CVE-2021-39935
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Tuesday's vulnerability disclosures reveal 27 CVEs affecting SAP, Microsoft, Apple, and several open-source projects. Critical disclosures dropped 50% from the prior day to 2, while high-priority CVEs surged 150% to 25. A maximum-severity SAP WhatsApp bridge flaw (CVE-2026-2577, CVSS 10.0) and a critical EFM/iptime router vulnerability (CVE-2026-2550, CVSS 9.8) stand out among the new disclosures. Microsoft Windows and Office account for six actively exploited vulnerabilities, alongside confirmed exploitation targeting GitLab, Sangoma FreePBX, and Apple OS. No patches are currently available for the disclosed CVEs, requiring organizations to prioritize compensating controls and monitoring.
Immediate action: Prioritize compensating controls for Microsoft Windows and Office systems, SAP WhatsApp bridge integrations, and Apple OS environments where active exploitation is confirmed. With 0% patch availability across all disclosures, implement network segmentation, enhanced monitoring, and access restrictions for affected products until vendor patches are released.
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Sangoma FreePBX OS Command Injection Vulnerability - Active in CISA KEV catalog.
Sangoma FreePBX Improper Authentication Vulnerability - Active in CISA KEV catalog.
React Native Community CLI OS Command Injection Vulnerability - Active in CISA KEV catalog.
SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
A protection mechanism failure in the MSHTML Framework allows an unauthenticated attacker to bypass security features over a network, potentially leading to unauthorized system access.
Microsoft Windows NULL Pointer Dereference Vulnerability - Active in CISA KEV catalog.
A protection mechanism failure in the Windows Shell allows an unauthenticated attacker to bypass security features over a network connection.
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate their privileges locally on the affected system.
A type confusion vulnerability in the Desktop Window Manager (DWM) allows an authorized local attacker to elevate their privileges to a higher level.
A security feature bypass vulnerability in Microsoft Office Word exists due to reliance on untrusted inputs, allowing an unauthorized local attacker to circumvent security protections.
A memory corruption vulnerability in Apple software was addressed through improved state management to prevent potential exploitation.
Microsoft Configuration Manager SQL Injection Vulnerability - Active in CISA KEV catalog.
Notepad++ Download of Code Without Integrity Check Vulnerability - Active in CISA KEV catalog.
The Nanobot WhatsApp bridge component exposes an unauthenticated WebSocket server on all network interfaces, allowing remote attackers to hijack sessions and intercept real-time communications.
A critical unrestricted file upload vulnerability in the iptime A6004MX router allows remote attackers to execute arbitrary code via the commit_vpncli_file_upload function.
The Zarinpal Gateway for WooCommerce plugin for WordPress is vulnerable to improper access control, allowing unauthorized modification of payment status updates.
A vulnerability has been identified in Unidocs ezPDF DRM Reader and ezPDF Reader 2, which could allow for unauthorized code execution or data access.
The WowRevenue plugin for WordPress contains a missing capability check in its installation function, allowing unauthorized users to install and activate arbitrary plugins.
The WP Maps plugin for WordPress is vulnerable to Local File Inclusion (LFI) in versions up to 4, allowing attackers to access sensitive server-side files.
A security flaw has been identified in the Tosei Self-service Washing Machine 4, which could allow for unauthorized access or manipulation of the device's operational functions.
A security weakness has been identified in Total VPN that could allow an attacker to compromise the confidentiality or integrity of the VPN service.
A security flaw has been discovered in Flos Freeware Notepad2 that could potentially allow for unauthorized code execution or system compromise.
SmarterTools SmarterMail is vulnerable to Cross-Site Scripting (XSS) via MAPI requests in versions prior to 9526, potentially allowing session hijacking.
A security flaw exists within the Alps Alpine Bluetooth stack utilized in Bosch Infotainment ECUs, potentially allowing for remote exploitation via Bluetooth.
A vulnerability in the Alps Alpine Bluetooth stack used in Bosch Infotainment ECUs poses a risk of remote exploitation, affecting the security of the vehicle's infotainment system.
The Alps Alpine Bluetooth stack in Bosch Infotainment ECUs contains a high-severity flaw that could lead to unauthorized system access or denial of service.
The eNet SMART HOME server version 2 contains a security flaw that could allow for unauthorized access or system manipulation.
A Reflected Cross-Site Scripting (XSS) vulnerability in ENOVIAvpm Web Access allows attackers to execute arbitrary scripts in a user's browser session.
A high-severity security flaw has been identified in the Intelbras VIP 3260 Z IA 2 camera, which could permit unauthorized access or system interference.
A Use of Uninitialized Variable vulnerability in SOLIDWORKS eDrawings allows arbitrary code execution when a user opens a specially crafted EPRT file.
An Out-Of-Bounds Read vulnerability in SOLIDWORKS eDrawings can lead to arbitrary code execution when processing a maliciously crafted EPRT file.
An Out-Of-Bounds Write vulnerability in the EPRT file reading procedure of SOLIDWORKS eDrawings allows for arbitrary code execution via crafted files.
Mattermost Desktop App versions 6 and earlier are affected by a high-severity vulnerability that could compromise the security of the communication platform.
A security flaw in yued-fe LuLu UI versions up to 3 allows for potential remote exploitation of the user interface components.
A high-severity vulnerability exists in the zhanghuanhao LibrarySystem through version 1, potentially allowing for unauthorized system access.
Smoothwall Express 3
Smoothwall Express 3
Smoothwall Express 3
A high-severity security vulnerability has been detected in Wavlink WL-NU516U1 devices, affecting firmware versions up to 130 and 260.
A security vulnerability has been identified in the Wavlink WL-NU516U1 firmware version 20251208, posing a risk to device integrity.