vulnerabilities, curated daily for security professionals
Netcore's NBR200V2 router accounts for five of the day's critical entries, including CVE-2026-94097 at CVSS 10, alongside a cluster of OrdaSoft Joomla Gallery flaws rated 9.3 to 9.4. The brief covers 15 critical CVEs (down 32% from 22 the prior day) and 72 high-priority CVEs (down 1% from 73), from 87 total disclosures. Beyond the Netcore set, CVE-2026-55366 (CVSS 9.8) affects Google Android and CVE-2026-86462 (CVSS 9.1) affects the Apache Airflow FAB provider, where the authentication layer is the exposed component. The pattern favours internet-facing network equipment and web application extensions, which matters most to organisations running consumer-grade routers at branch sites and Joomla-based public web properties. Six CVEs carry confirmed active exploitation, including CVE-2026-76460 in Cisco Identity Services Engine and CVE-2026-58704 in Google Pixel. Restrict management interfaces on edge routers to trusted networks, and treat Joomla extension code and Airflow web endpoints as priority review targets.
Immediate action: Prioritise Netcore NBR200V2 routers, Cisco Identity Services Engine, Acronis Backup, and Joomla installations running OrdaSoft Gallery, along with Android and Pixel device fleets, since these carry either maximum-severity ratings or confirmed exploitation. Confirm fix status in each vendor's advisory before scheduling remediation, and where no fix is documented, restrict network access to the affected management interfaces in the interim.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A logic error in the Google Pixel cellular modem component allows for unauthenticated, adjacent privilege escalation without user interaction.
An authentication bypass vulnerability in the Cisco Identity Services Engine API allows unauthenticated, remote attackers to gain unauthorized access to the management interface.
Acronis Backup plugins for cPanel and Plesk contain an insecure file permissions vulnerability that allows authenticated users to perform local privilege escalation.
A race condition in the Linux kernel crypto subsystem allows local users to cause state inconsistencies via concurrent writes to an af_alg socket.
A memory corruption vulnerability in the Linux kernel netfilter bridge component allows for out of bounds writes during ARP packet processing.
A vulnerability in the Linux kernel TLS implementation allows for improper handling of zero-length records during recvmsg processing, potentially leading to unauthorized system state manipulation.
The OrdaSoft Joomla Gallery extension allows authenticated privileged users to perform remote code execution by uploading malicious files due to insufficient file validation.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 18, analysis completed Sep 18.
The Apache Airflow FAB provider fails to invalidate existing database-backed session cookies when a user password is changed via the Admin user-edit PATCH endpoint, allowing session persistence.
A buffer overflow vulnerability in the Netcore NBR200V2 router allows remote attackers to execute arbitrary code via the wan_num argument in the vlan_load_form_uci function.
A remote buffer overflow vulnerability in the Netcore NBR200V2 WAN VLAN Reconfiguration function allows authenticated attackers to execute arbitrary code.
A code injection vulnerability in the OrdaSoft Joomla Gallery extension allows authenticated, privileged users to achieve remote code execution via the updateOSGallery task.
An unauthenticated SQL injection vulnerability exists in the OrdaSoft Joomla Gallery extension for Joomla due to improper input sanitization in the search functionality.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 21.
A logic error in the Android IP Multimedia Subsystem allows for an unauthenticated, remote authentication bypass and escalation of privilege.
Netcore NBR200V2 is vulnerable to unauthenticated command injection via the /www/cgi-bin/network_tools endpoint, allowing remote attackers to execute arbitrary system commands.
A command injection vulnerability in the restore.cgi component of Netcore NBR200V2 allows remote attackers to execute arbitrary system commands via the QUERY_STRING parameter.
A command injection vulnerability in the Netcore NBR200V2 LAN IP Configuration Handler allows remote attackers to execute arbitrary system commands via the ipv4 argument.
