Critical vulnerabilities, curated daily for security professionals
📊
Archived Security Brief
Friday's vulnerability disclosures include a CVSS 10.0 flaw in Copeland XWEB Pro (CVE-2026-21718) and a CVSS 9.9 Google Cloud service vulnerability (CVE-2026-27941), alongside critical issues in Xerox FreeFlow Core, Langflow, and EverShop. Critical CVEs jumped to 18, a 125% increase from the prior day's 8, while 100 high-priority vulnerabilities held steady. Remote code execution and authentication bypass patterns dominate the critical findings, affecting enterprise infrastructure from Totolink routers to OpenStack Vitrage deployments. Cisco Catalyst SD-WAN and multiple Microsoft Windows components are confirmed under active exploitation across 18 KEV entries. Patch availability remains at 0%, requiring organizations to prioritize compensating controls and network segmentation for affected systems.
CVSS 10.0 vulnerability in Copeland XWEB Pro (CVE-2026-21718) and CVSS 9.9 Google Cloud service flaw (CVE-2026-27941) require immediate risk assessment
18 critical CVEs disclosed, up 125% from 8 the prior day, spanning Microsoft, Xerox, HP, and Langflow products
100 high-priority CVEs remained consistent with the prior day's volume across the disclosure pipeline
Remote code execution and authentication bypass flaws affect Totolink N300RH routers, EverShop e-commerce, and OpenStack Vitrage
0% patch availability across all disclosed vulnerabilities — compensating controls and network isolation are essential
18 actively exploited vulnerabilities include Cisco Catalyst SD-WAN (CVSS 10.0), multiple Microsoft Windows components, and Roundcube Webmail
Immediate action: Prioritize network segmentation and access restrictions for Copeland XWEB Pro, Google Cloud services, Cisco Catalyst SD-WAN, and Microsoft Windows systems confirmed under active exploitation. With 0% patch availability, implement compensating controls including WAF rules, privilege reduction, and enhanced monitoring for all affected products until vendor patches are released.
How to read this brief
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
No / Low / High privileges — the access they need first. No privileges means no login required.
No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.
A protection mechanism failure in the MSHTML Framework allows an unauthenticated attacker to bypass security features over a network, potentially leading to unauthorized system access.
A security feature bypass vulnerability in Microsoft Office Word exists due to reliance on untrusted inputs, allowing an unauthorized local attacker to circumvent security protections.
Google Chrome is vulnerable to a "Use After Free" condition in its CSS engine, which could allow a remote attacker to execute arbitrary code via a crafted webpage.
FileZen is affected by a high-severity OS command injection vulnerability that allows a threat actor to execute arbitrary commands on the underlying operating system.
A critical flaw in Hoppscotch allows unauthenticated attackers to overwrite infrastructure configurations via the onboarding endpoint, leading to SSO hijacking and full credential exposure.
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE.
This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.
Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads
https://www.support.xerox.com/en-us/product/core/downloads
OpenLIT GitHub Actions workflows are vulnerable to unauthorized code execution via forked pull requests, leading to the potential theft of sensitive secrets and cloud service keys.
The Listee theme for WordPress allows unauthenticated registration as an Administrator due to a broken validation check in the listee-core plugin's registration function.
ZenTaoPMS is vulnerable to a directory traversal flaw in its AI module, enabling unauthenticated attackers to achieve remote code execution via malicious file uploads.
The EverShop eCommerce platform leaks password reset tokens in API responses, enabling unauthenticated attackers to bypass authentication and take over any user account.
A remote OS command injection vulnerability exists in the Totolink N300RH Web Management Interface due to improper handling of the webWlanIdx parameter.
OpenStack Vitrage contains a code execution vulnerability in its query parser, allowing authenticated API users to execute arbitrary code on the service host.
An unauthenticated OS command injection vulnerability in Copeland XWEB Pro allows remote code execution via a crafted request to the libraries installation route.
In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was denied.
A lack of authentication in OCPP WebSocket endpoints allows unauthenticated attackers to impersonate charging stations and manipulate charging network data.
Unauthenticated attackers can impersonate EV charging stations due to missing authentication mechanisms in OCPP WebSocket endpoints, enabling data manipulation.
WebSocket endpoints lack authentication, allowing unauthenticated attackers to impersonate charging stations and manipulate backend data via the Open Charge Point Protocol.
Unauthenticated attackers can perform station impersonation and manipulate backend data due to a lack of proper authentication on OCPP WebSocket endpoints.
WPGraphQL provides a GraphQL API for WordPress sites
CVE-2026-2252
7.5
performFreeFlow Core
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references
CVE-2026-1779
8.1
WordPressis vulnerable
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5
A vulnerability in the SNMP subsystem of Cisco Nexus 9000 Series switches could allow an authenticated attacker to cause a denial of service condition.
A vulnerability in the EVPN Layer 2 ingress packet processing of Cisco Nexus switches allows an adjacent attacker to trigger a disruptive Layer 2 traffic loop.
The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0
CVE-2026-1565
8.8
WordPressis vulnerable
The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'WPUF_Admin_Settings::check_filetype_and_ext' function and in the 'Admin_Tools::check_filetype_and_ext' function in all versions up to, and including, 4
A privilege escalation vulnerability in Cisco Catalyst SD-WAN Manager allows an authenticated, local attacker with low-level privileges to gain root access to the underlying operating system.
The minimatch library, a JavaScript utility for glob matching, is vulnerable to a flaw that could result in application instability or unauthorized processing of malicious expressions.
A second high-severity vulnerability in the minimatch JavaScript library could lead to system resource exhaustion or security bypasses when processing glob expressions.
