CVE-2026-9082
Drupal Core SQL Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Oracle dominates Friday's disclosures with multiple near-maximum-severity flaws across REST Data Services, iAssets, and Universal Work Queue, joined by a perfect-score SandboxJS sandbox escape that exposes server-side JavaScript execution. The brief covers 19 critical CVEs, unchanged from the prior day, and 58 high-priority CVEs, a 93% increase over yesterday's 30. CVE-2026-46840 (CVSS 10, Oracle REST Data Services) and CVE-2026-43898 (CVSS 10, SandboxJS) headline the critical set, with CVE-2026-46775 (CVSS 9.9, Oracle REST Data Services) and a string of CVSS 9.8 WordPress plugin flaws including CVE-2026-3655 and CVE-2026-8809 close behind. Remote code execution and authentication bypass patterns predominate, concentrated in enterprise middleware, identity infrastructure, and the WordPress plugin ecosystem. No patches are currently reflected for the disclosed set, so affected operators should prioritize compensating controls and vendor advisory monitoring; five vulnerabilities, including flaws in Drupal Core and GitHub Actions OIDC, have confirmed active exploitation.
Immediate action: Prioritize Oracle REST Data Services, iAssets, and Universal Work Queue instances along with SandboxJS deployments and the affected WordPress plugins, restricting external access and applying compensating controls where exposure exists. With no patches reflected for the disclosed set, monitor vendor advisories closely and expedite remediation for the five actively exploited issues, including Drupal Core and GitHub Actions OIDC, as fixes become available.
Drupal Core SQL Injection Vulnerability - Active in CISA KEV catalog.
LiteSpeed cPanel Plugin Privilege Escalation Vulnerability - Active in CISA KEV catalog.
A supply chain compromise of DAEMON Tools Lite resulted in the distribution of trojanized binaries signed with a legitimate certificate.
GitHub Actions OIDC was exploited to publish malicious npm packages by chaining multiple vulnerabilities, including cache poisoning and token extraction.
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
The OTP Login With Phone Number plugin for WordPress is vulnerable to authentication bypass, allowing unauthenticated attackers to hijack user accounts by exploiting a flawed Firebase verification flow.
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generated SQL without parameterization or validation, making every code path that exposes regConfig to untrusted input a SQL injection sink. This vulnerability is fixed in 8.36.1.
SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that allows unauthenticated attackers to gain root access by submitting the hardcoded credential to the recovery endpoint via HTTP. Attackers can leverage this hardcoded password to enable filtered SSH and Telnet services on the device, resulting in unauthenticated root-level remote access to the underlying system.
The Advanced Custom Fields: Extended plugin for WordPress contains a validation bypass vulnerability that allows unauthenticated attackers to create new administrator accounts.
The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonce field of the wpgmp_local JavaScript object, rendering the check ineffective as an access control mechanism. This makes it possible for unauthenticated attackers to invoke the wpgmp_temp_access_support handler with check_temp=false, which unconditionally creates a new WordPress user with the hardcoded role of administrator via wp_insert_user() and returns a magic login URL that, when visited, calls wp_set_auth_cookie() to fully authenticate the attacker as the newly created administrator, resulting in complete site takeover.
A sandbox escape vulnerability in SandboxJS allows unauthenticated attackers to execute arbitrary host JavaScript code by leveraging an exposed internal runtime callback.
An easily exploitable, unauthenticated remote code execution vulnerability exists in Oracle REST Data Services, allowing full system takeover via HTTPS.
A critical vulnerability in the core of Oracle REST Data Services allows low-privileged attackers to gain full system control via network-based HTTPS exploitation.
A critical vulnerability in the Oracle iAssets component of E-Business Suite allows low-privileged attackers to compromise the product via HTTP.
A critical vulnerability in the Oracle Universal Work Queue component of E-Business Suite allows low-privileged attackers to compromise the product via HTTP.
A critical vulnerability in the core of Oracle REST Data Services allows low-privileged attackers to gain full system control via network-based HTTPS exploitation.
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root.
An unauthenticated, easily exploitable vulnerability in Oracle Hospitality OPERA 5 allows remote attackers to compromise the property services platform via HTTP.
An unauthenticated, easily exploitable vulnerability in the Oracle Payments product of E-Business Suite allows remote attackers to compromise the service via HTTP.
A command injection vulnerability in the Admin Access feature of InHand Networks industrial routers allows remote attackers to gain root privileges.
A command injection vulnerability in the ZeroTier VPN feature of InHand Networks industrial routers allows remote attackers to gain root privileges.
A command injection vulnerability in the WireGuard VPN feature of various InHand Networks devices allows remote unauthenticated attackers to execute arbitrary commands with ROOT privileges.
A command injection vulnerability in the IPSec VPN feature of various InHand Networks devices allows remote unauthenticated attackers to execute arbitrary commands with ROOT privileges.
RustFS uses a hardcoded default secret key for internode RPC authentication, allowing attackers to bypass security if the environment is not explicitly configured.
The WooCommerce Infinite Scroll and Ajax Pagination plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1
A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store, potentially allowing local users to gain elevated system rights.
Use after free in Proxy in Google Chrome prior to 147
The Eupago Gateway For Woocommerce WordPress plugin before 4
Use after free in PDFium in Google Chrome prior to 78
Heap buffer overflow in GPU in Google Chrome prior to 146
Use after free in Dawn in Google Chrome prior to 147
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager)
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security)
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components)
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune
Uninitialized Use in Accessibility in Google Chrome on Windows prior to 147
Race in GPU in Google Chrome on Windows prior to 147
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments
phpMyFAQ before 4
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network
free5GC is an open-source implementation of the 5G core network
free5GC is an open-source implementation of the 5G core network
phpMyFAQ before 4
phpMyFAQ before 4
Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node
Dozzle is a realtime log viewer for docker containers
pyLoad is a free and open-source download manager written in Python
A vulnerability has been found in Tenda F456 1
IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user is logged in
GuardDog is a CLI tool to identify malicious PyPI packages
GitLab has remediated an issue in GitLab EE affecting all versions from 18
pam_usb provides hardware authentication for Linux using ordinary removable media
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files
A buffer overflow was found in grub_font_construct_glyph()
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix MasterStudy LMS masterstudy-lms-learning-management-system allows Blind SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Duplicate Page and Post allows Blind SQL Injection
Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation
Insecure Permissions vulnerability in kvf-admin v1
vllm-project/vllm version 0
An authorization vulnerability in MphRx's Minerva V3
RELATE is a web-based courseware package
TinyMCE is an open source rich text editor
TinyMCE is an open source rich text editor
TinyMCE is an open source rich text editor
TinyMCE is an open source rich text editor
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Path Traversal
Zed is a code editor
Zed is a code editor
Zed is a code editor
Zed is a code editor
Music Player Daemon (MPD) before version 0
The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth
Budibase is an open-source low-code platform
Nautobot is a Network Source of Truth and Network Automation Platform
A local attacker can perform a confusion attack on the cfgparser via a specially crafted file on an USB stick leading to code execution
An issue was discovered in Canonical Multipass before version 1
RVF (formerly Remix Validated Form) provides easy form validation and state management for React
Dalfox is a powerful open-source XSS scanner and utility focused on automation
Anchor is a framework providing several convenient developer tools for writing Solana programs