CVE-2026-22719
VMware Aria Operations contains a command injection vulnerability that could allow an attacker to execute arbitrary commands on the affected system.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's vulnerability disclosures highlight widespread risk across Apple, Google, Broadcom, and Qualcomm products, with 17 CVEs under active exploitation. The day saw 4 critical-severity vulnerabilities (up 100% from Sunday's 2) and 47 high-priority CVEs (down 49% from 93). Critical flaws include CVE-2026-3587 (CVSS 10.0) affecting Linux-based operating systems, CVE-2026-4567 (CVSS 9.8) in Tenda A15 routers, and CVE-2019-25614 (CVSS 9.8) targeting STOR FTP Server. Actively exploited vulnerabilities span Broadcom VMware Aria Operations, Qualcomm chipsets, Google Chrome V8, and multiple Apple products including iOS and iPadOS. No patches are currently available for the disclosed CVEs, requiring organizations to prioritize compensating controls and monitoring.
Immediate action: Prioritize risk assessment for Linux-based systems (CVE-2026-3587), Broadcom VMware Aria Operations, Qualcomm-powered devices, and Apple products including iOS and iPadOS, as these face active exploitation with no patches currently available. Implement compensating controls such as network segmentation, access restrictions, and enhanced monitoring for affected systems until vendor patches are released.
VMware Aria Operations contains a command injection vulnerability that could allow an attacker to execute arbitrary commands on the affected system.
A memory corruption vulnerability exists in memory allocation processes when handling specific alignments, potentially leading to arbitrary code execution or system instability.
n8n Improper Control of Dynamically-Managed Code Resources Vulnerability - Active in CISA KEV catalog.
Hikvision Multiple Products Improper Authentication Vulnerability - Active in CISA KEV catalog.
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability - Active in CISA KEV catalog.
Apple Multiple products Use-After-Free Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Integer Overflow or Wraparound Vulnerability - Active in CISA KEV catalog.
Apple iOS and iPadOS Use-After-Free Vulnerability - Active in CISA KEV catalog.
Google Chrome versions prior to 146 feature an inappropriate implementation in the V8 JavaScript engine that is currently being exploited in the wild to achieve code execution.
Google Chrome versions prior to 146 contain an out-of-bounds write vulnerability in the Skia graphics engine, which is currently being exploited in the wild.
Wing FTP Server Information Disclosure Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability - Active in CISA KEV catalog.
Craft CMS Code Injection Vulnerability - Active in CISA KEV catalog.
Laravel Livewire Code Injection Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Improper Locking Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Classic Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Buffer Overflow Vulnerability - Active in CISA KEV catalog.
A stack-based buffer overflow in the Tenda A15 UploadCfg function allows remote attackers to execute arbitrary code via a malicious File argument.
An unauthenticated remote attacker can escape a restricted CLI interface in certain Linux-based operating systems to gain root access.
Free Float FTP 1.0 contains a buffer overflow in the STOR command handler, enabling remote attackers to execute arbitrary code via a crafted payload.
The jsrsasign library is vulnerable to incomplete comparison checks in cryptographic functions, allowing attackers to bias DSA nonces and recover private keys.
phpTransformer 2016
WWBN AVideo, an open-source video platform, is affected by a high-severity vulnerability that could lead to unauthorized access or data compromise.
The WP Extended plugin for WordPress is vulnerable to privilege escalation, allowing low-privileged users to gain administrative access.
The ReviewX WordPress plugin is vulnerable to arbitrary method calls, which could allow attackers to execute unauthorized functions within the application.
The Import and export users and customers WordPress plugin is vulnerable to privilege escalation, enabling attackers to gain unauthorized administrative rights.
The WP Maps WordPress plugin is vulnerable to time-based SQL Injection via the âorderbyâ parameter, allowing attackers to extract sensitive database information.
A security vulnerability has been identified in phpTransformer 2016. The flaw could allow an attacker to compromise the integrity or availability of the application.
ownDMS 4
Easy Chat Server 3
A vulnerability was detected in projectworlds Online Notes Sharing System 1
A security flaw has been discovered in MacCMS 2025
A vulnerability was identified in code-projects Simple Laundry System 1
Green CMS 2
A critical security vulnerability has been identified in the D-Link DHP-1320 router. This flaw may allow for remote exploitation and unauthorized device control.
WWBN AVideo, an open-source video platform, is affected by a high-severity vulnerability. The flaw could permit unauthorized access or administrative bypass.
A high-severity vulnerability has been identified in Axessh 4. This security flaw could allow for unauthorized remote access or command execution via the SSH service.
A flaw has been found in Tenda FH451 1
A vulnerability has been found in Tenda FH451 1
A vulnerability was found in Tenda F453 1
A vulnerability was determined in Tenda F453 1
A vulnerability was identified in Tenda F453 1
A weakness has been identified in D-Link DIR-513 1
A flaw has been found in Linksys MR9600 2
A vulnerability was detected in Tenda AC21 16
Kepler Wallpaper Script 1
A security flaw has been discovered in Flos Freeware Notepad2 4
A weakness has been identified in Flos Freeware Notepad2 4
MiniFtp contains a buffer overflow vulnerability in the `parseconf_load_setting` function. This flaw allows local attackers to execute arbitrary code by providing oversized configuration values.
A vulnerability was determined in trueleaf ApiFlow 0
A high-severity flaw has been identified in the Belkin F9K1122 router, which could allow for unauthorized access or device compromise.
Versions of the package jsrsasign before 11
TuneClone 2
DVDXPlayer Pro 5
Iperius Backup 6
JetAudio jetCast Server 2
Lavavo CD Ripper 4
FTP Shell Server 6
SimplePress CMS 1
i-doit CMDB 1
Admin Express 1
CEWE PHOTO SHOW 6
Lyric Video Creator 2
EquityPandit 1
Versions of the package jsrsasign before 11
Versions of the package jsrsasign before 11
Versions of the package jsrsasign before 11
A vulnerability was found in Acrel Environmental Monitoring Cloud Platform 1