Critical vulnerabilities, curated daily for security professionals
π
Archived Security Brief
Wednesday's disclosures center on widespread web platform and edge device exposure, with WordPress plugins, D-Link routers, and Eclipse developer tooling driving the critical caseload. Critical CVEs fell 57% to 15 while high-priority issues rose 42% to 92, indicating broader but less severe activity than the prior day. Notable entries include CVE-2026-7411 (CVSS 10) in Eclipse BaSyx Java Server SDK, CVE-2026-7853 and CVE-2026-7854 (CVSS 9.8) in D-Link DI series routers, and CVE-2026-27960 (CVSS 9.8) in Intel OpenCTI Platform. Remote code execution and unauthenticated access patterns dominate, affecting industrial automation, network edge equipment, and threat-intelligence infrastructure. Patch availability remains at 0% for the disclosed set, and eight CVEs carry confirmed active exploitation including issues in Samsung MagicINFO, SimpleHelp, and ConnectWise ScreenConnect.
Critical CVEs decreased 57% day-over-day to 15, reflecting a narrower critical caseload than Tuesday's 35
High-priority CVEs increased 42% to 92, signaling broader exposure across the CVSS 7.0-8.9 band
Unauthenticated remote code execution affects D-Link DI routers (CVE-2026-7853, CVE-2026-7854) and EFM ipTIME NAS1dual (CVE-2026-7834), alongside multiple WordPress plugin flaws
Patch availability stands at 0% across the disclosed set, requiring compensating controls for exposed WordPress, D-Link, and Intel OpenCTI deployments
Eight CVEs are actively exploited, including Samsung MagicINFO 9 Server, SimpleHelp, ConnectWise ScreenConnect, and a Microsoft Windows issue (CVE-2026-32202)
Immediate action: Prioritize isolation and monitoring of Eclipse BaSyx, D-Link DI, WordPress, and Intel OpenCTI deployments while reviewing exposure on actively exploited Samsung MagicINFO, SimpleHelp, and ConnectWise ScreenConnect instances. With patch availability at 0% for the new disclosures, apply network segmentation, restrict administrative interfaces, and enable enhanced logging until vendor fixes are released.
How to read this brief
CVSS score (e.g. 9.1) β severity from 0β10. Red marks critical (9+), orange high (7β8.9).
Exploitability β how hard the flaw is to attack, read from the CVSS vector:
Network / Adjacent / Local / Physical β how close an attacker must get. Network means reachable over the internet.
No / Low / High privileges β the access they need first. No privileges means no login required.
No interaction / User interaction β whether a victim has to do something (open a file, click a link). No interaction means fully automatable.
The lower the bar on all three, the easier to exploit at scale β βNetwork Β· No privileges Β· No interactionβ is the worst case: hit from anywhere, no credentials, no victim action.
π΄ Actively exploited β confirmed under attack in the wild (CISAβs Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS Β· Nth percentile β FIRST.orgβs estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% β a statistical signal itβs unusually likely to be targeted, separate from whether attacks are confirmed.
π‘ Tip: Swipe CVE cards left to β star, right to β remove
Palo Alto NetworksPAN-OS (PA-Series and VM-Series firewalls)
Unauthenticated RCE in Palo Alto PAN-OS firewalls
A buffer overflow in the User-ID Authentication Portal lets an unauthenticated network attacker execute arbitrary code as root on PA-Series and VM-Series firewalls. Palo Alto Networks confirms limited exploitation in the wild against portals reachable from untrusted IP space.
The Geeky Bot plugin for WordPress contains a missing authorization vulnerability that allows unauthenticated attackers to achieve remote code execution via arbitrary plugin installation.
An authentication bypass vulnerability in MoreConvert Pro for WordPress allows unauthenticated attackers to hijack administrator accounts by manipulating email verification tokens.
A buffer overflow vulnerability in the D-Link DI-8100 POST parameter handler allows remote attackers to execute arbitrary code via the url_rule.asp function.
Eclipse Equinox OSGi version 3.7.2 and earlier contains a remote code execution vulnerability allowing unauthenticated attackers to execute commands via the console interface.
OpenCTI contains a privilege escalation vulnerability allowing unauthenticated attackers to query the API as any user, including the default administrator.