The Netcore NBR200V2 Traceroute Diagnostic Feature is vulnerable to remote command injection via the url argument, allowing attackers to execute arbitrary system commands.
A command injection vulnerability in the Netcore NBR200V2 firmware upgrade CGI endpoint allows remote attackers to execute arbitrary system commands via manipulation of the QUERY_STRING argument.
A stack-based buffer overflow in the D-Link DIR-868L authentication handler allows unauthenticated remote attackers to execute arbitrary code via the id parameter in webfa_authentication.cgi.
A stack-based buffer overflow in the Comfast CF-N1-S web management interface allows unauthenticated remote attackers to cause a crash or potentially execute arbitrary code.
A critical remote code execution vulnerability exists in REDCap survey routing and data import logic, allowing unauthenticated attackers to execute arbitrary code via manipulated HTTP requests.
NivoCart versions up to 2.4.0 contain an arbitrary file upload vulnerability in the File Manager multi() endpoint, allowing authenticated attackers to execute arbitrary PHP code.
The Unlimited Elements For Elementor WordPress plugin fails to perform capability checks on AJAX actions, allowing authenticated attackers to perform unauthorized PHP object deserialization.
Disclosed Sep 16 without a CVSS score; scored Sep 18, analysis completed Sep 18.
The WP Import Export Lite plugin fails to validate PHP functions applied to exported data, enabling authenticated users with export permissions to achieve remote code execution.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 18, analysis completed Sep 18.
Apache ZooKeeper quorum TLS fails to perform proper peer hostname verification in FIPS-mode, allowing unauthorized peers to join the quorum, participate in leader election, and access replication flows.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 18, analysis completed Sep 18.
A vulnerability in the Apache Airflow FAB provider allows deactivated user accounts to maintain access via existing, unexpired API tokens, bypassing administrative account suspension.
A SQL injection vulnerability exists in the QCMS content detail page due to improper input sanitization in the self_Tmp function, allowing remote unauthenticated attackers to query the database.
SourceCodester Drug Recommendation System 1.0 is vulnerable to unauthenticated SQL injection via the id parameter in /drug_recommender/Admin/edit_user.php, allowing full database compromise.
SourceCodester Drug Recommendation System 1.0 contains an unauthenticated SQL injection vulnerability in the /Admin/edit_symptom.php file via the id parameter, allowing remote database compromise.
The Internship Management System version 1.0 contains a time-based blind SQL injection vulnerability in the admin login form, allowing unauthenticated attackers to extract database information.
An unauthenticated SQL injection vulnerability in the Internship Management System 1.0 allows remote attackers to execute arbitrary database queries via the password parameter in employer/login.php.
The code-projects Internship Management System version 1.0 is vulnerable to an unauthenticated time-based blind SQL injection in the login.php file via the password parameter.
A SQL injection vulnerability in SourceCodester Online Reviewer Management System 1.0 allows unauthenticated remote attackers to execute arbitrary SQL commands via the id parameter.
A SQL injection vulnerability in SourceCodester Online Reviewer Management System 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands via the id parameter.
A SQL injection vulnerability exists in SourceCodester Online Reviewer Management System 1.0 within the courseID parameter of btn_functions.php, allowing unauthenticated remote code execution.
SourceCodester Online Reviewer Management System 1.0 contains an unauthenticated SQL injection vulnerability in the Course parameter of the btn_functions.php file, allowing remote data manipulation.
The OrdaSoft Joomla Gallery extension is vulnerable to an authenticated SQL injection flaw via unsanitized input in the saveGallery function, allowing database compromise by privileged users.
DedeCMS versions up to 5.7.118 contain a code injection vulnerability in the plus/mytag_js.php file, allowing remote attackers to execute arbitrary code via the aid parameter.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
A buffer overflow vulnerability in the afpfs component allows remote attackers to cause kernel memory corruption by inducing a user to connect to a malicious server.
