CVE-2026-46817
An unauthenticated, easily exploitable vulnerability in the Oracle Payments product of E-Business Suite allows remote attackers to compromise the service via HTTP.
Critical vulnerabilities, curated daily for security professionals
Remote code execution and authentication bypass flaws in internet-facing web applications dominated Monday's disclosures, with Joomla extensions, FreeRDP, xrdp, and Piwigo among the most exposed products. The brief covers 20 critical CVEs (up from 10 the prior day) and 109 high-priority CVEs, a sharp increase from 18 the day before. Two Joomla extensions from dj-extensions.com carry maximum CVSS 10 scores: CVE-2026-61424 in DJ-Classifieds and CVE-2026-61900 in jDownloads, while CVE-2026-64620 in FreeRDP and CVE-2026-41252 in neutrinolabs xrdp expose remote desktop infrastructure at CVSS 9.8. The pattern skews toward content management systems, WordPress and Joomla plugin ecosystems, and remote access services, all commonly reachable from untrusted networks. Six CVEs have confirmed active exploitation, including flaws in Microsoft SharePoint and Fortinet FortiSandbox. No confirmed patch data was available for this set at publication, so verify fix status directly with each vendor before planning remediation windows.
Immediate action: Prioritize internet-facing remote access services (FreeRDP, xrdp) and CMS deployments running Joomla extensions from dj-extensions.com, Piwigo, or affected WordPress plugins, since these carry CVSS 9.8 to 10 remote code execution and authentication bypass flaws. Systems running Microsoft SharePoint, Microsoft AD FS, and Fortinet FortiSandbox need attention given confirmed exploitation activity. No patch availability was confirmed for this set, so check vendor advisories directly and apply access controls or network restrictions where fixes are not yet published.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An unauthenticated, easily exploitable vulnerability in the Oracle Payments product of E-Business Suite allows remote attackers to compromise the service via HTTP.
A deserialization of untrusted data vulnerability in Microsoft SharePoint allows an unauthenticated, remote attacker to execute arbitrary code.
An OS command injection vulnerability in FortiSandbox allows unauthenticated attackers to execute unauthorized commands via specifically crafted HTTP requests.
Fortinet FortiSandbox is vulnerable to OS command injection, allowing unauthenticated attackers to execute unauthorized code on the appliance.
Microsoft Active Directory Federation Services is affected by a vulnerability involving insufficient granularity of access control.
The KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that is currently being exploited in the wild.
The Piwigo installer improperly sanitizes database configuration POST parameters, allowing unauthenticated attackers to inject and execute arbitrary PHP code via the configuration file.
The Easy Form Builder plugin for WordPress contains an unauthenticated privilege escalation vulnerability allowing attackers to reset any user password and gain administrative access.
AVideo contains an OS command injection vulnerability in the Live plugin, where insufficient escaping allows attackers to execute arbitrary system commands via the on_publish.php endpoint.
FileThingie version 2.5.7 contains a vulnerability in the ft2.php component that allows a remote, authenticated attacker to obtain sensitive information from the system.
A SQL injection vulnerability in the ureport component allows unauthenticated attackers to execute arbitrary SQL queries and access sensitive database information.
ktransformers contains an unauthenticated pickle deserialization vulnerability in the SchedulerServer ZMQ ROUTER socket, allowing remote attackers to execute arbitrary commands via crafted payloads.
A heap-based buffer overflow in FreeRDP's crypto_rsa_common function allows an unauthenticated attacker to cause a denial of service by sending a forged RDP standard security ciphertext.
A heap-based buffer overflow in xrdp, occurring in vnc-any mode, allows remote, unauthenticated attackers to cause a denial of service or potentially achieve remote code execution.
The DJ-Classifieds extension for Joomla contains an unauthenticated file upload vulnerability that allows a remote attacker to achieve full remote code execution on the server.
