CVE-2026-7273
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware allows potential remote command execution.
Critical vulnerabilities, curated daily for security professionals
Thursday's disclosures were led by critical flaws in the WordPress ecosystem (Visual Composer Website Builder, AF Companion, and a WooCommerce OTP plugin), along with ServiceNow AI Platform, Apache BuildStream, and Nocobase. The brief covers 28 critical CVEs, up 4% from 27 the prior day, and 75 high-priority CVEs, down 12% from 85. Among the highest-scoring issues are CVE-2026-61732 (CVSS 10) in BitterSecurity Decepticon, CVE-2026-82331 (CVSS 9.8) in Apache BuildStream, and CVE-2026-12227 (CVSS 9.8) in Visual Composer Website Builder. Web-facing content management plugins and developer or database tooling (Bytebase DBHub, http4s-scala-xml, Nocobase) make up much of the critical set, and seven CVEs affecting network and security infrastructure from F5, Check Point, Zyxel, and Arista VeloCloud are confirmed as actively exploited. Defenders should verify fix status with each vendor, restrict internet exposure of WordPress admin interfaces and appliance management planes, and prioritize internet-facing systems first.
Immediate action: Start with the actively exploited network and security appliances (F5 BIG-IP, Check Point Quantum, Zyxel GS1900, Arista VeloCloud Orchestrator) and Adobe Commerce storefronts, then inventory WordPress sites running Visual Composer, AF Companion, or the affected WooCommerce plugin. Confirm fix status in each vendor's advisory before scheduling remediation. Where a fix cannot be applied right away, restrict management interfaces and admin panels to trusted networks.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware allows potential remote command execution.
VeloCloud Orchestrator (VCO) on-prem is vulnerable to improper input validation, allowing unauthenticated remote attackers to access privileged functionality and compromise the host.
A heap-based buffer overflow in F5 BIG-IP APM, when configured as an OAuth Authorization Server, allows unauthenticated attackers to achieve remote code execution via malicious traffic.
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server.
An improper certificate trust validation vulnerability exists in Check Point Quantum Security Gateways during VPN negotiation, allowing unauthenticated remote code execution.
The WSO2 JWT authentication mechanism incorrectly validates tokens using unsupported algorithms, potentially allowing unauthenticated attackers to bypass security controls and gain unauthorized access.
Adobe Commerce and Magento Open Source are vulnerable to an improper authorization flaw that allows unauthenticated attackers to escalate privileges and access sensitive resources.
Disclosed Sep 18 without a CVSS score; scored Sep 21, analysis completed Sep 25.
The AF Companion WordPress plugin fails to validate uploaded file types, allowing authenticated users with store-management privileges to achieve remote code execution.
The Visual Composer Website Builder plugin for WordPress is susceptible to unauthenticated Local File Inclusion via the vcv-template parameter, potentially leading to remote code execution.
The Automation Web Platform plugin for WordPress contains a critical privilege escalation vulnerability allowing unauthenticated attackers to gain administrative access via improper REST API input handling.
A SQL injection vulnerability in the ServiceNow AI Platform allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification.
Bytebase DBHub versions prior to 0.22.5 are vulnerable to DNS rebinding attacks, allowing unauthenticated remote attackers to execute MCP tool calls via a victim's browser.
The http4s-scala-xml library is vulnerable to XML External Entity (XXE) attacks due to insecure default SAX parser configurations, allowing unauthorized information disclosure or SSRF.
Disclosed Sep 23 without a CVSS score; scored Sep 24, analysis completed Sep 24.
A symlink follow vulnerability in the Apache BuildStream tar source plugin allows unauthenticated attackers to write arbitrary files to the host system during source fetching.
Disclosed Sep 21 without a CVSS score; tracked by CVE Brief from Sep 22; scored Sep 23, analysis completed Sep 23.
A SQL injection vulnerability in the checkSQL function of Nocobase v2.1.21 allows unauthenticated attackers to access sensitive database information via crafted SQL statements.
BitterSecurity Decepticon versions prior to 1.1.17 fail to neutralize ChatML special tokens, allowing unauthenticated attackers to forge LLM commands and achieve remote code execution.
