CVE-2026-54420
A symlink mishandling vulnerability in the LiteSpeed cPanel plugin allows users with limited access to escalate privileges on shared hosting environments.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Sunday's disclosures center on web-facing applications and developer infrastructure, with critical remote-code-execution and access-control flaws affecting WooCommerce, Prefect, and Flowise alongside several widely deployed WordPress plugins. The day brought 5 critical CVEs, down 37% from the prior day's 8, while high-priority volume rose 43% to 67. Notable entries include CVE-2026-5366 (CVSS 9.9) in Prefect, CVE-2022-50972 (CVSS 9.8) in WooCommerce, and CVE-2024-58351 (CVSS 9.8) in Flowise. Plugin- and platform-level weaknesses dominate the set, exposing content-management and workflow-orchestration systems to unauthenticated compromise, and four CVEs carry confirmed active exploitation across LiteSpeed, Joomla, Splunk, and Cisco SD-WAN Manager. No patches were referenced at disclosure for the scored set, so teams should prioritize compensating controls and vendor monitoring while fixes are validated.
Immediate action: Prioritize WordPress/WooCommerce environments, Prefect and Flowise deployments, and the actively exploited Splunk, Cisco SD-WAN Manager, LiteSpeed, and Joomla systems for immediate review and isolation where exposed. With no patches referenced at disclosure, apply WAF rules, restrict administrative and internet-facing access, and monitor vendor advisories closely for forthcoming fixes.
A symlink mishandling vulnerability in the LiteSpeed cPanel plugin allows users with limited access to escalate privileges on shared hosting environments.
An improper access control vulnerability in the Widget Factory Joomla Content Editor allows unauthorized users to perform restricted actions.
Splunk Enterprise and Cloud Platform contain an authentication bypass vulnerability in a PostgreSQL sidecar service, allowing unauthenticated users to create or truncate arbitrary files.
Cisco Catalyst SD-WAN Manager contains an arbitrary file write vulnerability in its web UI, allowing authenticated remote attackers to escalate privileges to root.
Ultimate Addons for Beaver Builder contains an authentication bypass flaw in its social login functionality, allowing unauthorized access via crafted POST requests to the admin-ajax.php endpoint.
WooCommerce 7.1.0 contains a remote code execution vulnerability allowing attackers to inject arbitrary PHP code via the product-type parameter.
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover, allowing unauthenticated attackers to change any user's password, including administrative accounts.
Prefect is vulnerable to remote code execution due to improper validation of user-controlled input in the GitRepository storage class, allowing attackers to inject arbitrary git flags.
Flowise versions before 2.1.4 are vulnerable to remote code execution and sandbox escape via an insecure overrideConfig option in the Chainflow execution process.
PhpWeasyPrint is a PHP library that facilitates PDF generation from URLs or HTML pages, containing a vulnerability that requires immediate remediation.
An out-of-bounds read vulnerability in Microsoft Office Excel allows an unauthorized attacker to disclose sensitive information over a network.
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient path validation in the view_page function.
A use-after-free vulnerability in the Linux kernel's page_pool_recycle_in_ring function could lead to kernel instability or privilege escalation.
A use-after-free vulnerability exists in the Linux kernel's Bluetooth hci_core component within the vhci_flush function.
A vulnerability in Malwarebytes Windows Firewall Control may allow for unauthorized security policy manipulation.
An unauthenticated remote code execution vulnerability exists in the Joomla PHP-Bridge component due to improper input validation.
PhpWeasyPrint is susceptible to security vulnerabilities due to its functionality as a PHP library for PDF generation from URLs or HTML pages.
AVideo versions through 29 contain a security vulnerability within its endpoint architecture that requires immediate investigation and patching.
The StreetGuessr Game extension for Joomla is affected by an unspecified vulnerability that may allow for unauthorized system impact.
The Ultimate Property Listing extension for Joomla is affected by an unspecified vulnerability that may allow for unauthorized system impact.
A vulnerability exists in the Joomla Event Registration Pro Calendar 4 extension, potentially allowing for unauthorized exploitation of the application.
A security vulnerability in the Joomla LMS King Professional 3 extension could potentially be exploited to compromise the integrity of the learning management system.
A vulnerability in the Joomla JoomRecipe 1 extension may allow for unauthorized access, potentially impacting the security of the affected Joomla site.
The JoomRecipe component for Joomla contains a high-severity vulnerability that may allow for unauthorized system access or data manipulation.
The Payage component for Joomla contains a high-severity vulnerability that may facilitate unauthorized access or administrative function manipulation.
The Myportfolio component for Joomla is susceptible to a high-severity vulnerability that may allow for unauthorized system interaction.
A vulnerability exists in the Joomla JHotelReservation component that may allow for unauthorized system access.
A vulnerability in the J-MultipleHotelReservation component for Joomla could lead to unauthorized system compromise.
A vulnerability within the J-ClassifiedsManager component for Joomla may allow attackers to compromise the application.
A vulnerability exists in the Joomla Component vRestaurant that may allow for unauthorized system access or manipulation.
