CVE-2026-48558
SimpleHelp contains an authentication bypass in the OIDC flow, allowing unauthenticated attackers to forge tokens and gain full technician access without multi-factor authentication.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Friday's disclosures center on Microsoft cloud services and WordPress/WooCommerce commerce plugins, with several near-maximum-severity flaws affecting Azure OpenAI, Microsoft Entra, and Microsoft 365 Copilot. The brief covers 34 critical CVEs (up 21% from 28) and 78 high-priority CVEs (unchanged from the prior day). Notable entries include CVE-2026-45499 (CVSS 9.9) in Microsoft Azure OpenAI, CVE-2026-57100 (CVSS 9.9) in Microsoft Entra Provisioning Service, and CVE-2026-5524 (CVSS 9.8) in Divi Form Builder. The disclosures skew toward remote code execution and authentication weaknesses across cloud identity services and e-commerce plugins, exposing both enterprise SaaS deployments and self-hosted WooCommerce storefronts. No patches were available at disclosure time (0%), so teams should prioritize monitoring and compensating controls; two CVEs, in SimpleHelp and Microsoft Office SharePoint, have confirmed active exploitation.
Immediate action: Prioritize Microsoft cloud identity and AI services (Azure OpenAI, Entra, 365 Copilot) and self-hosted WooCommerce storefronts running the affected Divi, Novalnet, and Printcart plugins for immediate review. With no vendor patches available at disclosure, apply vendor mitigations, restrict exposure, and increase monitoring on the actively exploited SimpleHelp and SharePoint issues until fixes ship.
SimpleHelp contains an authentication bypass in the OIDC flow, allowing unauthenticated attackers to forge tokens and gain full technician access without multi-factor authentication.
An insecure deserialization vulnerability in Microsoft Office SharePoint allows an authorized attacker to execute arbitrary code over a network.
The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to unauthenticated arbitrary file deletion via improper path validation and nonce exposure.
The Divi Form Builder plugin for WordPress contains an arbitrary file upload vulnerability allowing unauthenticated remote code execution via insufficient file extension validation.
Auto_Bangumi contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to gain administrative access.
Dockwatch is vulnerable to unauthenticated OS command injection via improper session handling and unsanitized input in the composePath parameter.
An unauthenticated PHP object injection vulnerability exists in the Novalnet Payment Gateway for WooCommerce plugin, allowing potential remote code execution.
A Server-Side Request Forgery (SSRF) vulnerability in Azure OpenAI allows an authorized attacker to escalate privileges over a network.
A Server-Side Request Forgery (SSRF) vulnerability in the Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
An unauthenticated PHP object injection vulnerability in the Booktics plugin allows remote attackers to execute arbitrary code on affected systems.
An open redirect vulnerability in Microsoft 365 Copilot could be leveraged by an unauthorized attacker to facilitate privilege escalation over a network.
An integer overflow in the HPLIP hpcups processing path allows a remote attacker to escalate privileges or execute arbitrary code via specially crafted print data.
An unauthenticated remote code execution vulnerability in Blocksy Companion Pro allows attackers to execute arbitrary commands on the server.
Yonyou KSOA 9.0 is vulnerable to unauthenticated arbitrary file uploads via the ImageUpload servlet, allowing remote attackers to execute arbitrary code by uploading malicious JSP files.
Guangzhou Red Sea Cloud eHR contains an arbitrary file upload vulnerability in the PtFjk.mob servlet, allowing unauthenticated attackers to achieve remote code execution via malicious file uploads.
A path traversal vulnerability in the fast-mcp-telegram MCP server allows remote attackers to bypass session authentication via malicious HTTP Bearer tokens.
A use-after-free race condition in WatchGuard Fireware OS allows unauthenticated remote attackers to execute arbitrary code via the IKEv2 Mobile VPN.
A cryptographic flaw in Apereo CAS allows unauthenticated attackers to decrypt webflow conversation states by exploiting AES-GCM initialization vector reuse.
Authenticated SQL injection vulnerabilities in the UniFi Talk Application allow low-privileged network attackers to escalate privileges on the host device.