A memory corruption vulnerability in the BioStar BIOS Update Utility kernel driver allows local attackers to perform arbitrary memory writes via a crafted IOCTL request.
A memory corruption vulnerability in the BioStar Temperature Monitor Utility kernel driver allows local attackers to perform arbitrary memory writes via a crafted IOCTL request.
BioStar VIVID LED DJ version 4.0.2411.1500 contains a write-what-where vulnerability in the BS_LED64.sys IOCTL handler, which may allow local attackers to gain elevated system privileges.
A memory corruption vulnerability in the BioStar VALKYRIE AURORA kernel driver allows local attackers to perform arbitrary memory writes via a crafted IOCTL request.
NivoCart versions up to 2.4.0 contain a predictable password reset token vulnerability in the forgotten.php endpoint, allowing unauthorized administrative account access.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
An out-of-bounds write vulnerability in multiple Apple platforms allows for memory corruption when processing maliciously crafted web content.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 21.
A logic error in the Android kernel initialization policy creates a permission bypass, enabling local escalation of privilege without requiring user interaction.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 21.
A missing bounds check in the Android kernel's video processing unit leads to an out-of-bounds write, enabling local privilege escalation without user interaction.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 21.
A use-after-free vulnerability caused by improper locking in the Android kernel allows for local escalation of privilege.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 21.
A use-after-free vulnerability in the fpc_tee_hal.c component of the Android kernel allows for local privilege escalation without user interaction or elevated execution privileges.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
A memory handling vulnerability in Apple operating systems allows a local attacker to cause system termination or kernel memory corruption.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
A sandbox escape vulnerability in Apple iOS, iPadOS, and macOS allows a malicious application to bypass security restrictions and execute actions outside its intended environment.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 21.
A logic error in the Android kernel allows for a permission bypass, potentially enabling local escalation of privilege without user interaction.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
A memory handling vulnerability in Apple products allows a maliciously crafted video file to cause application termination or process memory corruption.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
A memory handling vulnerability in multiple Apple operating systems allows a local application to cause system termination or write to kernel memory.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
A race condition in multiple Apple operating systems allows a local application to cause system termination or kernel memory corruption through improved state handling flaws.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
A vulnerability in Apple macOS allows an application to trigger an unexpected system termination due to insufficient authentication checks.
Disclosed Sep 17; published with a limited analysis after repeated re-checks found no further public detail.
Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in the wake_up_set.cgi endpoint, which allows attackers to corrupt program memory through crafted MAC and ID input.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
An authentication flaw in the Sign In With Apple flow allows malicious applications to gain unauthorized access to a user's Apple Account.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
A memory safety vulnerability in Apple macOS allows a local application to trigger unexpected process termination or unauthorized disclosure of process memory due to an out-of-bounds read error.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
A local attacker can cause system termination or kernel memory disclosure by mounting a maliciously crafted exFAT volume due to an out-of-bounds write vulnerability.
The Apache MINA CompressionFilter class fails to limit the size of inflated data, allowing for memory exhaustion through highly compressed inputs.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 18, analysis completed Sep 18.
A remote attacker who controls a container registry can redirect a client's token request to a malicious host, resulting in the unauthorized disclosure of registry credentials.
The Forminator Forms WordPress plugin allows authorized users to execute arbitrary code via insecure deserialization of XML-RPC requests.
The SAML Single Sign On WordPress plugin fails to validate identity linking criteria, allowing unauthenticated attackers to impersonate any WordPress user, including administrators.
Disclosed Sep 17; published with a limited analysis after repeated re-checks found no further public detail.
Netcore NR268 firmware version 1.7.121109 contains an integrity verification flaw in mtd_write that allows attackers to bypass signature validation and load unauthorized firmware images.