The jDownloads extension for Joomla contains an unauthenticated file upload vulnerability that allows a remote attacker to achieve full remote code execution on the server.
The @beproduct/nestjs-auth package was compromised via a malicious npm publish, leading to the distribution of versions containing code designed to exfiltrate environment secrets and credentials.
A flaw in the Network-AI agent sandbox allows authenticated users to bypass command allowlists, leading to arbitrary OS command execution.
GPT-SoVITS is vulnerable to OS command injection via the webui.py interface, allowing unauthenticated attackers to execute arbitrary commands on the server.
Crypt::Password versions 0.28 and earlier utilize a cryptographically weak pseudo-random number generator, leading to predictable salt generation.
Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via the /cgi-bin/UploadCfg endpoint
Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including `TDE_IOCTL_INDEXIO_READ` and `TDE_IOCTL_INDEXIO_WRITE` permit unprivileged user-mode callers to perform arbitrary hardware I/O port reads and writes w
Image::EPEG for Perl versions 0 through 0.15 embeds a legacy, unmaintained Epeg library from 2004, exposing applications to critical security vulnerabilities.
An out-of-bounds read vulnerability in the YAML::Syck Perl module allows attackers to access adjacent memory regions through crafted binary YAML nodes.
HTML::Bare versions through 0.04 for Perl contain an out-of-bounds read vulnerability in the parserc_parse function due to improper handling of character lookaheads.
XML::Bare versions through 0.53 for Perl are susceptible to an out-of-bounds read vulnerability when processing malformed or truncated XML strings.
The Quix Page Builder Pro extension for Joomla is susceptible to authenticated PHP code execution due to improper code generation controls.
The FreeScout help desk software contains an unrestricted file upload vulnerability that allows authenticated users to execute arbitrary files on the server.
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 is vulnerable to cross-site scripting, which may allow attackers to execute arbitrary scripts in a user's browser.
FreeScout help desk software is affected by an improper authentication vulnerability, allowing unauthenticated attackers to bypass security controls.
A vulnerability in the Linux kernel RDMA core component involves improper handling of NLA_STRING attributes, potentially leading to memory issues when checking for null terminators.
AgenticMail packages are affected by a missing authentication vulnerability, allowing unauthenticated attackers to perform unauthorized actions on critical functions.
The dataCycle-CORE management system contains an improper authorization vulnerability that allows authenticated users to perform unauthorized data management operations.
The Modern Event Calendar Pro WordPress plugin is vulnerable to SQL injection, allowing unauthenticated attackers to potentially extract sensitive database information.
A missing error check in the Linux kernel BPF subsystem allows for potential memory corruption or instability during tail call processing.
A validation error in the Linux kernel f2fs filesystem allows for potential memory corruption when replaying orphan inodes.
A signature validation flaw in the PhonePe Payment Solutions WordPress plugin allows unauthenticated attackers to forge payment success callbacks and manipulate order statuses.
A boundary checking error in the Linux kernel network devmem implementation allows for out-of-bounds access during dma-buf binding.
A vulnerability in EGroupware allows an authenticated user to achieve remote code execution due to improper authorization checks.
A TOCTOU race condition in the Linux kernel MPTCP output path can lead to integrity issues or denial of service when computing receive windows.
SailPoint IdentityIQ is vulnerable to unauthorized API access due to improper validation of OAuth bearer tokens, allowing unauthenticated attackers to retrieve protected data.
A race condition in the Linux kernel ovpn TCP implementation allows for improper memory handling during socket closure.
AgenticMail contains multiple vulnerabilities including improper input validation, SQL injection, and broken access controls.
A vulnerability in rsync allows for integer overflow and subsequent sensitive information exposure during file synchronization.
HCL Commerce is vulnerable to an incorrect privilege assignment flaw, enabling authenticated attackers to perform unauthorized administrative operations, access user data, or cause a denial of service.
Roo-Code contains an incomplete list of disallowed inputs vulnerability, which could allow for command injection via parameter expansion parsing.