A critical SQL injection vulnerability in the Raera Destekz application allows unauthenticated attackers to execute arbitrary SQL commands.
GeekyBot is susceptible to an unauthenticated SQL injection vulnerability, allowing remote attackers to manipulate database queries.
An unauthenticated SQL injection vulnerability exists in Epsiloncool WP Fast Total Search versions 1.80.280 and earlier, allowing remote attackers to manipulate database queries.
Gardyn Home Firmware exposes a privileged iothubowner key, allowing attackers to access device connection info, execute arbitrary commands, and potentially pivot to other network devices.
An improper access control vulnerability in the UniFi Connect Application allows unauthenticated network attackers to execute arbitrary commands on the host device.
A missing validation vulnerability in the SUSE Rancher Fleet Helm Deployer allows authenticated tenants to access the fleet credentials of other tenants.
Improper input validation in the UniFi Access Application allows low-privileged network attackers to perform command injection and execute arbitrary code on the host device.
An improper input validation vulnerability in the Ubiquiti UniFi OS Server allows authenticated low-privilege network users to execute arbitrary commands on the host device via command injection.
A Server-Side Request Forgery (SSRF) vulnerability in the Ubiquiti UniFi Protect Application allows authenticated low-privilege network users to escalate privileges on the host device.
An arbitrary file upload vulnerability in Zozothemes Zegen allows authenticated attackers to execute malicious code.
A critical authentication bypass in TR7 Cyber Defense WAF-ASP enables unauthenticated attackers to perform unauthorized administrative actions.
An unauthenticated Cross-Site Scripting (XSS) vulnerability in ASE Pro allows attackers to inject malicious scripts into the web interface.
An Improper Access Control vulnerability in the Ubiquiti UniFi Access Application allows an authenticated attacker with high privileges to escalate their permissions on the host device.
An arbitrary code execution vulnerability exists in Rustaurius Five Star Business Profile and Schema versions 2.3.19 and earlier, exploitable by authenticated users with Editor capabilities.
An improper access control flaw in Ubiquiti Dream Machines running UniFi OS allows network-adjacent attackers to make unauthorized configuration changes to the device.
An unauthenticated arbitrary code execution vulnerability exists in BoldGrid W3 Total Cache versions 2.9.4 and earlier, allowing remote attackers to execute commands on the server.
A shellcode injection vulnerability in the obs tar_scm source service allows attackers to execute arbitrary code via a malicious _service file.
A heap buffer overflow vulnerability in the ANGLE graphics engine of Google Chrome for Mac allows for potential memory corruption and arbitrary code execution.
A use-after-free vulnerability in the V8 JavaScript engine of Google Chrome allows attackers to execute arbitrary code via a crafted web page.
A heap buffer overflow vulnerability exists in the Skia graphics library within Google Chrome, potentially allowing for arbitrary code execution.
A use-after-free vulnerability in Microsoft Edge (Chromium-based) allows an authorized attacker to execute arbitrary code over a network.
An incorrect authorization vulnerability in Microsoft Exchange Online permits an authorized attacker to elevate privileges over a network.
A PHP Object Injection vulnerability in ARMember Premium allows authenticated contributors to execute arbitrary code.
A PHP Object Injection vulnerability in the Werkstatt theme allows authenticated contributors to execute arbitrary code.
An inappropriate implementation vulnerability exists within the V8 JavaScript engine of Google Chrome prior to version 150.
An out-of-bounds read and write vulnerability exists in the Tint component of Google Chrome prior to version 150.
An integer overflow vulnerability exists in the Skia graphics library within Google Chrome prior to version 150.
An out-of-bounds write vulnerability exists in the ANGLE graphics engine component of Google Chrome, potentially allowing for memory corruption or arbitrary code execution.
Insufficient validation of untrusted input in the ANGLE component of Google Chrome for Android may lead to security bypasses or system compromise.
A vulnerability involving insufficient validation of untrusted input in the ANGLE component of Google Chrome could allow an attacker to trigger unintended behavior.
An uninitialized memory use vulnerability exists within the ANGLE graphics engine in Google Chrome, potentially leading to arbitrary code execution.
