CVE-2026-34197
Apache ActiveMQ Improper Input Validation Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Wednesday's disclosed vulnerabilities center on networking infrastructure and browser security, with Totolink A8000RU routers accounting for five critical CVEs and Mozilla Firefox/Thunderbird facing a sandbox escape flaw. The brief includes 16 critical CVEs, down 50% from the prior day, and 100 high-priority issues, unchanged from yesterday. Notable critical entries include CVE-2026-7321 (CVSS 9.6) affecting Firefox and Thunderbird sandboxes, CVE-2026-7248 (CVSS 9.8) in D-Link DI devices, and CVE-2026-24178 (CVSS 9.8) in NVIDIA NVFlare Dashboard. Attack patterns trend toward remote code execution and unauthenticated access against consumer routers, IoT cameras, and enterprise dashboards. No vendor patches are currently available for the disclosed issues, requiring compensating controls and network segmentation; 13 CVEs across Apache ActiveMQ, Microsoft Defender, and SimpleHelp show active exploitation.
Immediate action: Prioritize isolation and access restriction for Totolink A8000RU routers, D-Link DI devices, NVIDIA NVFlare Dashboard, and Mozilla Firefox/Thunderbird deployments where sandbox integrity is critical. With no patches available for the new critical disclosures, apply network segmentation and monitor exploitation indicators for actively exploited products including Apache ActiveMQ, Microsoft Defender, and SimpleHelp.
Apache ActiveMQ Improper Input Validation Vulnerability - Active in CISA KEV catalog.
Kentico Xperience Path Traversal Vulnerability - Active in CISA KEV catalog.
PaperCut NG/MF Improper Authentication Vulnerability - Active in CISA KEV catalog.
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability - Active in CISA KEV catalog.
JetBrains TeamCity Relative Path Traversal Vulnerability - Active in CISA KEV catalog.
Microsoft Defender Insufficient Granularity of Access Control Vulnerability - Active in CISA KEV catalog.
Marimo Remote Code Execution Vulnerability - Active in CISA KEV catalog.
D-Link DIR-823X Command Injection Vulnerability - Active in CISA KEV catalog.
Samsung MagicINFO 9 Server Path Traversal Vulnerability - Active in CISA KEV catalog.
SimpleHelp Path Traversal Vulnerability - Active in CISA KEV catalog.
SimpleHelp Missing Authorization Vulnerability - Active in CISA KEV catalog.
ConnectWise ScreenConnect Path Traversal Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Protection Mechanism Failure Vulnerability - Active in CISA KEV catalog.
A sandbox escape vulnerability in the WebRTC networking component allows attackers to bypass security boundaries.
A remote buffer overflow vulnerability in the D-Link DI-8100 CGI endpoint allows for arbitrary code execution.
NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data tampering, information disclosure, code execution, and denial of service.
Milesight AIOT cameras use SSL certificates with default private keys, enabling potential man-in-the-middle attacks.
A request smuggling vulnerability in the retired Lua version of Pony Mail allows for unauthorized administrative account takeover.
A remote OS command injection vulnerability in the Totolink A8000RU CGI handler allows attackers to execute arbitrary code via the wscDisabled argument.
A remote OS command injection vulnerability exists in the Totolink A8000RU CGI handler, reachable via the setUrlFilterRules function and the enable argument.
The Totolink A8000RU is susceptible to remote OS command injection via the setPptpServerCfg function and the enable argument in the CGI handler.
A remote OS command injection vulnerability in the Totolink A8000RU CGI handler is reachable through the setVpnAccountCfg function's User argument.
The Totolink A8000RU is vulnerable to remote OS command injection via the setWiFiBasicCfg function, triggered by the wifiOff argument.
A remote OS command injection vulnerability in the Totolink A8000RU CGI handler is accessible via the setOpenVpnClientCfg function's enabled argument.
The Totolink A8000RU is susceptible to remote OS command injection in the setRadvdCfg function, reachable via the maxRtrAdvInterval argument.
A remote OS command injection vulnerability in the Totolink A8000RU CGI handler is reachable via the setWiFiEasyGuestCfg function's merge argument.
A default web security misconfiguration in Spring Boot 4.0.0â4.0.5 allows unauthenticated access to all endpoints in specific servlet-based applications.
A privilege escalation vulnerability in OpenClaw during device pairing allows attackers to gain unauthorized access by manipulating device roles.
