CVE-2026-21513
A protection mechanism failure in the MSHTML Framework allows an unauthenticated attacker to bypass security features over a network, potentially leading to unauthorized system access.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Yesterday's disclosures reveal 24 critical vulnerabilities affecting a broad range of products including HP FreeFlow and scripting components, WeGIA Web Manager, Xerox FreeFlow Core, and Copeland XWEB Pro â both scoring a perfect CVSS 10. Critical CVEs rose 33% from the prior day while high-priority vulnerabilities held steady at 97 (down 3%). Notable entries include CVE-2026-28409 in WeGIA Web Manager and CVE-2026-21718 in Copeland XWEB Pro, both with maximum severity scores, alongside multiple CVSS 9.8 flaws in SODOLA firmware, Totolink routers, and Vikunja project management software. Microsoft Windows and Office account for the majority of the 17 actively exploited vulnerabilities, with legacy flaws in Zimbra, GitLab, and Roundcube Webmail also under active exploitation. Patch availability currently sits at 0%, making compensating controls and network segmentation essential while vendors release fixes.
Immediate action: Prioritize mitigation for Microsoft Windows and Office systems, which represent the largest cluster of actively exploited vulnerabilities, and isolate any internet-facing Copeland XWEB Pro, WeGIA, and Roundcube Webmail instances. With 0% patch availability, apply network segmentation, restrict access to affected services, and monitor vendor advisories closely for upcoming fixes.
A protection mechanism failure in the MSHTML Framework allows an unauthenticated attacker to bypass security features over a network, potentially leading to unauthorized system access.
Microsoft Windows NULL Pointer Dereference Vulnerability - Active in CISA KEV catalog.
A protection mechanism failure in the Windows Shell allows an unauthenticated attacker to bypass security features over a network connection.
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate their privileges locally on the affected system.
A type confusion vulnerability in the Desktop Window Manager (DWM) allows an authorized local attacker to elevate their privileges to a higher level.
A security feature bypass vulnerability in Microsoft Office Word exists due to reliance on untrusted inputs, allowing an unauthorized local attacker to circumvent security protections.
A memory corruption vulnerability in Apple software was addressed through improved state management to prevent potential exploitation.
Microsoft Configuration Manager SQL Injection Vulnerability - Active in CISA KEV catalog.
Notepad++ Download of Code Without Integrity Check Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability - Active in CISA KEV catalog.
TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Google Chrome is vulnerable to a "Use After Free" condition in its CSS engine, which could allow a remote attacker to execute arbitrary code via a crafted webpage.
GitLab Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
RoundCube Webmail Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
RoundCube Webmail Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
FileZen is affected by a high-severity OS command injection vulnerability that allows a threat actor to execute arbitrary commands on the underlying operating system.
A critical RCE vulnerability in WeGIA's database restoration allows administrative users to execute arbitrary OS commands via crafted filenames in backup uploads.
A path traversal vulnerability in Xerox FreeFlow Core allows unauthenticated attackers to access restricted directories, potentially leading to remote code execution (RCE).
A missing authentication and permission check in WeGIA allows unauthenticated attackers to inject massive amounts of unauthorized data into the application server's storage.
Unsafe use of the PHP extract() function in WeGIA allows unauthenticated attackers to overwrite local variables and bypass administrative authentication checks.
The Listee theme for WordPress allows unauthenticated registration as an Administrator due to a broken validation check in the listee-core plugin's registration function.
A remote OS command injection vulnerability exists in the Totolink N300RH Web Management Interface due to improper handling of the webWlanIdx parameter.
SODOLA SL902-SWTGW124AS firmware contains hardcoded default credentials, allowing remote attackers to gain full administrative control over the device management interface.
A logic flaw in the Vikunja password reset mechanism allows reset tokens to be reused indefinitely, enabling persistent account takeover if a token is intercepted.
OpenStack Vitrage contains a code execution vulnerability in its query parser, allowing authenticated API users to execute arbitrary code on the service host.
Copeland XWEB Pro suffers from an authentication bypass vulnerability that allows unauthenticated attackers to achieve remote code execution.
An unauthenticated OS command injection vulnerability in Copeland XWEB Pro allows remote code execution via a crafted request to the libraries installation route.
The Dayneks E-Commerce Platform is vulnerable to SQL injection due to improper neutralization of special elements in SQL commands, potentially exposing the entire database.
