CVE-2026-16812
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
Critical vulnerabilities, curated daily for security professionals
Yesterday's disclosures were dominated by web platform and application infrastructure flaws, with unauthenticated remote code execution and authentication bypass affecting WordPress themes, Joomla extensions, Apache Airflow, and WebPros Plesk. The set includes 34 critical CVEs (CVSS 9.0+), up 48% from the prior day's 23, and 61 high-priority CVEs, up 5% from 58. Notable entries include CVE-2026-65883 (CVSS 10) in the Aimy Captcha-Less Form Guard plugin for Joomla, CVE-2026-58046 (CVSS 9.9) in WebPros Plesk, and CVE-2026-59243 (CVSS 9.8) in the Apache Airflow FAB provider. Beyond web platforms, the day extends into network edge and operational technology with Google Chrome (CVE-2026-16424, CVE-2026-16419), Phoenix Contact CHARX SEC-3150 EV charging controllers, and healthcare integration via the Care Everywhere Gateway. Three CVEs carry confirmed active exploitation (Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS), and with patch data recorded at 0% for this batch, teams should verify fix availability directly with vendors rather than assuming updates are published.
Immediate action: Prioritize internet-facing network edge devices first: Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS all have confirmed exploitation, followed by hosting control planes (WebPros Plesk) and Apache Airflow deployments using the FAB provider. WordPress and Joomla site operators should audit for the affected Streamit theme, Cost Calculator Builder PRO, ASE Pro, and Aimy Captcha-Less Form Guard, and update or disable them. Patch availability is recorded at 0% for this batch, so check vendor advisories directly and apply access restrictions or network segmentation where fixes are not yet published.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
A hard-coded password vulnerability in Cisco Secure Firewall Management Center allows unauthenticated attackers to potentially bypass security controls.
A sensitive information disclosure vulnerability exists in Fortinet FortiOS, allowing unauthenticated attackers to access restricted system data.
The Streamit WordPress theme contains an unauthenticated AJAX vulnerability that allows remote attackers to execute arbitrary PHP functions, leading to account takeover or remote code execution.
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to remote code execution via insufficient sanitization of input passed to a PHP eval function.
The Apache Airflow FAB provider fails to verify Azure AD OAuth ID token signatures, allowing unauthenticated attackers to bypass authentication and gain administrative access via forged tokens.
The Aimy Captcha-Less Form Guard plugin for Joomla contains a PHP object injection vulnerability that enables remote code execution via a forged clfgd field.
A blind SQL injection vulnerability in the Plesk XML-RPC API allows an authenticated low-privileged user to read arbitrary data from the Plesk database.
Care Everywhere Gateway 14.3.10 is vulnerable to remote code execution due to hard-coded credentials in the bundled WildFly management interface, allowing unauthenticated administrative access.
The CHARX JupiCore service in various Phoenix Contact CHARX SEC controllers contains a missing authentication vulnerability, allowing unauthenticated remote attackers to reconfigure charging points.
A use after free vulnerability in the GPU component of Google Chrome on Android allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
The ASE Pro WordPress plugin is vulnerable to remote code execution due to improper input sanitization and a lack of authentication checks in its frontend save handler.
An out of bounds read and write in ANGLE in Google Chrome on Android allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
An incorrect authorization vulnerability in Adobe Campaign Classic allows unauthenticated attackers to achieve arbitrary code execution.
Flyto-core fails to properly validate directory paths in its file-writing modules, enabling unauthenticated path traversal and arbitrary file write operations.
The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin contains a missing authorization flaw that permits unauthenticated users to create administrative accounts.
Axway SecureTransport is vulnerable to server-side template injection in its mail template functionality, allowing authenticated admins to execute arbitrary code.
The flyto-verification service in flyto-core prior to 2.26.7 allows unauthenticated SSRF and secret exfiltration via a vulnerable POST endpoint that improperly handles callback URLs.
A continuation forgery vulnerability in Google ADK allows unauthenticated attackers to forge tool confirmations and execute unauthorized tools.
The logging-operator for Kubernetes fails to properly escape input in Fluentd configuration rendering, allowing authenticated users to execute arbitrary commands within the Fluentd aggregator.
A heap-based buffer overflow in Xlight FTP Server prior to 3.9.5 allows remote unauthenticated attackers to corrupt memory via a malformed SSH client identification string.
The Apache Traffic Server certifier plugin incorrectly validates certificates by relying on attacker-controlled client SNI, leading to potential security misconfigurations.
A vulnerability in Rocket.Chat's SAML SSO implementation allows unauthenticated attackers to bypass authentication and impersonate arbitrary users via forged XML assertions.
A missing authentication vulnerability in the Phoenix Contact CHARX SEC series allows unauthenticated remote attackers to access and potentially compromise the MQTT broker.
The CHARX OCPP Agent service on Phoenix Contact devices lacks authentication, allowing remote attackers to reconfigure backend connections and cause denial of service.
