CVE-2025-62593
Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.
Critical vulnerabilities, curated daily for security professionals
Six maximum-severity flaws in the Fabrik extension for Joomla dominate yesterday's disclosures, alongside remotely reachable defects in TRENDnet and Comfast networking hardware. Twelve critical CVEs (CVSS 9.0+) were published, down 45% from the prior day's 22, while high-priority disclosures held steady at 84 (down 2%). CVE-2026-76604, CVE-2026-76605, and CVE-2026-76606 all carry CVSS 10 ratings in Fabrik, CVE-2026-77946 (CVSS 10) affects the TRENDnet TEW-821DAP access point, and CVE-2026-12710 (CVSS 9.3) affects Google Cloud Application Integration. Web application components (Joomla extensions, WordPress form builders) and internet-facing SOHO network devices account for most of the critical set, a pattern that favors unauthenticated remote access as the primary attack path. No patch information was available for the critical items at collection time, so exposure reduction and monitoring should carry the load until vendor fixes are confirmed; nine CVEs across Microsoft, VMware, Apple, and Zimbra products are under confirmed active exploitation.
Immediate action: Prioritize the actively exploited set first: Microsoft Windows and SharePoint, VMware vCenter and Cloud Foundation, Apple macOS, Zimbra Collaboration, TrueConf Server, Ray, and MLflow. For the critical disclosures, audit Joomla installations for the Fabrik extension and inventory internet-facing TRENDnet and Comfast devices, as no patches were listed at collection time. Where fixes are unavailable, restrict administrative interfaces to trusted networks and increase logging on the affected services until vendor updates are published.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.
A double-free vulnerability in the Windows IKE Extension allows unauthenticated attackers to execute arbitrary code over a network.
VMware vCenter contains a directory traversal vulnerability in the Syslog server, which may allow an unauthenticated attacker with network access to execute arbitrary code on the system.
A weak authentication vulnerability in Microsoft SharePoint allows unauthenticated remote attackers to bypass security controls and access sensitive information.
An improper authentication flaw in Apple macOS Screen Sharing allows unauthenticated network attackers to bypass credentials and gain remote access.
TrueConf Server contains a vulnerability involving missing authentication for critical functions, which allows unauthorized remote attackers to perform sensitive actions.
Zimbra Collaboration (ZCS) is susceptible to remote code execution due to improper neutralization of OS commands.
MLflow contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to reach internal services due to improper validation of redirected URLs.
TrueConf Server is affected by a code injection vulnerability that allows attackers to execute arbitrary code and escape isolated environments.
The WS Form LITE plugin for WordPress is vulnerable to PHP Object Injection via deserialization of untrusted form submission meta values by unauthenticated attackers.
The Fabrik extension for Joomla is vulnerable to unauthenticated remote code execution due to improper control of code generation within the PHP form element.
The Fabrik extension for Joomla contains an unauthenticated SQL injection vulnerability in the list filter condition parameter, allowing for unauthorized database access.
A missing authorization flaw in the QueryEngineTask of Google Cloud Application Integration allowed unauthorized access to sensitive internal data.
The Fabrik extension for Joomla is susceptible to remote code execution through the image element, potentially allowing unauthorized command execution on the server.
A stack-based buffer overflow vulnerability in the Comfast CF-N1-S web management interface allows remote attackers to execute arbitrary code via the timestr or ntp_client_enabled arguments.
A stack-based buffer overflow in the TRENDnet TEW-821DAP NTP Timezone Configuration Handler allows unauthenticated remote attackers to execute arbitrary code via crafted NTP server configuration parameters.
The Fabrik extension for Joomla contains an unauthenticated SQL injection vulnerability in the list model's order parameter, allowing attackers to execute arbitrary SQL commands.
A path traversal vulnerability in the image element of the Fabrik extension for Joomla allows unauthenticated attackers to access or manipulate files on the underlying filesystem.
The Fabrik extension for Joomla contains a missing access control check in the download element, permitting unauthenticated users to perform unauthorized actions.
The Fabrik extension for Joomla is susceptible to code injection via a heredoc terminator breakout in the calc element and a lack of access controls on the onUpdateComment endpoint.
An out-of-bounds access vulnerability in the Linux kernel NVMe subsystem's Flexible Data Placement feature could lead to system instability.
The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection, allowing authenticated attackers with low privileges to execute arbitrary code.
The BOSH CLI tool on Windows is vulnerable to command injection, allowing a remote attacker to execute arbitrary shell commands.
Insufficient policy enforcement in Settings in Google Chrome prior to 151.
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation, allowing unauthenticated attackers to modify product data.
Git for Windows contains a vulnerability involving the exposure of sensitive information to unauthorized actors through an externally controlled reference.
Jet Admin allows an authenticated attacker to perform stored cross-site scripting via the sign-in page's scripts and styles configuration option.