Disclosed Sep 19; published with a limited analysis after repeated re-checks found no further public detail.
The Product Question and Answer WordPress plugin contains an unauthenticated SQL injection vulnerability via AJAX actions, allowing attackers to extract sensitive database information.
Disclosed Sep 19; published with a limited analysis after repeated re-checks found no further public detail.
The Tz Weekly Radio Schedule WordPress plugin fails to sanitize input, enabling unauthenticated SQL injection attacks via AJAX actions to extract database information.
Disclosed Sep 21 without a CVSS score; tracked by CVE Brief from Sep 22; scored Sep 23, analysis completed Sep 23.
The gray-matter library uses eval() to parse JavaScript front matter, allowing unauthenticated attackers to achieve remote code execution.
Disclosed Sep 21 without a CVSS score; tracked by CVE Brief from Sep 22; scored Sep 23, analysis completed Sep 23.
Email::Sender::Transport::Sendmail for Perl contains an OS command injection vulnerability on Windows systems that allows unauthenticated attackers to execute arbitrary commands via crafted email headers.
A command injection vulnerability in the Dokploy tRPC procedure allows authenticated users to execute arbitrary shell commands as root, potentially leading to full host and container compromise.
Rejetto HFS2 contains a server-side template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution via malicious filenames.
Honeywell PD45 industrial printers are vulnerable to unauthenticated remote code execution due to improper file upload validation in the web management interface.
A vulnerability in Velociraptor allows authenticated investigators to execute arbitrary VQL statements as an administrator by manipulating internal hunt object fields.
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a Server Side Request Forgery flaw due to improper validation of the X-Forwarded-Proto header, allowing sensitive information disclosure.
An improper cryptographic signature verification flaw in dashbit nimble_zta allows unauthenticated remote attackers to bypass authentication by forging Cloudflare service tokens.
A missing authorization flaw in the ServiceNow AI Platform allows unauthenticated users to perform unauthorized data extraction and privilege escalation.
HFS2 contains an unauthenticated arbitrary file access vulnerability allowing remote attackers to read, write, and delete files outside the shared directory via the template macro engine.
An integer underflow in the Linux kernel RDMA server allows unauthenticated remote attackers to trigger out-of-bounds memory access via malicious network messages.
A memory safety vulnerability in the Linux kernel SUNRPC implementation allows unauthenticated attackers to trigger stale pointer dereferences via improper credential clearing during decode failures.
A flaw in the iSteamX AWS policy allows authenticated users to access wildcard MQTT topics, potentially exposing user data and enabling unauthorized control of connected steam devices.
The Eufy Omni C20 fails to perform proper certificate validation, enabling man-in-the-middle attacks that allow unauthenticated attackers to execute arbitrary code.
A critical authorization flaw in the ixo-blockchain x/bonds module allows unauthenticated attackers to drain funds from arbitrary victim addresses by manipulating DID verification methods.
Disclosed Sep 22 without a CVSS score; scored Sep 22, analysis completed Sep 22.
A memory leak vulnerability in the Net::IDN::Punycode Perl module allows unauthenticated attackers to cause process memory exhaustion via specially crafted inputs.
Disclosed Sep 22 without a CVSS score; scored Sep 23, analysis completed Sep 23.
The Net::IDN::Punycode::PP library for Perl incorrectly decodes truncated labels, potentially leading to deterministic inconsistencies between different backend implementations.
An authenticated cross-site scripting (XSS) vulnerability in the Snipe-IT file upload API allows attackers to execute arbitrary JavaScript within the application origin.
A SQL injection vulnerability in the StopWords::add method of phpMyFAQ allows authenticated administrators to execute arbitrary SQL commands via the word parameter.
The s2Member plugin for WordPress is vulnerable to unauthenticated remote code execution due to improper sanitization of the first_name parameter and exposure of a site-global proxy verification key.
IBM Enterprise Build of Quarkus is vulnerable to SQL injection, allowing remote unauthenticated attackers to manipulate back-end database information.
phpIPAM through 1.8.3 contains an incorrect authorization vulnerability in the API controller, allowing unauthorized access to administrative functions.
