CVE-2026-8398
A supply chain compromise of DAEMON Tools Lite resulted in the distribution of trojanized binaries signed with a legitimate certificate.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Progress Sitefinity led Wednesday's disclosures with two critical vulnerabilities, including CVE-2026-7312 at the maximum CVSS 10 and CVE-2026-7198 at 9.8, placing content-management deployments at the front of remediation queues. The day brought 7 critical CVEs, down 22% from the prior day's 9, and 17 high-priority CVEs, down 63% from 46. Beyond Sitefinity, critical issues affected identity and healthcare systems, including CVE-2026-49448 (9.8) in authentik, CVE-2026-0611 (9.8) in Spacelabs Healthcare Sentinel, and CVE-2026-47117 (9.8) in OpenMed. Remote code execution and authentication bypass dominated the critical set, spanning web platforms, WordPress/LMS plugins, and medical devices. No patches were available at disclosure for the reported critical issues, so teams should prioritize compensating controls and monitor vendor advisories closely; 7 CVEs carry confirmed active exploitation, including Palo Alto Networks PAN-OS and Oracle WebLogic Server.
Immediate action: Prioritize Progress Sitefinity, authentik, and internet-facing healthcare systems (Spacelabs Sentinel, OpenMed) for immediate review, and apply restrictions or isolation where fixes are not yet published. With patch availability at 0% for the disclosed critical issues, track vendor advisories continuously and apply mitigations as soon as they are released; separately, ensure actively exploited products such as Palo Alto Networks PAN-OS and Oracle WebLogic Server are remediated on an accelerated timeline.
A supply chain compromise of DAEMON Tools Lite resulted in the distribution of trojanized binaries signed with a legitimate certificate.
An authentication bypass vulnerability exists in Palo Alto Networks PAN-OS GlobalProtect, allowing unauthenticated attackers to forge authentication cookies and establish unauthorized VPN connections.
Oracle WebLogic Server contains an unspecified vulnerability that is currently being exploited in the wild.
A privilege escalation vulnerability in the Linux Kernel cgroup_release_agent_write function allows unprivileged users to escape container environments and gain elevated host privileges.
An integer overflow vulnerability in the Android Framework allows for potential unauthorized system access and is currently tracked in the CISA KEV catalog.
A critical supply chain attack involving embedded malicious code in the Nx Console VS Code extension has been identified and is being actively exploited.
GitHub Actions OIDC was exploited to publish malicious npm packages by chaining multiple vulnerabilities, including cache poisoning and token extraction.
The ARMember Premium plugin for WordPress stores plaintext password reset keys, allowing unauthenticated attackers to reset user passwords and hijack accounts.
Spacelabs Healthcare Sentinel contains an unauthenticated RCE vulnerability via a deprecated .NET Remoting HTTP channel, allowing attackers to write webshells and execute arbitrary code.
Progress Sitefinity web services contain a vulnerability that allows unauthenticated remote attackers to retrieve plain-text credentials for the Sitefinity Insight service.
Improper access control in Progress Sitefinity web services allows unauthenticated attackers to access restricted content and fully compromise the installation.
OpenMed contains a remote code execution vulnerability in its PII privacy-filter model loading path, allowing unauthenticated attackers to execute arbitrary code.
Themeisle Masteriyo LMS PRO contains an incorrect privilege assignment vulnerability, allowing unauthenticated attackers to escalate their privileges to administrator.
An authentication bypass vulnerability in the authentik Source stage allows unauthenticated attackers to bypass security checks by sending an empty POST request.
A use-after-free vulnerability in the Media component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
The Content Visibility for Divi Builder plugin for WordPress contains a vulnerability that allows for remote code execution.
A deserialization vulnerability in the Apache Airflow XCom PATCH endpoint allows authenticated users to achieve remote code execution by bypassing key validation.
A bug in Apache Airflow's KubernetesExecutor causes sensitive JWT tokens to be exposed as command-line arguments in pod specifications.
A missing authorization vulnerability in ThimPress Thim Core allows for arbitrary code execution after installing a malicious plugin.
Sparx Pro Cloud Server contains a broken access control vulnerability that allows low-privileged users to execute arbitrary SQL queries.
Improper input validation in web services within Progress Sitefinity 14 may lead to security vulnerabilities.
An authorization bypass vulnerability via user-controlled keys in web services affects Progress Sitefinity 15.
A stack-based buffer overflow in Moxa NPort 5110 allows remote attackers to execute arbitrary code or cause a denial-of-service.
A race condition in the Linux kernel SMB client handling of bitfields in `struct cached_fid` can lead to memory corruption or denial of service due to shared-byte read-modify-write operations.
A vulnerability in the OpenShift Route resource allows low-privileged users to inject malicious HAProxy configurations, potentially leading to cross-tenant traffic hijacking.
Amazon Kiro IDE contains an access control flaw in its file write tool that can be exploited by remote attackers to execute arbitrary code.
BrowserStack Runner contains a remote code execution vulnerability in its HTTP handler that can be exploited by unauthenticated, network-adjacent attackers.
A security vulnerability has been identified in authentik, an open-source identity provider, requiring immediate attention from security administrators.
A heap-overflow vulnerability in the OpenSLP service of VMware ESXi allows remote code execution for attackers on the same network segment.
A stack-based buffer overflow in STP BPDU frame handling in Siemens industrial networking devices may allow remote code execution or denial-of-service.
An authentication bypass vulnerability in Sparx Pro Cloud Server allows unauthorized access depending on the requested URL.