The Basekick-Labs arc database is vulnerable to path traversal, sensitive information exposure, and server-side request forgery due to improper handling of restricted directories.
A buffer overflow was addressed with improved bounds checking.
The Customer Switching WordPress plugin before 2.
A security flaw in docker-socket-proxy fails to properly restrict read access to the Docker API /containers namespace when the CONTAINERS environment variable is configured.
The Security Hardener plugin for WordPress is vulnerable to Missing Authorization, allowing authenticated attackers with low privileges to perform unauthorized administrative actions.
A race condition in the Linux kernel's amdgpu driver's coredump functionality can lead to a slab-out-of-bounds memory access.
Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.
An authorization issue was addressed with improved state management.
An issue in Dede CMS v.
A race condition was addressed with improved state handling.
The mod_auth_openidc Apache module contains out-of-bounds read and write vulnerabilities that can lead to service disruption.
The WP Travel Engine WordPress plugin before 6.
The WWBN AVideo platform contains an authorization bypass vulnerability where the getToken function generates insecure tokens, leading to unauthorized access.
AVideo contains an authentication bypass vulnerability where improper validation of video hash credentials allows for passwordless login as the video owner.
TensorZero contains vulnerabilities involving server side request forgery and improper file access, which could allow external parties to access restricted directories.
A null pointer dereference vulnerability in the kin-openapi Go project may allow an attacker to cause a denial of service via specifically crafted OpenAPI files.
A path traversal vulnerability in the is_path_trusted function of infinite-image-browsing allows unauthenticated attackers to access restricted files.
A missing authorization vulnerability in the Reconmap API allows unauthenticated attackers to access sensitive project and client organization data via the report preview endpoint.
Remote Utilities Host is vulnerable to an incorrect permission assignment for critical resources, which could allow local attackers to escalate privileges.
NLTK is vulnerable to remote code execution via a deserialization flaw in the AllowlistUnpickler component.
The Fabrik extension for Joomla is vulnerable to improper access control, allowing unauthenticated remote attackers to perform unauthorized actions.
The Fabrik extension for Joomla contains an improper access control vulnerability that permits unauthenticated remote attackers to execute unauthorized operations.
The Fabrik extension for Joomla is susceptible to improper access control and path traversal attacks, enabling unauthenticated remote attackers to manipulate files or bypass security.
The Fabrik extension for Joomla is vulnerable to improper access control, allowing unauthenticated attackers to potentially access sensitive information.
SiYuan is affected by a path traversal vulnerability that allows authenticated administrators to delete arbitrary files on the host system.
A cross-site scripting vulnerability exists in the Fabrik extension for Joomla, allowing unauthenticated attackers to execute malicious scripts in a user's browser.
The JoomGallery extension for Joomla is vulnerable to cross-site scripting, which could allow authenticated attackers with administrative privileges to execute malicious scripts.
Combodo iTop is vulnerable to stored cross-site scripting (XSS) which allows authenticated users to execute malicious scripts in the context of other users' sessions.
Combodo iTop contains a cross-site scripting vulnerability that allows an authenticated user with low privileges to execute arbitrary scripts in the context of the application.
Combodo iTop is susceptible to a cross-site scripting vulnerability that allows an authenticated attacker to inject arbitrary scripts into the application.
A cross-site scripting vulnerability in Combodo iTop allows authenticated users with low privileges to execute arbitrary JavaScript in the context of the application.
The chirpmyradio CHIRP software is susceptible to eval injection via specially crafted CSV data, allowing for potential arbitrary code execution.
The hashcat utility fails to properly restrict command-line arguments when parsing restore files, allowing for arbitrary output redirection and potential file write operations.
The better-npm-audit package is vulnerable to OS command injection via the registry flag, potentially allowing local attackers to execute arbitrary commands.
A path traversal vulnerability exists in the DataRecce recce toolkit, allowing unauthenticated attackers to manipulate file paths via external control.
A code injection and unsafe reflection vulnerability exists in the facebookresearch hydra framework, potentially allowing arbitrary code execution.
An insecure deserialization vulnerability in the funstory-ai BabelDOC tool could allow an attacker to execute arbitrary code.
UAC (Unix-like Artifacts Collector) is vulnerable to OS command injection via the run_command.sh script, potentially allowing an attacker to execute arbitrary system commands.
UAC (Unix-like Artifacts Collector) contains an OS command injection vulnerability in command_collector.sh, which may allow an attacker to execute arbitrary commands on the host system.
A vulnerability in the parse_artifact.sh script of UAC (Unix-like Artifacts Collector) allows for OS command injection via improper handling of user-supplied input.
Combodo iTop versions prior to 3.2.3 are susceptible to an information exposure vulnerability allowing authenticated users to access sensitive data.