A path traversal vulnerability in the pfSense Dashboard allows an authenticated user to execute arbitrary PHP code via crafted widget sequence data.
A race condition in the Linux kernel nvme-fc driver allows unauthenticated attackers to trigger an improper state check, potentially leading to a kernel crash or system instability.
ZITADEL Actions V1 contains an improper access control vulnerability allowing authenticated organization administrators to read sensitive files from the server, potentially leading to privilege escalation.
The Discourse video placeholder component is vulnerable to Stored Cross-site Scripting (XSS) via attribute breakout, allowing authenticated users to execute arbitrary JavaScript in other users' sessions.
Root Browser Classic 3.3.0 contains an OS command injection vulnerability where SQLite database paths are passed to the system shell without proper sanitization.
An integer overflow in the MongoDB Python Driver BSON encoding component can lead to an out-of-bounds write within the application process when processing unusually large, caller-supplied data.
Amazon Kiro IDE versions before 1.0.242 allow unauthenticated remote actors to inject malicious instructions into the agent context, leading to unauthorized modifications of global configuration paths.
Disclosed Sep 19; published with a limited analysis after repeated re-checks found no further public detail.
Incorrect authorization in Microsoft Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
The Knit Pay plugin for WordPress is susceptible to privilege escalation in versions up to 9.6.1.0 due to insufficient validation of user roles during Gravity Forms submissions.
A type confusion vulnerability in AWS pgcollection versions 2.0.0 to 2.1.1 allows an authenticated user to execute arbitrary code as the postgres system user via crafted SQL statements.
Gerrit Code Review is vulnerable to uncontrolled resource consumption via crafted regex queries in search predicates and REST API endpoints, potentially causing CPU starvation and JVM heap exhaustion.
Dell ThinOS 10 contains a missing authentication vulnerability that allows unauthenticated remote attackers to gain unauthorized access to critical system functions.
Disclosed Sep 19; published with a limited analysis after repeated re-checks found no further public detail.
The Tz Weekly Radio Schedule WordPress plugin fails to sanitize AJAX parameters, enabling unauthenticated SQL injection and potential sensitive data exposure.
Logto versions prior to 1.43.0 contain a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated tenant administrators to access internal network resources and metadata services.
Gerrit Code Review is vulnerable to an uncontrolled resource consumption flaw in its ANTLR 3 search query parser, allowing unauthenticated attackers to trigger a persistent denial of service.
BentoPDF versions 2.8.6 and earlier contain a Server-Side Request Forgery vulnerability in the CORS proxy, allowing unauthenticated attackers to reach internal or reserved network destinations.
Disclosed Sep 18 without a CVSS score; scored Sep 21, analysis completed Sep 25.
A memory leak in Netty's StompSubframeDecoder component allows remote attackers to trigger a Denial of Service by sending malformed STOMP frames.
Disclosed Sep 22 without a CVSS score; scored Sep 23, analysis completed Sep 23.
Dancer2 versions 2.0.0 through 2.1.x allow unauthenticated attackers to bypass route restrictions due to improper exception handling, resulting in unintended route execution.
Disclosed Sep 18 without a CVSS score; scored Sep 19, analysis completed Sep 19.
The All-in-One WP Migration and Backup plugin fails to implement proper capability checks on AJAX actions, allowing authenticated users with export privileges to import arbitrary archives and gain admin.
Disclosed Sep 19 without a CVSS score; scored Sep 20, analysis completed Sep 20.
The WP Import Export Lite WordPress plugin fails to perform proper capability checks during data imports, allowing authorized users to escalate privileges to administrator.
Disclosed Sep 18 without a CVSS score; scored Sep 19, analysis completed Sep 19.
The Filter Gallery WordPress plugin fails to validate nonces and capability checks on AJAX handlers, allowing authenticated users to modify post content and delete gallery settings.
Disclosed Sep 19 without a CVSS score; scored Sep 21, analysis completed Sep 21.
The Estatik Real Estate Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via unauthenticated AJAX request parameters that fail to sanitize input.