Insufficient validation of untrusted input in the Dawn component of Google Chrome for Android may allow for remote code execution.
Insufficient validation of untrusted input in the Skia graphics library within Google Chrome may lead to memory corruption and arbitrary code execution.
A TOCTOU race condition in the Erlang/OTP ssl module allows unauthenticated remote attackers to crash DTLS sessions.
The TinyPNG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient input validation within the delete_converted_image_size function.
The Image Optimizer plugin for WordPress contains a vulnerability allowing for arbitrary file deletion due to inadequate path validation.
A path traversal vulnerability in Apache Lucene allows unauthorized access to restricted directories, potentially exposing sensitive system files.
A path traversal vulnerability in Apache Lucene allows unauthorized access to restricted directories, potentially exposing sensitive system files.
The PIA OIDC issuer allowlist for Jenkins tokens is vulnerable to improper validation, using a bare string-prefix check that may allow unauthorized token issuance.
The Erlang/OTP SSL application fails to properly validate PSK identity and binder lists during TLS 1.3 handshakes.
A null pointer dereference in WatchGuard Fireware OS allows unauthenticated remote attackers to trigger a denial-of-service via crafted IKEv2 messages.
An improper access control vulnerability in the UniFi Protect Application allows network-adjacent attackers to bypass authentication on specific API endpoints.
Authenticated SQL injection vulnerabilities in the Ubiquiti UniFi OS Server allow low-privileged users to escalate their privileges within the device or instance.
An authenticated SQL injection vulnerability in the UniFi Protect Application allows low-privileged users to escalate their privileges on the host device.
A deserialization of untrusted data vulnerability in the Themify Popup plugin allows for remote object injection, potentially leading to arbitrary code execution.
Improper input validation in the ASUS AI Suite 3 driver allows a local authenticated user to access unintended memory regions via crafted IOCTL requests, leading to privilege escalation.
A SQL injection vulnerability in the Unicamp theme allows authenticated subscribers to execute arbitrary database queries, potentially leading to data theft or unauthorized access.
A SQL injection vulnerability in the Custom Field Template plugin allows authenticated contributors to execute arbitrary database commands.
A SQL injection vulnerability in iNET Webkit allows authenticated contributors to execute arbitrary database commands.
A SQL injection vulnerability in the nicen-localize-image plugin allows authenticated contributors to execute arbitrary database commands.
A SQL injection vulnerability exists in the WP EasyCart plugin, allowing authenticated contributors to execute arbitrary SQL commands via insufficient input validation.
An argument injection vulnerability in TUBITAK BILGEM pardus-software allows attackers to execute arbitrary commands by improperly neutralizing argument delimiters.
A missing authorization vulnerability in TUBITAK BILGEM pardus-software allows for argument injection, potentially leading to unauthorized system actions.
A vulnerability in Eclipse Theia potentially allows for unauthorized system interaction. The exact nature of the flaw requires further clarification from the vendor.
A critical security vulnerability in Weaviate versions prior to 1 allows for potential unauthorized system interaction.
An improper access control vulnerability in the Ubiquiti UniFi Network Application allows authenticated users with low privileges to escalate their access within the application.
An unauthenticated Cross-Site Request Forgery (CSRF) vulnerability exists in the ProfileGrid plugin, allowing attackers to perform actions on behalf of users without their consent.
An unauthenticated Cross-Site Request Forgery (CSRF) vulnerability exists in the WPIDE File Manager & Code Editor plugin, potentially allowing unauthorized actions.
A path traversal vulnerability in self-hosted Ubiquiti UniFi Network Application instances allows high-privileged authenticated attackers to escalate write permissions on the underlying host device.
A critical vulnerability exists in Progress Flowmon versions prior to 12, potentially exposing the system to unauthorized access or compromise.
Progress Flowmon ADS versions prior to 12 are affected by a high-severity vulnerability requiring immediate attention to prevent unauthorized system exploitation.
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS networkd process allows authenticated privileged users to execute arbitrary code via crafted Management Web UI requests.
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS CLI allows authenticated privileged users to execute arbitrary code via specially crafted CLI commands.
