CVE-2009-0238
Microsoft Office Remote Code Execution - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's disclosures center on network infrastructure and enterprise utilities, with critical remote code execution flaws affecting Totolink routers and LG IP device management software. Critical CVEs increased to 2 (up 100% from yesterday) and high-priority CVEs rose to 61 (up 97%), reflecting a substantially heavier disclosure volume. Notable critical issues include CVE-2026-7037 (CVSS 9.8) in the Totolink A8000RU router and CVE-2026-42363 (CVSS 9.3) in the LG GV-IP Device Utility. Attack patterns skew toward remote code execution and authentication weaknesses in network-edge devices, alongside exploitation activity targeting Microsoft SharePoint, Apache ActiveMQ, and SimpleHelp. With patch availability at 0% for the disclosed set, defenders should prioritize compensating controls and network segmentation while vendor fixes are pending.
Immediate action: Prioritize Totolink A8000RU and LG GV-IP Device Utility deployments for isolation and monitoring, and accelerate review of SharePoint, Apache ActiveMQ, PaperCut, SimpleHelp, and JetBrains TeamCity instances given confirmed exploitation. With no vendor patches available for today's disclosures, apply network segmentation, restrict management interfaces, and increase logging on affected systems until fixes ship.
Microsoft Office Remote Code Execution - Active in CISA KEV catalog.
Microsoft SharePoint Server Improper Input Validation Vulnerability - Active in CISA KEV catalog.
Apache ActiveMQ Improper Input Validation Vulnerability - Active in CISA KEV catalog.
Kentico Xperience Path Traversal Vulnerability - Active in CISA KEV catalog.
PaperCut NG/MF Improper Authentication Vulnerability - Active in CISA KEV catalog.
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability - Active in CISA KEV catalog.
JetBrains TeamCity Relative Path Traversal Vulnerability - Active in CISA KEV catalog.
Microsoft Defender Insufficient Granularity of Access Control Vulnerability - Active in CISA KEV catalog.
Marimo Remote Code Execution Vulnerability - Active in CISA KEV catalog.
D-Link DIR-823X Command Injection Vulnerability - Active in CISA KEV catalog.
Samsung MagicINFO 9 Server Path Traversal Vulnerability - Active in CISA KEV catalog.
SimpleHelp Path Traversal Vulnerability - Active in CISA KEV catalog.
SimpleHelp Missing Authorization Vulnerability - Active in CISA KEV catalog.
A remote OS command injection vulnerability exists in the Totolink A8000RU router via the pptpPassThru argument in the setVpnPassCfg function.
GeoVision GV-IP Device Utility 9.0.5 uses insufficient encryption for administrative credentials, allowing attackers to intercept and decrypt sensitive data over local broadcast traffic.
The Highland Software Custom Role Manager plugin for WordPress is susceptible to privilege escalation, allowing unauthorized users to obtain elevated permissions.
Memory safety bugs in Firefox ESR 115 could lead to arbitrary code execution if exploited by an attacker via a malicious webpage.
Memory safety bugs in Firefox ESR 140 could allow a remote attacker to execute arbitrary code or cause a crash via a malicious webpage.
A vulnerability was determined in KLiK SocialMediaWebsite up to 1
A vulnerability was found in Typecho up to 1
A vulnerability was detected in code-projects Employee Management System 1
A security weakness has been identified in the Toowiredd chatgpt-mcp-server, potentially allowing unauthorized access or service disruption.
A vulnerability in CodePanda Source canteen_management_system 1 allows for potential unauthorized actions due to improper security controls.
A security flaw has been found in the itsourcecode Construction Management System 1, potentially leading to unauthorized system access.
A vulnerability has been found in the itsourcecode Construction Management System 1 that could allow for unauthorized data access or system manipulation.
A security vulnerability exists in the itsourcecode Construction Management System 1, potentially exposing the application to unauthorized exploitation.
A security vulnerability exists in the itsourcecode Courier Management System 1, potentially exposing the application to unauthorized exploitation.
A security vulnerability exists in the itsourcecode Courier Management System 1, potentially exposing the application to unauthorized exploitation.
A security vulnerability exists in the SourceCodester Pharmacy Sales and Inventory System 1, potentially exposing the application to unauthorized exploitation.
A security vulnerability exists in the SourceCodester Pharmacy Sales and Inventory System 1, potentially exposing the application to unauthorized exploitation.
A flaw has been found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon
A vulnerability was identified in Tenda F456 1
A weakness has been identified in Tenda F456 1
A security vulnerability has been detected in Tenda F456 1
A vulnerability was detected in Tenda F456 1
A flaw has been found in Tenda F456 1
A vulnerability has been found in Tenda F456 1
A vulnerability was found in Tenda FH1202 1
A vulnerability was determined in Tenda FH1202 1
A security flaw has been discovered in Tenda F456 1
A weakness has been identified in Tenda F456 1
A security vulnerability has been detected in Tenda F456 1
A vulnerability was detected in Tenda F456 1
A flaw has been found in Tenda F456 1
An OS command Injection issue exists in LogonTracer prior to v2
A vulnerability was identified in D-Link DIR-825 3
A security flaw has been discovered in Tenda F456 1
A weakness has been identified in Tenda F456 1
A security vulnerability has been detected in Tenda F456 1
A vulnerability was detected in Tenda F456 1
A flaw has been found in Tenda F456 1
A security flaw has been discovered in Tenda HG3 2
A weakness has been identified in Tenda F456 1
A security vulnerability has been detected in tufantunc ssh-mcp up to 1
Technitium DNS Server before 15
A security flaw has been discovered in D-Link DIR-825 up to 3
A vulnerability was identified in Tenda i9 1
A vulnerability was determined in D-Link DIR-822 A_101
A vulnerability was identified in Linksys MR9600 2
Faleemi Desktop Software 1
iSmartViewPro 1
CEWE Photoshow 6
A security vulnerability has been identified in the Vanna-AI Vanna framework, affecting versions up to 2.
A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd
A vulnerability was detected in PicoClaw up to 0
A security vulnerability has been identified in SmythOS SRE, affecting versions up to 0.
A flaw has been found in 666ghj MiroFish up to 0
A vulnerability has been found in 666ghj MiroFish up to 0
A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec
A security vulnerability has been identified in the Intina47 context-sync software, potentially allowing unauthorized access to synchronized data.
A flaw has been found in AgentDeskAI browser-tools-mcp up to 1
A vulnerability has been found in BidingCC BuildingAI up to 26
A vulnerability was found in choieastsea simple-openstack-mcp up to 767b2f4a8154cca344344b9725537a58399e6036
A weakness has been identified in code-projects Inventory Management System 1
A vulnerability was determined in ShadowCloneLabs GlutamateMCPServers up to e2de73280b01e5d943593dd1aa2c01c5b9112f78
Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local privilege escalation and granting system-level access to the affected software