A heap-based buffer overflow vulnerability in the neutrinolabs xrdp RDP server allows authenticated attackers to potentially execute arbitrary code or cause a crash.
Scille parsec-cloud is susceptible to a path traversal vulnerability via Windows UNC share names, allowing authenticated users to potentially access unauthorized files.
A heap-based buffer overflow vulnerability in ProFTPD allows authenticated users to trigger memory corruption via improper SFTP packet reassembly.
A stack-based buffer overflow vulnerability in the Tenda AC10 router, specifically within the AdvSetLanip function, allows authenticated attackers to corrupt memory.
SurrealDB versions before 3.1.0 contain a missing authentication vulnerability for critical functions, potentially allowing unauthorized access to RPC sessions.
A vulnerability in the Linux kernel vfio/pci driver allows improper export of DMABUF objects without verifying that BAR resources are correctly reserved.
The batman-adv protocol in the Linux kernel contains a vulnerability where the tt_buff_len field is incorrectly declared as a signed integer, potentially causing issues with negative values.
A race condition in the Linux kernel batman-adv module's tp_meter functionality allows for improper timer cleanup, potentially leading to memory corruption or system instability.
A use-after-free vulnerability exists in the Linux kernel batman-adv multicast component, caused by incorrect RCU grace period handling during entry purging.
A use-after-free vulnerability in the Linux kernel af_unix implementation allows local users to trigger a race condition in unix_stream_data_wait, potentially leading to privilege escalation.
A use-after-free vulnerability in the Linux kernel vsock/vmci implementation occurs when a peer resets a connection during the handshake process.
A race condition in the Linux kernel mac80211 wifi stack leads to memory corruption when capturing RX rates during mesh data processing.
The ksmbd server in the Linux kernel fails to properly validate Security Identifier (SID) data during ACL inheritance, leading to potential security bypasses.
A local privilege escalation vulnerability exists in the Linux kernel drm/msm driver due to an incorrect return value check in iommu_map_sgtable, potentially leading to system instability or compromise.
A Use-After-Free (UAF) vulnerability exists in the Linux kernel Bluetooth bnep driver, caused by improper synchronization when reading device names, potentially allowing for arbitrary code execution.
An improper bounds check in the Linux kernel mac80211 wifi subsystem allows an adjacent attacker to trigger memory corruption via a specially crafted ML element.
A race condition in the Linux kernel DRM GEM subsystem allows for potential handle manipulation issues due to improper locking during handle changes.
An out-of-bounds read vulnerability exists in the Linux kernel NFC HCI subsystem due to insufficient validation of packet headers during parsing.
An out-of-bounds write vulnerability exists in the Linux kernel Wacom HID driver due to incorrect assumptions about feature report structures.
A vulnerability in the Linux kernel IP6 VTI implementation allows for potential privilege escalation due to improper handling of tunnel encapsulation.
A reference counting vulnerability in the Linux kernel XFRM subsystem allows for potential memory corruption during deferred transport reinjection.
A vulnerability in the Linux kernel IP6 VTI implementation relates to improper tunnel handling, mirroring logic issues found in related networking components.
A validation vulnerability exists in the Linux kernel octeontx2-af driver within the rvu_mbox_handler_rep_event_notify function, potentially allowing for improper input handling.
A Time-of-Check Time-of-Use (TOCTOU) vulnerability in the Linux kernel KVM SEV implementation arises from improper handling of the Page State Change buffer.
An improper capping vulnerability exists in the Linux kernel KVM arm64 implementation regarding the handling of ZCR_EL2 by guest hypervisors.
A use-after-free vulnerability exists in the Linux kernel Bluetooth subsystem due to improper lock handling within the hci_le_create_cis_sync function.
A use-after-free vulnerability in the Linux kernel Bluetooth ISO implementation allows for potential memory corruption due to improper lock management in iso_recv_frame.