A path traversal vulnerability in the WatchGuard Fireware OS Management Web UI allows authenticated attackers to write arbitrary files to the Firebox filesystem.
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS ikestubd process allows authenticated privileged users to execute arbitrary code via crafted Management Web UI requests.
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS wgagent process enables authenticated privileged users to execute arbitrary code via the Management Web UI.
WatchGuard Fireware OS is susceptible to a firmware validation bypass, potentially allowing unauthorized code execution through the backup and restore functionality.
A path traversal vulnerability in Ubiquiti UniFi OS Server allows network-adjacent attackers to bypass authentication mechanisms and gain unauthorized access to device instances.
Ubiquiti UniFi Protect Application contains an improper access control vulnerability, enabling unauthenticated attackers to bypass authentication for data streaming.
A path traversal vulnerability in the Ubiquiti UniFi Access Application allows an attacker with network access to read arbitrary files from the host device.
A security flaw has been identified in Eclipse Theia that could lead to unauthorized system impacts. Users are advised to await further guidance from the vendor.
An External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered Inter-Process Communication (IPC) message.
A relative path traversal vulnerability exists within the "keyhint" option of the `repomd` functionality in the SUSE libzypp library.
An improper access control vulnerability in the Ubiquiti UniFi Network Application allows authenticated users with low privileges to escalate their permissions under certain conditions.
A high-severity vulnerability exists in the GeoWebPlayer addon for GeoVision software, potentially allowing unauthorized system impact.
A high-severity vulnerability has been identified in the GeoWebPlayer addon used across multiple GeoVision software platforms.
A high-severity security vulnerability has been reported in the GeoWebPlayer addon, impacting various GeoVision software deployments.
GeoVision GeoWebPlayer, an add-on for GV-VMS and GV-Cloud, contains a high-severity vulnerability that requires immediate attention.
GeoVision GeoWebPlayer contains a high-severity security vulnerability affecting its integration with GV-VMS and GV-Cloud products.
An unauthenticated broken access control vulnerability exists in Gurmehub POS Entegratör versions 3 and below, potentially allowing unauthorized system access.
An improper access control vulnerability in the Ubiquiti UniFi Talk Application allows authenticated users with low privileges to perform unauthorized actions through privilege escalation.
An unauthenticated local file inclusion (LFI) vulnerability exists in AncoraThemes Lighthouse versions 1 and below, allowing for potential sensitive file disclosure.
A Local File Inclusion (LFI) vulnerability exists in the Pearl - Corporate Business theme, allowing unauthenticated attackers to read sensitive files on the server.
An unauthenticated Local File Inclusion (LFI) vulnerability in the Audrey theme allows remote attackers to read arbitrary files from the server's filesystem.
An unauthenticated Cross-Site Request Forgery (CSRF) vulnerability in the Heateor Social Login plugin allows attackers to perform unauthorized actions on behalf of users.
MLflow versions prior to 3 are vulnerable to a security flaw, necessitating an immediate review of vendor-provided security updates to mitigate potential risks.
A security vulnerability exists in RT-Thread up to version 5 that may allow for unauthorized system impact.
A security flaw has been identified in the RT-Thread operating system up to version 5, potentially impacting system security posture.
A vulnerability in the Minifilter communication port for the GameFirst Anti-Cheat driver, GFAC_Sys_x64, may expose the system to unauthorized interactions.
An improper validation vulnerability exists in the `GFAC_Sys_x64` driver for GameFirst Anti-Cheat, which could lead to unauthorized system-level actions.
TinaCMS is affected by a security vulnerability that may expose the headless content management system to unauthorized manipulation.
An out-of-bounds write vulnerability in WatchGuard Fireware OS could allow unauthenticated local network attackers to execute arbitrary code.
A path traversal vulnerability in the react-native-receive-sharing-intent library allows malicious co-resident applications to overwrite files outside the intended cache directory.
A security vulnerability has been identified in JuiceFS that may allow for unauthorized access or system compromise.
A high-severity security vulnerability exists in LobeChat that could potentially lead to unauthorized access or data exposure.