The Carlson VASCO-B GNSS Receiver lacks authentication, allowing unauthenticated attackers to modify configurations and operational functions.
OpenCATS prior to commit 3002a29 contains a PHP code injection vulnerability in the installer AJAX endpoint that allows unauthenticated attackers to execute arbitrary code by injecting PHP statements into the databaseConnectivity action parameter
The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java
Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings
OpenClaw before 2026
The LatePoint â Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 5
When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel
The camel-mina component's MinaConverter
The ConsulRegistry in the camel-consul component (class org
A weakness has been identified in BrowserOperator browser-operator-core up to 0
Out-of-bounds Read vulnerability in Apache Thrift
An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central
The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue affects Apache Thrift: before 0
Uncontrolled Recursion vulnerability in Apache Thrift Node
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift
Cross Site Request Forgery vulnerability in diskoverdata diskover-community v
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation
NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message
A security flaw has been discovered in SourceCodester Pharmacy Sales and Inventory System 1
A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1
A security vulnerability has been detected in SourceCodester Pharmacy Sales and Inventory System 1
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1
A vulnerability has been found in code-projects Online Lot Reservation System up to 1
A weakness has been identified in SourceCodester Pharmacy Sales and Inventory System 1
A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1
A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1
A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1
A weakness has been identified in dvladimirov MCP up to 0
A security vulnerability has been detected in Tenda F456 1
A vulnerability was detected in Tenda F456 1
A flaw has been found in Tenda F456 1
A vulnerability has been found in Tenda F456 1
A vulnerability was detected in Tenda HG3 2
A vulnerability was determined in Tenda HG3 2
A vulnerability has been found in D-Link DIR-825M 1
A vulnerability was found in D-Link DIR-825M 1
An issue in the /store/items/search endpoint of Agent Protocol server commit e9a89f allows attackers to cause a Denial of Service (DoS) via a crafted POST request
SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret
An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive information, including hashed credentials and access codes
Authentication Bypass vulnerability exists in Netmaker versions prior to 1
ProjeQtor versions 7
The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog
A vulnerability was determined in Tenda HG3 2
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials
An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
In Spring AI, various FilterExpressionConverter implementations accept a filter expression object and translate them to specific vector store query languages
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
mod_sql in ProFTPD before 1
Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes
Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction
Document structural anomalies caused inconsistencies between page element relationships and internal index states
AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a malicious DLL in a specific directory, resulting in arbitrary code execution with system privileges when the system loads the DLL
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensitive Data
Outline is a service that allows for collaborative documentation
OpenClaw before 2026
Text::Minify::XS versions from v0
A path traversal vulnerability in the UI/static component of leonvanzyl autocoder commit 79d02a allows attackers to read arbitrary files via sending crafted URL path containing traversal sequences
An issue in Pro-Bit before v1
A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8
Information disclosure due to incorrect boundary conditions in the Audio/Video component
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
A security vulnerability has been detected in AlejandroArciniegas mcp-data-vis up to de5a51525a69822290eaee569a1ab447b490746d
A vulnerability was detected in JoeCastrom mcp-chat-studio up to 1
A vulnerability has been found in dexhunter kaggle-mcp up to 406127ffcb2b91b8c10e20e6c2ca787fbc1dc92d
A flaw has been found in disler aider-mcp-server up to b2516fa466d0d851932da92ee6d0e66946db9efc
A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6
A vulnerability was found in douinc mkdocs-mcp-plugin up to 0
A security flaw has been discovered in ChatGPTNextWeb NextChat up to 2
A weakness has been identified in ChatGPTNextWeb NextChat up to 2
A vulnerability was identified in duartium papers-mcp-server 9ceb3812a6458ba7922ca24a7406f8807bc55598
A security flaw has been discovered in dubydu sqlite-mcp up to 0
A security vulnerability has been detected in edvardlindelof notes-mcp up to 0
A vulnerability was detected in ef10007 MLOps_MCP 1
A vulnerability was identified in eghuzefa engineer-your-data up to 0
A security flaw has been discovered in egtai gmx-vmd-mcp up to 0
A weakness has been identified in donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd
A vulnerability has been found in jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620
A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2
A vulnerability was identified in BigSweetPotatoStudio HyperChat up to 2
A vulnerability was detected in AgiFlow scaffold-mcp up to 1