A buffer handling vulnerability in the Linux kernel Bluetooth HIDP implementation allows for memory corruption due to missing length checks in hidp_input_report.
A race condition in the Linux kernel Bluetooth subsystem allows for potential memory corruption or system instability during device shutdown and reset sequences.
A logic error in the Linux kernel Bluetooth L2CAP implementation allows for potential crashes when processing malformed destination CID connection responses.
An improper state management flaw in the Linux kernel Bluetooth L2CAP module allows for the retention of stale identifiers following successful ECRED reconfiguration.
A use-after-free race condition exists in the Linux kernel NFC LLCP connection state machine, potentially allowing local attackers to trigger memory corruption.
An unbalanced lock usage in the Linux kernel drm/gpusvm component, specifically within the drm_gpusvm_scan_mm function, can lead to denial of service or potential privilege escalation.
The Linux kernel improperly allows certain LSM sleepable hooks to be used from contexts that do not support sleep, leading to potential kernel instability or security bypasses.
A memory management flaw exists in the Linux kernel mt7996 Wi-Fi driver where failure to clear the WCID pointer during station link deinitialization can lead to memory corruption or instability.
The Linux kernel OCFS2 file system driver fails to properly validate group bitmap descriptors, allowing for oversized descriptors that can lead to memory corruption or system instability.
A use-after-free vulnerability in the Linux kernel TIPC (Transparent Inter-Process Communication) protocol allows for memory corruption during AEAD decryption due to improper reference counting.
A memory management flaw exists in the Linux kernel KVM x86 shadow MMU, which fails to correctly validate memory slots before checking hugepage mapping levels.
A privilege check vulnerability exists in the Linux kernel ip_gre tunnel implementation, failing to properly enforce CAP_NET_ADMIN requirements during device changelink operations.
A memory safety flaw in the Linux mac802154 wireless subsystem fails to perform necessary data copying before in-place cryptographic operations, leading to potential memory corruption.
A race condition or improper handling in the Linux kernel mt76 wifi driver allows unauthorized memory reinitialization due to a missing wcid publish check.
The Linux kernel amdgpu driver fails to zero-initialize the GART table upon allocation, potentially leading to information disclosure or memory corruption.
The Linux kernel amdgpu VCE driver allows partial address patches, which can result in the firmware writing to invalid or malicious memory addresses.
VSee Clinic contains an authorization bypass vulnerability allowing authenticated users to manipulate user-controlled keys to access unauthorized resources.
Quix Page Builder Pro for Joomla is vulnerable to unauthenticated path traversal through form elements, allowing unauthorized access to sensitive files.
The Quix Page Builder Pro extension for Joomla is vulnerable to improper access control, which may allow unauthenticated attackers to gain unauthorized access to sensitive information.
Extreme Networks Switch Engine (EXOS) utilizes a cryptographically weak pseudo-random number generator for its debug-mode challenge-response authorization mechanism.
Extreme Networks Switch Engine (EXOS) file utilities fail to properly validate paths and resolve symbolic links, allowing access outside of intended boundaries.
A cross-site scripting vulnerability in the ci4ms content management system allows authenticated users to inject malicious scripts, potentially leading to unauthorized actions or data theft.
An information exposure vulnerability in FileBrowser Quantum allows unauthenticated remote attackers to access sensitive information due to improper security controls.
A vulnerability in the Linux kernel's SEV-guest driver causes improper page state handling during memory encryption failures, potentially leading to information disclosure or system instability.
The Quix Page Builder Pro extension for Joomla contains an authenticated stored cross-site scripting vulnerability that could lead to full compromise of the affected system.
EGroupware version 26.0 and earlier are vulnerable to OS command injection and eval injection, which could allow an authenticated attacker to execute arbitrary code on the underlying system.
HeyForm versions before 3.0.0-rc.9 are susceptible to missing authentication for critical functions and unrestricted file uploads, potentially allowing unauthenticated attackers to execute arbitrary code.