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6
VMware Aria Operations contains a stored cross-site scripting vulnerability
CVE-2026-20128
7.5
CiscoCatalyst SD
A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain DCA user privileges on an affected system
CVE-2026-20010
7.4
CiscoNX
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly
CVE-2026-20033
7.4
CiscoNexus
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device
CVE-2026-3261
7.3
HPof the
A flaw has been found in itsourcecode School Management System 1
CVE-2026-0980
8.3
RedSatellite
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite
CVE-2026-26984
8.7
Archand Imaging
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research
CVE-2026-25164
8.1
HPMultiple Products
OpenEMR is a free and open source electronic health records and medical practice management application
CVE-2025-71057
8.2
D-LinkWireless
Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1
CVE-2026-26985
8.1
Archand Imaging
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research
CVE-2026-25476
7.5
HPMultiple Products
OpenEMR is a free and open source electronic health records and medical practice management application
CVE-2026-3271
8.8
TendaF453
A vulnerability was found in Tenda F453 1
CVE-2026-3272
8.8
TendaF453
A vulnerability was determined in Tenda F453 1
CVE-2026-3273
8.8
TendaF453
A vulnerability was identified in Tenda F453 1
CVE-2026-3274
8.8
TendaF453
A security flaw has been discovered in Tenda F453 1
CVE-2026-3275
8.8
TendaF453
A weakness has been identified in Tenda F453 1
CVE-2026-27831
7.5
DNSMultiple Products
rldns is an open source DNS server
CVE-2026-26955
8.8
UnknownMultiple Products
FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-26965
8.8
UnknownMultiple Products
FreeRDP is a free implementation of the Remote Desktop Protocol
CVE-2026-0752
8
versionshas remediated
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16
CVE-2026-28216
8.3
UnknownMultiple Products
hoppscotch is an open source API development ecosystem
CVE-2026-25191
7.8
FinalCodepath
The installer of FinalCode Client provided by Digital Arts Inc
CVE-2025-14511
7.5
versionshas remediated
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12
CVE-2026-1388
7.5
versionshas remediated
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9
CVE-2026-1662
7.5
versionshas remediated
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14
CVE-2026-28372
7.4
inetutilsin release
telnetd in GNU inetutils through 2
CVE-2026-27850
7.5
sourceMultiple Products
Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source port 5222, exposing all services which are normally only accessible through the local network
CVE-2026-27635
7.5
collectionMultiple Products
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing
CVE-2026-3071
8.4
fromMultiple Products
Deserialization of untrusted data in the LanguageModel class of Flair from versions 0
CVE-2026-3172
8.1
BufferMultiple Products
Buffer overflow in parallel HNSW index build in pgvector 0
CVE-2026-28136
7.6
VeronaLabs WP SMSMultiple Products
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs WP SMS wp-sms allows SQL Injection
CVE-2026-28193
8.8
YouTrackMultiple Products
In JetBrains YouTrack before 2025
CVE-2026-25746
8.8
prescriptionMultiple Products
OpenEMR is a free and open source electronic health records and medical practice management application
CVE-2026-27976
8.8
ArchMultiple Products
Zed, a code editor, has an extension installer allows tar/gzip downloads
CVE-2026-27952
8.8
UnknownMultiple Products
Agenta is an open-source LLMOps platform
CVE-2026-27961
8.8
UnknownMultiple Products
Agenta is an open-source LLMOps platform
CVE-2026-28274
8.7
UnknownMultiple Products
Initiative is a self-hosted project management platform
CVE-2026-27730
8.6
UnknownMultiple Products
esm
CVE-2026-26938
8.6
TemplateMultiple Products
Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) exists in Workflows in Kibana which could allow an attacker to read arbitrary files from the Kibana server filesystem, and perform Server-Side Request Forgery (SSRF) via Code Injection (CAPEC-242)
CVE-2026-25085
8.6
ProMultiple Products
A vulnerability exists in Copeland XWEB Pro version 1
CVE-2025-67601
8.3
RancherMultiple Products
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts
CVE-2026-24890
8.1
patientMultiple Products
OpenEMR is a free and open source electronic health records and medical practice management application
CVE-2026-25136
8.1
UnknownMultiple Products
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies
CVE-2026-23750
8.1
PouchMultiple Products
Golioth Pouch version 0
CVE-2026-28275
8.1
UnknownMultiple Products
Initiative is a self-hosted project management platform
CVE-2026-20742
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-20902
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-20910
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-21389
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-24517
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-24689
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-24695
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-25109
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-25111
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-25195
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-20764
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-23702
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-24452
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-25037
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-25105
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-25196
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-25721
8
ProMultiple Products
An OS command injection
vulnerability exists in XWEB Pro version 1
CVE-2026-3037
8
ProMultiple Products
An OS command injection vulnerability exists in XWEB Pro version 1
CVE-2026-28364
7.9
OCamlMultiple Products
In OCaml before 4
CVE-2026-23703
7.8
FinalCodeMultiple Products
The installer of FinalCode Client provided by Digital Arts Inc
CVE-2026-26682
7.8
UnknownMultiple Products
An issue in fastCMS before v
CVE-2026-28211
7.8
UnknownMultiple Products
The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing
CVE-2026-1442
7.8
LGMultiple Products
Since the encryption algorithm used to protect firmware updates is itself encrypted using key material available to an attacker (or anyone paying attention), the firmware updates may be altered by an unauthorized user, and then trusted by a Unitree product, such as the Unitree Go2 and other models
CVE-2026-27706
7.7
UnknownMultiple Products
Plane is an an open-source project management tool
CVE-2025-14343
7.6
Dokuzsoft TechnologyMultiple Products
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft Technology Ltd