An authenticated remote code execution vulnerability in the Honeywell PD45 Industrial Printer allows command injection via the Intermec Fingerprint interface.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to arbitrary code execution due to unsafe deserialization of untrusted data by an authenticated remote attacker.
Disclosed Sep 18 without a CVSS score; scored Sep 23, analysis completed Sep 23.
A broken access control vulnerability in Apache Airflow allows authenticated users with read-only access to delete queued asset events, disrupting automated DAG scheduling.
The Linux kernel iwlwifi driver contains a memory validation flaw in the TX_CMD response layout, potentially allowing unauthenticated adjacent attackers to trigger corruption or instability.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, which could allow a remote authenticated attacker to execute arbitrary code on the underlying system.
IBM DataStage on Cloud Pak for Data is vulnerable to OS command injection, which could allow a remote authenticated attacker to execute arbitrary commands on the underlying system.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to path traversal, which can be exploited by an authenticated remote attacker to execute arbitrary system commands.
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an OS command injection vulnerability, allowing authenticated remote attackers to execute arbitrary commands.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection via improper neutralization of environment variables by an authenticated remote attacker.
A vulnerability in @bsv/wallet-toolbox packages allows a compromised storage provider to redirect funds by injecting malicious output scripts into transactions without user detection.
An authentication bypass in Snipe-IT allows an authenticated user to generate an API token before completing two-factor authentication, potentially leading to full administrative account takeover.
A vulnerability in the Netlink ICT HG323RW router allows authenticated attackers to execute arbitrary system commands with root privileges via the diagnostic script import function.
Disclosed Sep 18 without a CVSS score; tracked by CVE Brief from Sep 19; scored Sep 22, analysis completed Sep 22.
A heap-based buffer overflow in the ipaccess_proxy_read_msg function of osmo-bsc allows unauthenticated attackers to cause a denial of service via malformed IPA frame lengths.
Disclosed Sep 18 without a CVSS score; tracked by CVE Brief from Sep 19; scored Sep 22, analysis completed Sep 22.
A reachable assertion in the ranap_handle_co_dt function of osmo-iuh allows unauthenticated remote attackers to trigger a process crash via a malformed NAS-PDU, resulting in a denial of service.
An authentication bypass vulnerability in goauthentik allows attackers to hijack user sessions by intercepting email factor enrollment during the authentication flow.
A Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows unauthenticated attackers to perform unauthorized actions on behalf of a victim.
The Botslab G980H dash camera firmware utilizes predictable, sequential session identifiers, allowing unauthenticated attackers on the adjacent network to bypass authorization controls.
The Botslab G980H dash camera firmware fails to properly expire sessions after a client connection is terminated, potentially allowing unauthorized access to existing sessions.
The Botslab G980H dash camera firmware features an authorization flaw where session identifiers are not correctly bound to the originating client, allowing unauthorized access to privileged commands.
A memory management flaw in the Linux kernel DRM pagemap subsystem leads to invalid memory operations during DMA unmapping, potentially allowing for system-level impact.
An out-of-bounds memory access vulnerability exists in the Linux kernel iwlwifi driver, potentially allowing memory corruption during block acknowledgment processing.
The Linux kernel contains an out-of-bounds memory access vulnerability in the iwlwifi wireless driver, which can be triggered by a malicious firmware notification.
A memory safety flaw in the Linux kernel wireless subsystem (cfg80211) allows unauthenticated attackers within radio range to trigger out-of-bounds memory access via malformed association responses.
An authorization flaw in the goauthentik identity provider allows authenticated users with delegated management permissions to escalate privileges and improperly assign roles.
A memory corruption vulnerability in the Linux kernel ath11k Wi-Fi driver allows adjacent attackers to trigger invalid data access via maliciously crafted packet lengths.
A reference counting vulnerability in the Linux kernel thunderbolt driver allows unauthorized access to XDomain service data, potentially leading to system instability or information disclosure.
A buffer over-read vulnerability in the Linux kernel Greybus audio driver allows unauthenticated attackers to trigger out-of-bounds memory access via maliciously crafted topology blobs.
An authorization bypass in the ServiceNow AI Platform allows unauthenticated attackers to access restricted data, potentially leading to further unauthorized system access.