Disclosed Sep 17; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an authenticated low-privileged attacker to achieve a full system takeover via network access.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Client Bundle of Oracle WebCenter Enterprise Capture allows a low privileged, network-based attacker to compromise the application.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A security flaw in the Oracle PeopleSoft Enterprise PeopleTools Report Distribution component allows authenticated attackers to gain full control of the application.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in Oracle WebCenter Sites allows a low privileged, network-based attacker to fully compromise the application via HTTP.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Fusion Middleware Control Framework allows authenticated attackers with low privileges to compromise the application via HTTP.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Alert component of Oracle E-Business Suite allows low-privileged, authenticated attackers to compromise the system via HTTP.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Marketing component of Oracle E-Business Suite allows a low privileged attacker to achieve full system takeover via network access.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Report Manager component of Oracle E-Business Suite allows a low privileged attacker to achieve full system takeover via network access.
The Tripzzy WordPress plugin fails to perform authorization checks in an AJAX action, allowing unauthenticated attackers to permanently delete arbitrary comments.
A file upload vulnerability in the Photo Gallery, Sliders, Proofing and Themes WordPress plugin allows authenticated users to achieve remote code execution via improper file extension validation.
The Import and export users and customers WordPress plugin contains a privilege escalation flaw allowing users with create_users capability to promote accounts to administrator during CSV imports.
The Import and export users and customers WordPress plugin contains an improper privilege management flaw that allows users with create_users capability to promote others to administrator.
The generateInvoicePDF function in vas3k TaxHacker up to 0.8.5 is vulnerable to unauthenticated Server-Side Request Forgery and local file read due to improper input sanitization of the businessLogo argument.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 18, analysis completed Sep 18.
The Apache Airflow FAB provider fails to validate OAuth token audience claims, allowing attackers with tokens from other applications to impersonate users.
A remote code execution vulnerability exists in openEQUELLA due to an unsandboxed FreeMarker template configuration, allowing authenticated attackers to execute arbitrary system commands.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 18, analysis completed Sep 18.
An unauthenticated information disclosure vulnerability exists in Apache ZooKeeper due to missing ACL checks during SetWatches reconnect replay operations.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 18, analysis completed Sep 18.
A missing authorization flaw in Apache ZooKeeper allows unauthenticated remote attackers to delete arbitrary empty persistent znodes via the deleteContainer opcode.
A critical improper access control vulnerability in D-Link DIR-X1860 and DIR-X1860Z routers allows unauthenticated attackers on the local network to change administrative passwords and hijack devices.
A SQL injection vulnerability exists in the makeCriteria function of the drogonframework drogon ORM component, allowing remote attackers to execute arbitrary SQL commands via the filter argument.
A SQL injection vulnerability exists in the Mapper::orderBy function of the drogonframework drogon ORM Mapper component, allowing remote attackers to execute arbitrary SQL commands.
A command injection vulnerability in the Cookie Handler of the Feiyu Star Router allows authenticated remote attackers to execute arbitrary commands via the session_id parameter in /send_order.cgi.
An unauthenticated path traversal vulnerability exists in the 03-lovepreetSingh MCP create_file function, allowing remote attackers to write arbitrary files to the server filesystem.
A server-side request forgery vulnerability in the NonceGeek dim-sum-app Deno backend allows unauthenticated attackers to exfiltrate service role keys and gain full administrative access.
A hard-coded credential vulnerability exists in aiyiyi121 SxDevOps versions 1.0 and 1.1, allowing remote, unauthenticated attackers to access the system via the Settings Handler component.
A hard-coded credential vulnerability exists in the ensure_default_superuser function of aiyiyi121 SxDevOps versions 1.0 and 1.1, allowing for remote exploitation.
Exim versions prior to 4.100.1 contain an out-of-bounds write vulnerability when utilizing the Proxy-Protocol with an attacker-controlled proxy.
getID3 contains an OS command injection vulnerability in shell-out handlers that fail to properly escape filenames, allowing attackers to execute arbitrary commands.
The Canva Mobile App for HarmonyOS fails to restrict headers returned to external origins in privileged WebViews, potentially allowing session access by unauthorized parties.