CVE-2026-33824
A double-free vulnerability in the Windows IKE Extension allows unauthenticated attackers to execute arbitrary code over a network.
Critical vulnerabilities, curated daily for security professionals
Apple iOS, iPadOS, and macOS account for the largest cluster of critical disclosures, with four CVSS 9.8 flaws spanning mobile and desktop platforms, alongside enterprise infrastructure issues in VMware Cloud Foundation, Microsoft SharePoint, and Zimbra Collaboration. The set includes 23 critical CVEs (CVSS 9.0+), up 92% from the prior day's 12, and 36 high-priority CVEs, down 57% from 84. Named critical items include CVE-2026-43778, CVE-2026-43799, and CVE-2026-43805 in Apple iOS and iPadOS (all CVSS 9.8), CVE-2026-64698 in Apple macOS (CVSS 9.8), and CVE-2026-78155 in OnGres StackGres (CVSS 9.9). Remote code execution and unauthenticated access patterns dominate, affecting endpoint fleets, virtualization platforms, collaboration servers, and open-source data infrastructure such as mlflow and StackGres. Patch data is not yet published for any of these entries (0% confirmed availability), so teams should track vendor advisories directly and prepare mitigations where fixes are pending; 8 CVEs have confirmed active exploitation.
Immediate action: Prioritize Apple endpoint fleets (iOS, iPadOS, macOS) and internet-facing enterprise infrastructure: VMware Cloud Foundation and vCenter, Microsoft SharePoint, Zimbra Collaboration, and TrueConf Server, where active exploitation is confirmed. No patch availability is confirmed for the critical items in this set, so monitor vendor advisories and apply updates as they ship. In the interim, restrict external access to affected management and collaboration services and review logs on exposed instances for signs of compromise.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A double-free vulnerability in the Windows IKE Extension allows unauthenticated attackers to execute arbitrary code over a network.
VMware vCenter contains a directory traversal vulnerability in the Syslog server, which may allow an unauthenticated attacker with network access to execute arbitrary code on the system.
A weak authentication vulnerability in Microsoft SharePoint allows unauthenticated remote attackers to bypass security controls and access sensitive information.
An improper authentication flaw in Apple macOS Screen Sharing allows unauthenticated network attackers to bypass credentials and gain remote access.
TrueConf Server contains a vulnerability involving missing authentication for critical functions, which allows unauthorized remote attackers to perform sensitive actions.
Zimbra Collaboration (ZCS) is susceptible to remote code execution due to improper neutralization of OS commands.
MLflow contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to reach internal services due to improper validation of redirected URLs.
TrueConf Server is affected by a code injection vulnerability that allows attackers to execute arbitrary code and escape isolated environments.
Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.
The justhtml library before 1.15.0 is vulnerable to multiple sanitization bypasses, allowing for the injection of active HTML and JavaScript content.
The StackGres operator is vulnerable to privilege escalation, allowing a low-privilege tenant who owns a database to gain administrator privileges.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memo
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or read kernel memory.
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file
A stack-based buffer overflow vulnerability exists in the UTT HiPER 1250GW HTTP request handler, allowing remote attackers to achieve arbitrary code execution via a manipulated Profile argument.
An improper authentication vulnerability in the EFM ipTIME T16000M session validation handler allows remote attackers to bypass security controls and gain unauthorized access to the device.
An OS command injection vulnerability in 4MOSAn GCB Doctor allows unauthenticated remote attackers to execute arbitrary system commands via a test page parameter.
A session validation vulnerability in EFM ipTIME T24000M allows remote, unauthenticated attackers to bypass authentication controls via the httpcon_check_session_url function.
The Page Builder CK extension for Joomla contains a second order SQL injection vulnerability in the loadStyles method of the frontend page model.
EmilStenstrom justhtml contains multiple HTML sanitization bypass vulnerabilities in versions before 1.16.0 that can lead to cross-site scripting when processing malicious input.
A failure to properly escape HTML characters in the justhtml library when converting to Markdown allows for sanitizer bypass and potential cross-site scripting.
A prototype pollution vulnerability in the exceljs deepMerge helper allows attackers to inject malicious keys into object prototypes via crafted cell notes.
DJI drones contain an FTP service with hardcoded credentials that allows unauthorized file uploads and storage exhaustion, potentially disabling critical flight logging and firmware update capabilities.
A DMA cleanup flaw in the Linux kernel Marvell Octeontx crypto driver can lead to memory leaks and unauthorized access to protected memory.
A memory access vulnerability in the Linux kernel sch_codel component can be exploited to cause a system crash, resulting in a Denial of Service.
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary comman
An authorization bypass vulnerability in the Product Feed PRO for WooCommerce plugin allows unauthenticated users to disclose sensitive store configuration and product category data.