ServiceNow AI Platform contains an improper access control vulnerability that allows unauthenticated users to perform unauthorized data creation, modification, or deletion on affected instances.
A stored cross-site scripting (XSS) vulnerability in code16 Sharp allows authenticated attackers to bypass HTML sanitization via the SharpEditorFormField, leading to potential script execution.
Brocade SANnav incorrectly logs sensitive IPsec pre-shared keys, allowing authenticated users with log access to compromise credentials and potentially intercept network tunnel traffic.
Brocade SANnav log files contain plaintext administrative credentials and session tokens, allowing local users with file read access to compromise managed network infrastructure.
Brocade SANnav fails to sanitize logs during IPsec policy collection, causing sensitive pre-shared keys to be written to system logs where they are accessible to unauthorized users.
ServiceNow has addressed an authorization bypass vulnerability in the AI Platform that allows authenticated users to access unauthorized data and potentially facilitate further unauthorized access.
A double-free vulnerability exists in the Linux kernel virtio-fs driver, caused by improper cleanup of pointers during a failed queue setup that can lead to memory corruption.
A vulnerability in the Linux kernel ACPICA subsystem allows potential memory corruption or unauthorized access due to improper validation of handler object types in specific handler functions.
An integer overflow vulnerability in the Linux kernel ACPICA subsystem allows potential memory corruption via improper truncation length calculations during memcpy operations.
A memory management flaw exists in the Linux kernel ACPICA subsystem where invalid references can be added to local, argument, or debug objects during copy operations.
A use-after-free vulnerability in the Linux kernel ACPICA subsystem allows local attackers to potentially achieve arbitrary code execution or cause system instability.
Disclosed Sep 22 without a CVSS score; scored Sep 23, analysis completed Sep 23.
Net::IDN::UTS46 for Perl is vulnerable to CPU exhaustion via quadratic punycode encoding of overlong labels in the to_ascii function.
Disclosed Sep 18 without a CVSS score; tracked by CVE Brief from Sep 19; scored Sep 22, analysis completed Sep 22.
An out-of-bounds read vulnerability in the smpp34_unpack function of libsmpp34 allows unauthenticated attackers to trigger memory corruption via crafted SMPP PDUs.
Disclosed Sep 21 without a CVSS score; tracked by CVE Brief from Sep 22; scored Sep 23, analysis completed Sep 23.
Jazzware RT1000 Edge webUI v. 20.0.1 allows an authenticated administrative user to upload and execute arbitrary server-side files, leading to remote code execution.
Disclosed Sep 22 without a CVSS score; scored Sep 22, analysis completed Sep 22.
Net::IDN::Punycode for Perl is vulnerable to CPU exhaustion during the decoding of long labels in decode_punycode due to inefficient algorithmic complexity.
Disclosed Sep 22 without a CVSS score; scored Sep 23, analysis completed Sep 23.
The Net::IDN::Punycode Perl module fails to validate UTF-8 input, leading to infinite loops, crashes, or incorrect label generation when processing malformed data via the encode_punycode function.
Disclosed Sep 22 without a CVSS score; scored Sep 23, analysis completed Sep 23.
Dancer2 for Perl allows unauthenticated path traversal via the File route handler, enabling attackers to read sensitive files outside the intended public directory.
Disclosed Sep 21 without a CVSS score; tracked by CVE Brief from Sep 22; scored Sep 23, analysis completed Sep 23.
CrossWire Xiphos versions 4.3.2 and earlier contain a vulnerability allowing a local attacker to execute arbitrary code through the url.cc and menu_popup.c components.
Disclosed Sep 21 without a CVSS score; tracked by CVE Brief from Sep 22; scored Sep 23, analysis completed Sep 23.
An improper access control vulnerability in x-ui 0.3.2 allows authenticated users to expose the xray management gRPC service to external network interfaces.
Disclosed Sep 19 without a CVSS score; tracked by CVE Brief from Sep 20; scored Sep 22, analysis completed Sep 22.
Perl's Pod::Text module is vulnerable to an infinite loop during POD document formatting, which can lead to CPU and memory exhaustion when processing maliciously crafted input.