A vulnerability exists in the Joomla Component vReview that may allow for unauthorized system access or manipulation.
A vulnerability exists in the Linux kernel's smb client, specifically within the smb2_ioctl_query_info function, involving an out-of-bounds read.
A vulnerability exists in the Realtek High Definition Audio Driver that may allow for unauthorized system interaction or privilege escalation.
A security flaw in the Realtek Audio Service may allow an attacker to manipulate service operations, potentially leading to privilege escalation or system instability.
A vulnerability in the Linux kernel's io_uring subsystem allows for improper opcode sanitization, potentially leading to speculative execution-based attacks.
The gonic music streaming server and Subsonic API implementation contains a security vulnerability that may impact server stability or data access.
Iperius Remote 1 contains a security vulnerability that may allow for unauthorized access or control within the remote desktop environment.
A security vulnerability exists in Matrix42 Remote Control Host 3 that may expose the system to unauthorized access or control.
A high-severity vulnerability has been identified in vLLM that could potentially lead to unauthorized system interactions or data exposure.
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent
A high-severity vulnerability exists within the Zap Calendar Lite component for Joomla, potentially allowing unauthorized data access or remote exploitation.
A vulnerability exists in the Joomla KissGallery component that may allow for unauthorized access or system compromise.
A security vulnerability has been identified in the Joomla Twitch Tv component, which could expose the site to unauthorized exploitation.
A vulnerability has been discovered in the Joomla SIMGenealogy component that could potentially be leveraged by an attacker to compromise the site.
The Joomla! Extra Search component contains an unspecified vulnerability that may allow for unauthorized access or system impact.
The Joomla! jCart component for OpenCart contains an unspecified vulnerability that could permit unauthorized access or system manipulation.
The Joomla! J-BusinessDirectory component contains an unspecified vulnerability that may allow for unauthorized access or system impact.
The Joomla! VMap component contains an unspecified security vulnerability that may allow for unauthorized access or malicious activity within the application.
The Joomla! vAccount component contains an unspecified security vulnerability that may allow for unauthorized access or malicious activity within the application.
A vulnerability in the Net::Statsd::Tiny package may allow an attacker to trigger unintended behaviors within the application's telemetry handling.
The Metrics::Any::Adapter::Statsd library contains a vulnerability affecting versions prior to the current release.
The mcp-memory-service, a semantic memory layer for AI applications, is affected by a security vulnerability that may expose sensitive data or allow unauthorized system access.
A double-free vulnerability in Autodesk Design Review allows for potential arbitrary code execution when a user opens a maliciously crafted PDF file.
Vembu StoreGrid 4 contains a security vulnerability that may allow for unauthorized system access or compromise.
Fortitude HTTP 1 contains a security vulnerability that may allow for unauthorized system access or remote exploitation.
Comodo Chromodo Browser version 52 is susceptible to a security vulnerability that may allow for unauthorized system compromise.
Comodo Dragon Browser versions up to 52 contain a security vulnerability that may facilitate unauthorized system access.
NetDrive 2 contains a security vulnerability that could potentially be leveraged by an attacker to compromise the affected system.
A vulnerability in Wise Care 365 version 4 may expose the system to unauthorized access or potential compromise.
A security vulnerability identified in AnyDesk version 2 could potentially permit unauthorized access or system-level exploitation.
A vulnerability in Network Inventory Advisor version 5 may allow for unauthorized access or potential compromise of the inventory management system.
A high-severity vulnerability has been identified in TFTP Broadband 4, potentially allowing unauthorized system interactions.
A security vulnerability exists within RealTimes Desktop Service 18, which may expose the host system to unauthorized actions.
A high-severity vulnerability has been identified in Winstep 18, presenting a potential risk to the security and integrity of the host environment.
A vulnerability exists in Wondershare PDFelement 5 that may allow for unauthorized system impact.
A vulnerability in Brother SAPSprint 7 could allow an attacker to compromise the integrity of the printing service.
A security vulnerability in Malwarebytes 4 could potentially lead to unauthorized access or system instability.
A vulnerability has been identified in Personify ChromaCam 4, potentially allowing for unauthorized system interaction.
A high-severity vulnerability exists in Avast Antivirus 25 that could potentially be leveraged by an attacker to compromise host security.
A security vulnerability has been identified in AOMEI Partition Assistant up to version 10 that may permit unauthorized system access or manipulation.
A vulnerability in AOMEI Dynamic Disk Manager up to version 10 may allow attackers to perform unauthorized operations on disk management functions.
A security vulnerability has been discovered in AOMEI Backupper up to version 8, which could potentially expose backup data or system configurations to unauthorized access.
A security vulnerability has been identified in EaseUS Partition Master up to version 14 that could allow for unauthorized system or disk manipulation.
A security flaw exists in EaseUS Partition Master up to version 14 that may expose the system to unauthorized access or exploitation.
A security weakness has been identified in IM-Magic Partition Resizer up to version 7 that could facilitate unauthorized system impact.
A security vulnerability found in Ezbsystems UltraISO Premium Edition up to version 9 could allow for unauthorized system impact.