The Velociraptor verify() VQL function is susceptible to missing authorization and code injection, allowing authenticated users to execute unauthorized operations.
The UTT HiPER 1200GW router is affected by a memory corruption and buffer overflow vulnerability, which can be triggered by an authenticated user.
The HTTP media server in multiple DJI drone models lacks authentication, allowing unauthenticated attackers to access stored photos and videos via the /v2 endpoint.
Heptabase contains a reflected cross-site scripting vulnerability that allows an authenticated user to execute malicious scripts in the context of other users.
DJI drones expose an unauthenticated Bluetooth DUML interface, allowing attackers within range to modify critical Wi-Fi and network configuration parameters.
GitLab CE/EE is affected by a path traversal vulnerability that allows an authenticated user with low privileges to potentially access or manipulate restricted files.
Sakura Editor is affected by an OS command injection vulnerability, potentially allowing an attacker to execute arbitrary commands on the host system.
The exceljs library is vulnerable to CSV formula injection, which can lead to unauthorized data access or malicious actions when a user opens a generated CSV file in spreadsheet software.
The 4MOSAn Management Center is affected by a relative path traversal vulnerability, which may allow an unauthenticated attacker to access unauthorized files on the system.
The exceljs library is vulnerable to a data amplification attack due to improper handling of highly compressed data, leading to potential denial of service.
The exceljs library is vulnerable to path traversal through unvalidated filenames provided in the addImage function, potentially allowing unauthorized access to local files.
The justhtml library is vulnerable to a denial of service attack via specially crafted CSS selectors that trigger uncontrolled resource consumption.
The justhtml library is vulnerable to uncontrolled recursion, which can be exploited by an attacker to trigger a denial of service condition via deeply nested HTML content.
A memory corruption vulnerability, specifically an out-of-bounds read, exists in Open5GS 2.8.0, potentially allowing for system instability or unauthorized information disclosure.
A heap-based buffer overflow vulnerability in Open5GS 2.8.0 allows authenticated low-privilege attackers to cause memory corruption via network-based vectors.
The Tenda CH22 router contains a command injection vulnerability, allowing authenticated attackers to execute arbitrary system commands through the web interface.
The itsourcecode Payroll System contains an unrestricted file upload vulnerability, allowing unauthenticated attackers to upload malicious files to the server.
A SQL injection vulnerability exists in itsourcecode Payroll System version 1.0, allowing unauthenticated attackers to manipulate database queries.
A SQL injection vulnerability in SourceCodester Simple Online Food Ordering System version 1.0 allows unauthenticated remote attackers to compromise database integrity.
SourceCodester Simple Online Food Ordering System version 1.0 contains a SQL injection vulnerability that allows unauthenticated remote code execution or data extraction.
SourceCodester Simple Online Food Ordering System version 1.0 contains a vulnerability allowing for SQL Injection attacks.
The Ractive.js library is vulnerable to code injection and prototype pollution, allowing for potential remote code execution.
A SQL injection vulnerability exists in the PlanController.getImmediatePlans function of the XBROTHER Dynamic Environment Monitoring System, allowing remote unauthenticated attackers to manipulate queries.
A security flaw in Alibaba Fusion Next allows for improper control of object prototype attributes, potentially leading to code injection.
A prototype pollution and code injection vulnerability exists in jQWidgets versions 24.0.0 and 24.0.1, allowing unauthenticated attackers to modify object attributes.
The itsourcecode Sales and Inventory System contains an SQL injection vulnerability that allows unauthenticated attackers to compromise database integrity.
A memory corruption vulnerability in warmcat libwebsockets allows for out-of-bounds writes, which can be triggered by a remote attacker.
A missing authentication vulnerability in the open-wearables Public Invitation-Code Redemption Endpoint allows remote attackers to bypass security controls via the code argument.
A critical deserialization vulnerability in the ggml-rpc component of llama.cpp at commit bec4772f6 allows remote unauthenticated attackers to execute arbitrary code.
A SQL injection vulnerability in the Barangay Resident Profiling Management System 1.0 allows remote attackers to bypass authorization via the ID parameter in /boarders.php.
Ghostwriter contains an authorization bypass vulnerability allowing authenticated users to access or modify sensitive report templates via user controlled keys.
A reflected cross-site scripting (XSS) vulnerability in the Brave Popup Builder plugin allows unauthenticated attackers to execute arbitrary scripts in the context of a user session.
A local privilege escalation vulnerability exists in the Linux kernel RDMA/bnxt_re component due to missing validation of hardware slot limits for Work Queue Entries.
A vulnerability in the Linux kernel TIPC component allows for an integer underflow, which can be exploited to cause a Denial of Service by congesting network connections.
A vulnerability in the Linux kernel ASoC hdac_hdmi codec allows for out of bounds memory access due to insufficient validation of enum values used for array indexing.