Critical vulnerabilities, curated daily for security professionals
📊
Archived Security Brief
Thursday's brief is dominated by remote code execution flaws in infrastructure management and serverless platforms, led by Roxy-WI (CVE-2026-45552, CVE-2026-45558, CVE-2026-45556, all CVSS 9.9) and the Fission Kubernetes framework (CVE-2026-50545, CVE-2026-50563, CVE-2026-50564, CVSS 9.9). The disclosures include 12 critical CVEs, down 33% from the prior day's 18, alongside 37 high-priority CVEs, up 37% from 27. Enterprise software is also affected, with CVE-2026-35273 (CVSS 9.8) in Oracle PeopleSoft PeopleTools and CVE-2026-20253 (CVSS 9.8) in Splunk Enterprise and Cloud Platform. The activity centers on unauthenticated code execution against management interfaces, WordPress plugins, and container orchestration components. Patch availability is currently 0% across this set, so affected operators should prioritize access restriction and compensating controls until vendor fixes ship.
Patch availability stands at 0% for this set, affecting infrastructure management, serverless, and enterprise platforms
8 CVEs carry confirmed active exploitation, including flaws in Fortinet, Check Point, SolarWinds Serv-U, and Cisco SD-WAN
Immediate action: Prioritize Roxy-WI, Fission framework, Oracle PeopleSoft, and Splunk deployments, and restrict network access to these management and serverless interfaces immediately. With no patches yet available for the critical set, apply access controls, monitoring, and segmentation while tracking vendor advisories. Separately, the actively exploited Fortinet, Check Point, SolarWinds, Arista, and Cisco issues should be remediated where fixes exist.
How to read this brief
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
No / Low / High privileges — the access they need first. No privileges means no login required.
No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through 7.0.21, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.
An authentication bypass vulnerability in various Fortinet products allows attackers to log into devices registered to other accounts if FortiCloud SSO is enabled.
SolarWinds Serv-U is vulnerable to an uncontrolled resource consumption flaw allowing unauthenticated attackers to crash the service via specially crafted POST requests.
LiteLLM contains a command injection vulnerability in its MCP server test endpoints that, when chained with a host header bypass, enables unauthenticated remote code execution.
Roxy-WI contains an authenticated arbitrary file write vulnerability in its WAF rule saving functionality, allowing for Remote Code Execution on managed load balancers.
The Doctreat Core plugin for WordPress contains an unauthenticated privilege escalation vulnerability allowing attackers to register as administrators.
An unauthenticated, easily exploitable vulnerability in the PeopleSoft Updates Environment Management component allows for complete system takeover via HTTP.
Splunk Enterprise and Cloud Platform contain an authentication bypass vulnerability in a PostgreSQL sidecar service, allowing unauthenticated users to create or truncate arbitrary files.
A route authorization bypass in the Fission router allows unauthorized callers to invoke functions by guessing their metadata, bypassing defined HTTPTrigger restrictions.
A validation flaw in Fission’s pod specification handling allows for the propagation of dangerous fields, leading to unauthorized control over generated pods.
A privilege management flaw in Fission’s Container Executor allows tenants to supply arbitrary pod specifications, creating potential for unauthorized privilege escalation.
Fission prior to 1.24.0 contains a vulnerability in its Environment CRD that allows for privilege escalation by propagating insecure podspec fields without validation.
An RBAC flaw in Fission allows tenants to run privileged containers under high-privilege service accounts, enabling container-sandbox escape and cluster-level compromise.
Boxlite prior to 0.9.0 fails to restrict kernel capabilities, allowing malicious code to remount directories as read-write and perform arbitrary write operations.
A path traversal vulnerability in the SimpleSAMLphp-casserver allows attackers to read and potentially execute arbitrary code via malicious file-based ticket manipulation.
Roxy-WI versions 8.2.6.4 and prior contain an authentication bypass vulnerability triggered by specific URL patterns, potentially allowing unauthenticated access to the API.
A critical authorization flaw in Roxy-WI allows authenticated users to execute unauthorized systemd operations, leading to potential privilege escalation.
A remote code execution vulnerability in Splunk products arises from unsafe deserialization of data, allowing low-privileged users to execute arbitrary code.
Dulwich contains an arbitrary file write vulnerability via NTFS-hostile tree entries, enabling remote code execution when checking out malicious Git repositories.
A use-after-free vulnerability in the NVIDIA Display Driver for Linux may allow a local attacker to cause a system crash or potentially execute arbitrary code.
An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows for directory traversal and potential arbitrary file manipulation.
A vulnerability in the OpenShift Route resource allows low-privileged users to inject malicious HAProxy configurations, potentially leading to cross-tenant traffic hijacking.
A command injection vulnerability in dracut's legacy DHCP path allows remote attackers on an adjacent network to execute code as root within the initramfs.
Flowise versions prior to 3.1.2 lack authentication middleware on CRUD endpoints for OpenAI Assistants Vector Store, enabling unauthorized data modification.
A stored cross-site scripting (XSS) vulnerability in Vinna Process Monitor allows authenticated attackers to inject malicious scripts, potentially compromising session credentials.
Red HatUndertow (JBoss EAP / Apache Camel / Data Grid / Fuse / Process Automation / SSO)
A request smuggling vulnerability in Red Hat Undertow allows attackers to bypass authentication and access restricted information by exploiting inconsistent HTTP header processing.
A Server-Side Request Forgery (SSRF) vulnerability in the Fedify TypeScript library allows attackers to bypass IP validation and interact with internal or restricted network resources.
Spring WS is vulnerable to Server-Side Request Forgery (SSRF) when processing WS-Addressing headers, allowing attackers to force outbound connections to arbitrary destinations.
A denial-of-service vulnerability in the Linux kernel ibmveth driver on IBM Power systems can cause network traffic to halt due to improper GSO handling.