Signum Technology's Windesk.Fm platform contains an SQL injection vulnerability that allows attackers to execute arbitrary database commands via unsanitized inputs.
OpenClaw contains an input validation bypass in its `tools.exec.safeBins` component, where GNU long-option abbreviations can be used to execute unauthorized commands.
The Centreon Open Tickets module on Central Server contains a critical vulnerability that could lead to unauthorized system access or compromise.
PluXml CMS is vulnerable to session fixation, allowing unauthenticated attackers to pre-set a victim's session ID and hijack the session after the victim logs in.
SODOLA SL902-SWTGW124AS firmware generates predictable MD5-based session identifiers, allowing attackers to forge authenticated sessions and bypass the login flow.
A lack of authentication in OCPP WebSocket endpoints allows unauthenticated attackers to impersonate charging stations and manipulate charging network data.
Unauthenticated attackers can impersonate EV charging stations due to missing authentication mechanisms in OCPP WebSocket endpoints, enabling data manipulation.
OCPP WebSocket endpoints lack authentication, allowing unauthenticated attackers to impersonate legitimate charging stations and issue unauthorized commands.
Unauthenticated attackers can perform station impersonation and manipulate backend data due to a lack of authentication on OCPP WebSocket endpoints.
WebSocket endpoints lack authentication, allowing unauthenticated attackers to impersonate charging stations and manipulate backend data via the Open Charge Point Protocol.
Unauthenticated attackers can perform station impersonation and manipulate backend data due to a lack of proper authentication on OCPP WebSocket endpoints.
An improper input validation vulnerability in Centreon Open Tickets allows attackers to submit malicious data that could compromise the Central Server.
Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' parameter
Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the catid parameter
Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pt' parameter
Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'val' parameter
The WP Mail Logging plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references
phpMyFAQ is an open source FAQ web application
Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the hosting_id parameter
The Tutor LMS â eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon_code' parameter in all versions up to, and including, 3
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function in all versions up to, and including, 4
SPIP versions prior to 4
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6
osCommerce 2
osCommerce 2
osCommerce 2
nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm
SPIP versions prior to 4
Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker
A flaw has been found in itsourcecode School Management System 1
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite
Apache::SessionX versions through 2
A high-severity vulnerability in Kaniko, a container image builder, could allow attackers to compromise build environments within Kubernetes clusters.
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1
OpenEMR is a free and open source electronic health records and medical practice management application
Gradio is an open-source Python package designed for quick prototyping
A vulnerability was found in Tenda F453 1
A vulnerability was determined in Tenda F453 1
A vulnerability was identified in Tenda F453 1
A security flaw has been discovered in Tenda F453 1
A weakness has been identified in Tenda F453 1
Gradio is an open-source Python package designed for quick prototyping
hoppscotch is an open source API development ecosystem
telnetd in GNU inetutils through 2
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0
Blind SQL Injection via unsanitized array keys in Service Dependencies deletion
Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields
Statmatic is a Laravel and Git powered content management system (CMS)
Initiative is a self-hosted project management platform
PublicCMS v5
Statmatic is a Laravel and Git powered content management system (CMS)
IM-LogicDesigner module of intra-mart Accel Platform contains insecure deserialization issue
Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242)
A vulnerability exists in Copeland XWEB Pro version 1
CleverTap Web SDK version 1
CleverTap Web SDK version 1
Golioth Pouch version 0
Initiative is a self-hosted project management platform
Kiteworks is a private data network (PDN)
Unitree Go2 firmware versions V1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
An OS command injection vulnerability exists in XWEB Pro version 1
Statmatic is a Laravel and Git powered content management system (CMS)
In OCaml before 4
An issue in fastCMS before v
The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing
Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology Ltd
Discourse is an open source discussion platform
Discourse is an open source discussion platform
Due to missing nil check, sending 0x0a-0x0f HTTP/2 frames will cause a running server to panic
Umbraco Engage, a business intelligence platform, is affected by a high-severity vulnerability that could lead to unauthorized platform access.
Initiative is a self-hosted project management platform
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
Crypt::SysRandom::XS versions before 0
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests
A flaw was found in REXML
osctrl is an osquery management solution
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby
Zulip is an open-source team collaboration tool
Actual is a local-first personal finance tool
SODOLA SL902-SWTGW124AS firmware versions through 200