The firmware update process for Phoenix Contact charging controllers lacks cryptographic signature verification, allowing unauthenticated remote attackers to install malicious firmware.
A script execution order flaw during system shutdown causes the firewall to terminate prematurely, exposing internal services to unauthenticated remote attackers.
An improper command neutralization vulnerability allows an unauthenticated remote attacker to execute arbitrary commands as root on the system.
A missing authentication vulnerability in the NASA-AMMOS AIT-DSN Space Link Extension interface allows unauthenticated remote attackers to execute arbitrary API commands.
The Gridbox extension for Joomla is vulnerable to privilege escalation, allowing unauthenticated attackers to register new accounts with administrative permissions.
The HashiCorp consul-mcp-server fails to isolate session state in stateless mode, allowing one client's authentication token to be erroneously reused by other clients.
A server-side request forgery vulnerability in Prebid Server allows unauthenticated attackers to force the server to make requests to unintended destinations.
The Gridbox extension for Joomla contains an unauthenticated arbitrary password reset vulnerability that allows attackers to hijack user accounts.
The Gridbox extension for Joomla is affected by an account takeover vulnerability via the socialLogin method, allowing unauthenticated attackers to impersonate any user.
A missing authentication vulnerability in NASA-AMMOS AIT-GUI allows unauthenticated attackers to create sessions and issue arbitrary spacecraft commands.
IBM WebSphere Application Server is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled, potentially allowing unauthorized network requests.
The Gridbox extension for Joomla contains an arbitrary file upload vulnerability allowing authenticated attackers to execute code when combined with other flaws.
Linuxfabrik monitoring-plugins for Icinga and Nagios are vulnerable to input validation issues, potentially leading to Server-Side Request Forgery.
The swagger-typescript-api package is susceptible to code injection due to improper neutralization of special elements in generated output.
The swagger-typescript-api package is vulnerable to code injection due to improper neutralization of special elements in generated output, potentially allowing arbitrary code execution.
The swagger-typescript-api package is vulnerable to code injection due to improper neutralization of special elements in generated output, potentially allowing arbitrary code execution.
The swagger-typescript-api package is vulnerable to code injection due to improper neutralization of special elements in generated output, potentially allowing arbitrary code execution.
Adobe Campaign Classic is vulnerable to SQL injection, which may allow an unauthenticated attacker to disclose sensitive information from system memory.
The Extra Checkout Options plugin for WordPress is vulnerable to arbitrary file upload, which could allow authenticated attackers to execute malicious code on the server.
An out-of-bounds write in the ANGLE graphics component of Google Chrome allows a remote attacker to achieve a sandbox escape after compromising the renderer process.
Flyto-core versions prior to 2.26.6 are susceptible to the insertion of sensitive information into sent data and insufficient protection of credentials.
Flyto-core versions prior to 2.26.6 suffer from insufficient credential protection, improper resource exposure, and failures in security protection mechanisms.
The Adobe Photoshop Installer is vulnerable to an uncontrolled search path element flaw that allows an attacker to achieve arbitrary code execution in the context of the current user.
Flyto-core versions prior to 2.26.7 are vulnerable to Server-Side Request Forgery (SSRF) attacks, allowing authenticated users to trigger unauthorized requests.
A Server-Side Request Forgery (SSRF) vulnerability in the flyto-core execution kernel allows authenticated attackers to perform unauthorized requests.
Spring Tools for Eclipse uses a cryptographically weak pseudo-random number generator to create shared secrets for remote-restart authentication, allowing potential unauthorized access.
Insufficient input validation in the Google Chrome Chromecast integration allows a local attacker to perform a sandbox escape via malicious network traffic.
An integer overflow in the Chromecast component of Google Chrome allows a local attacker to potentially perform a sandbox escape via malicious network traffic.
The FleekDash V2 WordPress plugin contains a missing authorization vulnerability that allows authenticated users to perform unauthorized actions via the UserController.
The wp-media-folder-addon plugin for WordPress is vulnerable to path traversal, potentially allowing unauthenticated attackers to access sensitive files on the server.
Insufficient validation of untrusted input in Certificate in Google Chrome on Linux allows an attacker in a privileged network position to perform domain spoofing.
Apache Atlas contains a missing authorization vulnerability that allows authenticated users to perform unauthorized actions.
Apache Traffic Server improperly manages session and tunnel reuse, which can lead to the exposure of sensitive data across distinct client connections.
The ts_lua plugin in Apache Traffic Server incorrectly handles initialization, transform context, and per-instance state, which can lead to uncontrolled resource consumption.
Apache Traffic Server contains an authorization bypass vulnerability affecting Unix Domain Socket listeners and Access Control List matching logic.
The Apache Traffic Server header_rewrite plugin is susceptible to memory corruption or crashes during cookie operations and CIDR condition matching.