A remote OS command injection vulnerability in the Totolink A8000RU allows unauthenticated attackers to execute arbitrary commands via the `setAppFilterCfg` function.
The GoAhead web server on MeiG Smart FORGE_SLT711 devices allows unauthenticated remote attackers to perform OS command injection via the /action/SetRemoteAccessCfg endpoint.
Saleswonder LLC's WebinarIgnition plugin for WordPress is vulnerable to Blind SQL Injection, allowing unauthenticated attackers to extract database information.
OpenClaw contains an input validation vulnerability allowing external hook metadata to be enqueued as trusted system events, leading to privilege escalation.
Prometheus, an open-source monitoring system, is affected by a security vulnerability that may impact its time-series database and monitoring operations.
The Royal Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'status' parameter in the wpr_update_form_action_meta AJAX action in all versions up to, and including, 1
The GeekyBot β Generate AI Content Without Prompt, Chatbot and Lead Generation plugin for WordPress is vulnerable to SQL Injection via the 'attributekey' parameter in versions up to, and including, 1
The Form Maker by 10Web β Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to SQL Injection via the 'inputs' parameter in versions up to, and including, 1
The Forminator Forms β Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 1
CVE-2023-54346
7.5π Late Disclosure
WordPressPlugin Backup
WordPress Plugin Backup Migration 1
CVE-2026-7332
7.2
WordPressis vulnerable
The LatePoint β Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'booking_form_page_url' parameter in all versions up to, and including, 5
CVE-2026-7448
7.2
WordPressis vulnerable
The LatePoint β Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'first_name' parameter in all versions up to, and including, 5
CVE-2026-40563
8.1
Apache Atlas
Apacheendpoint that
Description:
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Atlas
Apache Atlas exposes a DSL search endpoint that accepts user-supplied query strings
CVE-2026-29169
7.5
HTTPHTTP Server
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2
CVE-2026-43869
7.3
ApacheThrift
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift
CVE-2026-29168
7.3
HTTPHTTP Server
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server'sΒ mod_md via OCSP response data
BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS option handler in networking/udhcp/d6_dhcpc
n8n is an open source workflow automation platform
CVE-2026-7855
8.8
D-LinkDI
A vulnerability was detected in D-Link DI-8100 16
CVE-2026-7776
7.5
BoundaryMultiple Products
Boundary Community Edition and Boundary Enterprise (βBoundaryβ) workers are vulnerable to a denial-of-service condition during node enrollment TLS handshakes
CVE-2026-7810
7.3
InforMultiple Products
A flaw has been found in UsamaK98 python-notebook-mcp up to a05a232815809a7e425b5fa7be26e0d4369894c2
CVE-2025-47407
7.8
Signalprocessor due
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level
CVE-2026-43532
7.7
Discordevent cover
OpenClaw versions 2026
CVE-2026-7851
7.2
D-LinkDI
A vulnerability was identified in D-Link DI-8100 16
CVE-2026-7856
7.2
D-LinkDI
A flaw has been found in D-Link DI-8100 16
CVE-2026-7857
7.2
D-LinkDI
A vulnerability has been found in D-Link DI-8100 16
An issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary code via the shutdownMachine and putMachineToSleep functions in PostCompressionActions
CVE-2025-47405
7.8
MemoryMultiple Products
Memory corruption when processing camera sensor input/output control codes with invalid output buffers
CVE-2025-47408
7.8
MemoryMultiple Products
Memory corruption when another driver calls an IOCTL with invalid input/output buffer
CVE-2026-24082
7.8
MemoryMultiple Products
Memory Corruption when copying data from a freed source while executing performance counter deselect operation
CVE-2026-42436
7.7
OpenClawMultiple Products
OpenClaw before 2026
CVE-2026-42438
7.7
OpenClawMultiple Products
OpenClaw versions 2026
CVE-2026-43527
7.7
OpenClawMultiple Products
OpenClaw before 2026
CVE-2026-43573
7.7
OpenClawMultiple Products
OpenClaw before 2026
CVE-2026-42997
7.7
IronicMultiple Products
An issue was discovered in idrac in OpenStack Ironic before 35
The fast-uri library improperly handles percent-encoded authority delimiters during normalization, leading to potential injection or parsing errors during re-serialization.