LXC Incus versions prior to 7.2.0 contain an improper access control vulnerability that may allow authenticated users to perform unauthorized actions.
LXC Incus versions prior to 7.2.0 are vulnerable to an improper access control issue, potentially allowing authenticated users to manipulate the system environment.
A double free vulnerability in strongSwan versions 4.3.3 through 6.0.6 allows authenticated remote attackers to cause a crash or potentially execute arbitrary code.
A path traversal vulnerability in the NLTK FrameNetCorpusReader allows unauthenticated remote attackers to bypass sandbox restrictions via crafted symlinks.
NLTK versions before 3.10.0 suffer from an insecure default configuration, potentially allowing unauthorized access to resources through improper initialization.
A path traversal vulnerability in the NLTK StreamBackedCorpusView allows unauthenticated attackers to perform arbitrary file reads.
The NLTK JSONTaggedDecoder is susceptible to a denial of service attack via uncontrolled recursion when processing maliciously crafted input.
Netty is susceptible to a TLS hostname verification bypass, allowing attackers to perform man-in-the-middle attacks.
Keystone, a content management system for Node, contains vulnerabilities related to improper input validation and incorrect operator usage, potentially leading to denial of service.
Combodo iTop, an IT service management tool, is susceptible to information disclosure due to the use of insufficiently random values for sensitive operations.
Combodo iTop, a web based IT service management tool, contains an observable response discrepancy vulnerability that could lead to unauthorized information disclosure.
Combodo iTop contains a vulnerability involving missing authentication for critical functions, potentially allowing unauthorized access to sensitive information.
Unleash contains an uncontrolled recursion vulnerability that can be triggered by unauthenticated attackers, leading to a denial-of-service condition.
Bluewave Labs Checkmate contains a resource consumption vulnerability that allows unauthenticated attackers to cause denial of service through excessive resource allocation.
Checkmate contains a vulnerability that allows unauthorized actors to access sensitive information due to insufficient protection of credentials and data exposure.
The to_abs_path function in infinite-image-browsing fails to properly resolve symlinks, allowing attackers to escape scanned directory restrictions and access arbitrary files.
Spring AI's MCP Streamable HTTP server transport fails to limit session retention and lacks default authentication, leading to potential resource exhaustion.
A command injection vulnerability in the Tenda CH22 router allows authenticated attackers to execute arbitrary system commands via the formEditFileName function.
A command injection vulnerability in the TRENDnet TEW-821DAP wireless access point allows authenticated attackers to execute arbitrary commands via the ssi interface.
A timing discrepancy vulnerability in the WeeChat client allows remote attackers to cause integrity or availability impacts by exploiting observable timing differences.
A hard-coded credential vulnerability exists in vas3k TaxHacker versions 0.8.0 through 0.8.2, potentially allowing unauthorized access to the application.
A cross-site scripting (XSS) vulnerability in Combodo iTop before version 3.2.3 allows authenticated users to execute malicious scripts via improper input neutralization.
A use-after-free vulnerability in the secure context cleanup handler of FreeRTOS-Kernel versions 10.2.0 through 11.3.0 allows for potential privilege escalation.
FreeRTOS-Kernel contains an out-of-bounds write vulnerability due to missing minimum size validation during secure context allocation.
The FORT-validator Resource Public Key Infrastructure (RPKI) validator contains an origin validation error that can be exploited by authenticated users.
The NLTK library is vulnerable to an integrity check failure when downloading code, which can lead to the execution of untrusted code.
WWBN AVideo contains a cross-site request forgery vulnerability in the releaseVideoNow function that allows unauthorized actions.
Combodo iTop is vulnerable to stored cross-site scripting due to improper neutralization of user-supplied input during web page generation.
The Linux kernel contains a memory management vulnerability in the BPF subsystem that can lead to memory corruption when freeing a BPF red-black tree root.
A locking flaw in the Linux kernel BPF subsystem's zap_pages function can result in a deadlock, leading to a local denial of service.
A use-after-free vulnerability in the Linux kernel configfs component allows local attackers to potentially trigger a system crash or execute arbitrary code.
A use-after-free vulnerability in the Linux kernel BPF filesystem (bpffs) allows local attackers to cause a denial of service or system instability.
Gitea is vulnerable to server-side request forgery (SSRF) due to improper validation of URLs in migration asset downloads, allowing access to internal files and cloud metadata.
In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: validate MAP frame length before ingress parsing When ingress deaggregation is disabled, rmnet_map_ingress_handler() passes the skb straight to __rmnet_map_ingress_handler(), skipping the length validation th.
A logic error in the Linux kernel OCFS2 file system's FITRIM range validation can lead to underflow and memory corruption when processing cluster sizes larger than the block size.
A flaw in the Linux kernel BPF subsystem allows incorrect map-in-map configurations, enabling unauthorized mutation of exclusive maps by unrelated programs.