Multiple experimental plugins in Apache Traffic Server contain memory-safety and limit-bypass errors that can be triggered by unauthenticated users.
The Apache Traffic Server Cripts framework contains vulnerabilities including out of bounds writes, path traversal, and use after free errors.
The regex_remap plugin in Apache Traffic Server is susceptible to stack based buffer overflows and integer overflows triggered by malicious substitution input.
The Boot Dashboard Docker integration in Spring Tools for Eclipse incorrectly binds container control ports to all host network interfaces, potentially exposing them to unauthorized network access.
An unauthenticated Server-Side Request Forgery vulnerability in the Eclipse CSI - PIA upload endpoint arises from improper validation of JWT issuer claims.
The TP-Link TL-WR940N v6 router contains a stack-based buffer overflow vulnerability in its RTSP connection tracking module.
A SQL injection vulnerability in the Black Duck Coverity Connect SOAP API allows authenticated users to execute arbitrary SQL commands.
The Model Context Protocol ruby-sdk is vulnerable to improper access control, allowing an unauthenticated remote attacker to potentially manipulate system integrity.
A remote code execution vulnerability exists in the Autel MaxiCharger AC Elite Home due to an integer underflow in the WebSockets implementation.
The Phoenix Contact CHARX series is vulnerable to a fail-open condition, allowing attackers to force a fallback to a firmware partition containing default credentials.
An OS command injection vulnerability in Phoenix Contact CHARX controllers allows unauthenticated remote attackers to execute arbitrary commands via the OCPP backend.
Samsung mobile devices are vulnerable to an out-of-bounds write in the ImsService, which may allow a remote attacker to execute arbitrary code.
A logic error in ads-tec Industrial IT DVG series devices allows low privileged attackers to overwrite user passwords, potentially leading to administrative lockout.
A SQL injection vulnerability in DriveLock allows authenticated, low-privileged users to escalate their privileges through specially crafted database queries.
A stack-based buffer overflow vulnerability in the ASUSTOR ADM File Explorer allows authenticated attackers to potentially execute arbitrary code.
A vulnerability in Schneider Electric EcoStruxure Cybersecurity Admin Expert allows a local privileged attacker to bypass authentication and modify credentials.
A file descriptor leak in the PCP linux_sockets module for Red Hat Enterprise Linux exposes unsecured internal connections to unauthorized parties.
An integer wraparound vulnerability exists in the IVFFlat index build process of the pgvector extension, potentially leading to memory corruption.
A use-after-free vulnerability in the Linux kernel Bluetooth L2CAP implementation allows potential memory corruption via improper socket handling.
An infinite loop vulnerability in the Netty framework's codec components can be triggered by a remote attacker to cause a denial of service.
The veraPDF validation model contains an XML External Entity (XXE) vulnerability, allowing unauthenticated attackers to potentially read sensitive files via maliciously crafted inputs.
The veraPDF validation model is susceptible to an XML External Entity (XXE) attack, which may allow unauthenticated remote attackers to read sensitive files from the underlying system.
A Double Free vulnerability in open-iscsi allows an unauthenticated man-in-the-middle attacker to cause a denial-of-service condition on the affected system.
A format string vulnerability in the Notification OAuth settings of ASUSTOR ADM allows for potential compromise of system integrity and availability.
The HashiCorp consul-mcp-server is vulnerable to Server-Side Request Forgery (SSRF), allowing unauthenticated attackers to potentially access unauthorized internal resources.
An interpretation conflict vulnerability in the V programming language, specifically within the net/urllib and net/http modules, allows for SSRF bypass.
GitLab CE and EE contain an insertion of sensitive information into sent data vulnerability, allowing authenticated users to access unauthorized information.
An incorrect authorization vulnerability in open-iscsi allows unprivileged local users to interact with the iscsiuio control socket, potentially leading to unauthorized operations.
GitLab CE/EE is vulnerable to an improper control of object attributes, allowing an authenticated user to perform unauthorized modifications.
An out-of-bounds write vulnerability in Schneider Electric IGSS Definition (Def.exe) allows for potential arbitrary code execution via malicious CGF file imports.
An incorrect authorization vulnerability in the ZITADEL identity management platform allows for unauthorized integrity impacts.
A resource exposure vulnerability in the termux proot-distro utility allows for potential unauthorized access to resources within the container environment.
A symbolic link following vulnerability in the proot-distro utility allows unauthorized file system access.
VaahCMS versions 2.0.0 through 2.3.4 contain embedded malicious code, posing a supply chain risk.
Xlight FTP Server prior to 3.9.5 is vulnerable to a stack-based buffer overflow via the SSH GCM cipher.
IBM Sterling B2B Integrator and Sterling File Gateway are affected by an SQL injection vulnerability, potentially allowing authenticated attackers to access sensitive data.
Pterodactyl Panel and Wings are affected by improper security token assignment and generation, allowing authenticated users to perform unauthorized actions.