CVE-2012-1854
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Sunday's disclosures center on a critical remote code execution flaw in the widely-used simple-git Node.js library, alongside 31 high-priority vulnerabilities affecting enterprise platforms including Microsoft, Adobe, Apache, and JetBrains products. Critical CVE volume dropped 95% from yesterday's 19 to a single disclosure, while high-priority CVEs declined 57% from 72 to 31. The headline issue is CVE-2026-6951 (CVSS 9.8) in simple-git, a foundational dependency embedded across countless CI/CD pipelines and developer tooling. Active exploitation continues across 19 KEV-listed vulnerabilities spanning Microsoft Office, Exchange, SharePoint, Adobe Acrobat, Apache ActiveMQ, JetBrains TeamCity, and SimpleHelp remote support software. No vendor patches were available for the disclosed CVEs at publication time, requiring defenders to rely on compensating controls and monitoring until fixes are released.
Immediate action: Development and security teams should immediately audit Node.js projects and CI/CD systems for simple-git dependencies and apply input validation on any user-controlled arguments passed to its API. With 0% patch availability, prioritize compensating controls including network segmentation, enhanced logging, and monitoring for actively exploited products from Microsoft, Adobe, Apache ActiveMQ, JetBrains TeamCity, and SimpleHelp.
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Link Following Vulnerability - Active in CISA KEV catalog.
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Out-of-Bounds Read Vulnerability - Active in CISA KEV catalog.
Adobe Acrobat Use-After-Free Vulnerability - Active in CISA KEV catalog.
Adobe Acrobat Reader is vulnerable to prototype pollution, which can result in arbitrary code execution when a victim opens a malicious file.
Microsoft Office Remote Code Execution - Active in CISA KEV catalog.
Microsoft SharePoint Server Improper Input Validation Vulnerability - Active in CISA KEV catalog.
Apache ActiveMQ Improper Input Validation Vulnerability - Active in CISA KEV catalog.
Kentico Xperience Path Traversal Vulnerability - Active in CISA KEV catalog.
PaperCut NG/MF Improper Authentication Vulnerability - Active in CISA KEV catalog.
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability - Active in CISA KEV catalog.
JetBrains TeamCity Relative Path Traversal Vulnerability - Active in CISA KEV catalog.
Microsoft Defender Insufficient Granularity of Access Control Vulnerability - Active in CISA KEV catalog.
Marimo Remote Code Execution Vulnerability - Active in CISA KEV catalog.
D-Link DIR-823X Command Injection Vulnerability - Active in CISA KEV catalog.
Samsung MagicINFO 9 Server Path Traversal Vulnerability - Active in CISA KEV catalog.
SimpleHelp Path Traversal Vulnerability - Active in CISA KEV catalog.
SimpleHelp Missing Authorization Vulnerability - Active in CISA KEV catalog.
The simple-git package is vulnerable to Remote Code Execution (RCE) via a bypass of previous security fixes, allowing attackers to inject malicious git configurations.
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology
The arduino-esp32 core, used for various ESP32 microcontrollers, contains an unspecified high-severity vulnerability requiring urgent security review.
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ
Apache ActiveMQ is vulnerable to improper input validation and code injection, potentially allowing for arbitrary code execution.
Axios is a promise based HTTP client for the browser and Node
Axios is a promise based HTTP client for the browser and Node
Axios is a promise based HTTP client for the browser and Node
Apache DolphinScheduler contains an incorrect authorization vulnerability that allows authenticated users to access unauthorized tenants during workflow execution.
A vulnerability was determined in KLiK SocialMediaWebsite up to 1
A vulnerability was found in Typecho up to 1
AWS Ops Wheel is vulnerable to an attribute modification flaw in Cognito User Pool configuration, allowing authenticated users to escalate their privileges to deployment administrator.
A flaw has been found in Tenda HG10 HG7_HG9_HG10re_300001138_en_xpon
A vulnerability was identified in Tenda F456 1
The lxml library, used for processing XML and HTML in Python, is subject to a high-severity security vulnerability that requires urgent attention.
Technitium DNS Server before 15
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy
Skim is a fuzzy finder designed to through files, lines, and commands
A vulnerability was identified in Linksys MR9600 2
A high-severity vulnerability has been identified in a Math-related software component, posing a significant risk to systems that rely on this library for calculations.
SiYuan, an open-source personal knowledge management system, is affected by a high-severity vulnerability that could lead to unauthorized access or system compromise.
A flaw was found in OVN (Open Virtual Network)
The OpenTelemetry eBPF Instrumentation tool is affected by a high-severity security vulnerability that could threaten the integrity of system-level observability.
Deskflow, an application for sharing keyboards and mice across computers, is vulnerable to a high-severity security flaw that could lead to unauthorized access.
The NSIS (Nullsoft Scriptable Install System) 3 is affected by a high-severity vulnerability that could be leveraged by attackers during software installation.
4ga Boards is a boards system for realtime project management
Zserio, a framework for serializing structured data, is affected by a high-severity vulnerability that could impact system data integrity and security.
The Zserio data serialization framework is susceptible to a security vulnerability that may impact data integrity or process execution.
A security vulnerability has been identified in the Vanna-AI Vanna framework, affecting versions up to 2.
A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd
A vulnerability was detected in PicoClaw up to 0
A security vulnerability has been identified in SmythOS SRE, affecting versions up to 0.