CVE-2026-35273
An unauthenticated, easily exploitable vulnerability in the PeopleSoft Updates Environment Management component allows for complete system takeover via HTTP.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Friday's disclosures lead with CVE-2026-49257, a CVSS 10 vulnerability in Apache Pinot (via mcp-pinot), the day's most severe issue. Volume fell sharply from the prior day, with critical CVEs dropping to 1 (down 98%) and high-priority CVEs to 41 (down 54%). Five vulnerabilities carry confirmed active exploitation, including CVE-2026-35273 in Oracle PeopleSoft Enterprise PeopleTools, CVE-2026-20253 in Splunk Enterprise and Cloud Platform, and CVE-2026-20262 in Cisco Catalyst SD-WAN Manager. Enterprise data, identity, and network-management platforms dominate the affected systems, with several flaws enabling remote code execution and authentication bypass. No vendor patches were available at disclosure time, so teams should prioritize compensating controls and monitor for vendor fixes.
Immediate action: Prioritize Apache Pinot deployments exposed via mcp-pinot, along with the actively exploited Oracle PeopleSoft, Splunk, Cisco Catalyst SD-WAN Manager, LiteSpeed cPanel, and Joomla Content Editor installations. No vendor patches were available at disclosure, so apply access restrictions, network segmentation, and exploitation monitoring while tracking advisories for fixes.
An unauthenticated, easily exploitable vulnerability in the PeopleSoft Updates Environment Management component allows for complete system takeover via HTTP.
A symlink mishandling vulnerability in the LiteSpeed cPanel plugin allows users with limited access to escalate privileges on shared hosting environments.
An improper access control vulnerability in the Widget Factory Joomla Content Editor allows unauthorized users to perform restricted actions.
Splunk Enterprise and Cloud Platform contain an authentication bypass vulnerability in a PostgreSQL sidecar service, allowing unauthenticated users to create or truncate arbitrary files.
Cisco Catalyst SD-WAN Manager contains an arbitrary file write vulnerability in its web UI, allowing authenticated remote attackers to escalate privileges to root.
The mcp-pinot server defaults to an unauthenticated configuration, allowing any network-adjacent attacker to execute arbitrary SQL and mutate table configurations.
Authenticated privilege escalation in the U.S. GAO EPDS and CBCA EDS docketing systems via an unverified client-supplied 'epds_role_id' parameter (CWE-602).
A use-after-free vulnerability exists in the Metrics component of Google Chrome, which may allow for arbitrary code execution.
An integer overflow vulnerability in the V8 JavaScript engine of Google Chrome may lead to arbitrary code execution.
A SQL injection vulnerability exists in pgAdmin 4 within dialog templates that render the "COMMENT ON" command, potentially allowing unauthorized database manipulation.
A critical vulnerability has been found in the Wifi-soft UniBox Controller, which could lead to unauthorized system access.
A critical security vulnerability has been identified in the Wifi-soft UniBox Controller that may allow for unauthorized system compromise.
A critical security vulnerability has been identified in the Wifi-soft UniBox Controller that requires immediate administrative attention to mitigate potential unauthorized access.
An out-of-bounds write vulnerability in FFmpeg's MagicYUV decoder allows for denial-of-service and potential remote code execution via malicious video files.
A critical vulnerability has been identified in the Tenda FH1201 router, potentially allowing unauthorized system impact.
A critical vulnerability has been identified in the Tenda FH1205 router, posing a significant security risk to affected network environments.
A critical security vulnerability has been identified in the Tenda FH1205 router, which may permit unauthorized system-level actions.
A critical vulnerability has been discovered in the Tenda FH1203 router, creating a significant security risk for the device.
A security vulnerability has been identified in the D-Link DIR-619L router, potentially impacting device security and integrity.
A critical security vulnerability has been identified in the D-Link DIR-619L router, potentially allowing for unauthorized system impact.
A critical security flaw has been discovered in the D-Link DIR-665 router, which may expose the device to unauthorized exploitation.
A critical vulnerability has been identified in the D-Link DIR-825 router, potentially permitting unauthorized system-level actions.
A security vulnerability has been identified in the D-Link DIR-825 router, requiring immediate administrative attention to prevent unauthorized access.
A security vulnerability has been discovered in the D-Link DIR-815 router, posing a risk of potential unauthorized access.
AutoGPT is a workflow automation platform for creating and managing continuous artificial intelligence agents.
PraisonAI versions before 4.5.128 contain an arbitrary shell command execution vulnerability due to insecure handling of approval modes.
A path traversal vulnerability in PraisonAI's MultiAgentMonitor allows attackers to read, write, or overwrite arbitrary files.
A critical vulnerability has been identified in the H3C GR-5400AX router, potentially allowing unauthorized access or control.
A security vulnerability has been identified in the H3C GR-3000AX router that may pose a risk to network security.
A critical vulnerability has been discovered in the TOTOLINK EX1200T range extender, posing a significant risk to network security.
A critical vulnerability found in the TOTOLINK EX1200T range extender requires immediate remediation to prevent potential unauthorized access.
A critical vulnerability has been identified in the TOTOLINK EX1200T range extender, necessitating an immediate security review and update.
A critical vulnerability has been identified in TOTOLINK T10 routers that may allow for unauthorized system compromise.
A critical vulnerability has been identified in TOTOLINK T10 routers that may allow for unauthorized system compromise.
A critical vulnerability has been identified in the TOTOLINK EX1200T range extender that may allow for unauthorized system compromise.
A vulnerability has been identified in the TOTOLINK EX1200T range extender that may allow for unauthorized system compromise.
A vulnerability has been identified in the TOTOLINK EX1200T range extender that may allow for unauthorized system compromise.
A critical security vulnerability has been identified in the TOTOLINK X15 router, potentially allowing for unauthorized system impact.
A critical security vulnerability has been identified in the TOTOLINK A702R router, potentially allowing for unauthorized system impact.
A critical security vulnerability has been identified in the TOTOLINK A3002RU router, potentially allowing for unauthorized system impact.
A critical security vulnerability has been identified in the TOTOLINK A3002R router, potentially allowing for unauthorized system impact.
A critical security vulnerability has been identified in the TOTOLINK X15 router, potentially allowing for unauthorized system impact.
A critical security vulnerability has been identified in the TOTOLINK EX1200T firmware that may allow for unauthorized system compromise.
A security vulnerability has been identified in the TOTOLINK A3002RU router firmware that could potentially lead to unauthorized system access.
A security flaw has been discovered in the TOTOLINK A3002R router that may permit unauthorized access or control by an attacker.
A security vulnerability in the TOTOLINK X15 device firmware may allow for unauthorized access to the system.
A critical vulnerability has been identified in the TOTOLINK EX1200T that may lead to unauthorized system-level access.