Jovancoding Network-AI versions before 5.13.4 are vulnerable to an improper verification of cryptographic signatures, allowing unauthenticated attackers to bypass integrity checks.
Paymenter contains vulnerabilities involving improper input validation and authorization bypass, allowing authenticated users to perform unauthorized actions.
Wazuh is susceptible to a deserialization vulnerability, which could allow a highly privileged attacker to achieve remote code execution.
The Linux kernel's arm_ffa firmware driver lacks proper validation for framework notification message layouts, leading to potential memory corruption.
A memory management flaw exists in the Linux kernel qed driver, where an improper error handling path leads to a double free condition during CID bitmap allocation failures.
A flaw in the Linux kernel IOMMU implementation allows for improper page size handling, potentially leading to memory access issues.
A use-after-free vulnerability exists in the Linux kernel omap2430 USB driver due to improper reference counting of device tree nodes during probe initialization.
A memory management flaw exists in the Linux kernel bpf_msg_push_data function, where improper handling of scatterlist fragment offsets during data insertion can lead to memory corruption.
A security flaw in the Linux kernel memfd implementation fails to properly deny writable mappings when SEAL_EXEC is present, violating W^X memory protection requirements.
A use-after-free vulnerability in the Linux kernel rpmsg character device driver occurs during error handling in the probe path, allowing for potential memory corruption.
A memory handling flaw exists in the Linux kernel f2fs file system where i_inline_xattr_size is loaded without proper validation for non-inline-xattr inodes.
A security flaw in the Linux kernel AppArmor module fails to properly mediate the implicit connection associated with TCP Fast Open sendmsg operations.
The Linux kernel UDF file system driver lacks proper validation for CRC lengths, allowing for potential heap-based overflows when processing malformed descriptors.
A vulnerability exists in the xrdp open source RDP server where an integer overflow or wraparound flaw can be exploited by an unauthenticated attacker.
The Caddy Defender plugin for Caddy contains an access control vulnerability that allows attackers to bypass IP-based security restrictions.
Dancer2 contains a vulnerability involving the generation of predictable identifiers due to a cryptographically weak pseudo-random number generator.
A flaw in the Linux kernel netfilter conntrack TCP state machine allows unauthenticated attackers to force connections into a closed state using invalid sequence number RST packets.
NextCRM contains a missing authorization vulnerability (CWE-862) that allows authenticated users to perform unauthorized actions within the application.
SurrealDB suffers from an authorization bypass vulnerability (CWE-639) that allows authenticated users to access or modify data they are not authorized to view.
A race condition vulnerability in SurrealDB allows unauthorized actors to perform privilege escalation via RPC session handling.
A vulnerability in the Linux kernel iwlwifi driver improperly handles transmission rates on legacy devices, potentially leading to information disclosure or denial of service.
An integer overflow in the Linux kernel SCSI transport layer allows an adjacent attacker to trigger a system hang via malicious Fibre Channel frames.
A integer wrap vulnerability in the Linux kernel Thunderbolt property subsystem allows for potential memory corruption.
An out-of-bounds read regression in the Linux kernel ksmbd module's access control entry processing can be triggered by a remote attacker.
A replay protection failure in the Linux kernel macsec implementation at XPN lower-PN wrap allows for potential packet manipulation.
A vulnerability in the Linux kernel ksmbd module allows an out-of-bounds read during the processing of SMB permission-check Access Control Entries.
A missing authentication vulnerability in the xrdp server allows attackers to bypass security controls for critical functions.
The Perl module HTML::Bare is susceptible to a denial of service through an infinite loop when parsing malformed HTML attributes.
The Perl module XML::Bare is susceptible to a denial of service through an infinite loop when parsing malformed XML attributes.
LogicalDOC Enterprise contains a blind SQL injection vulnerability in the ComparisonServlet, allowing authenticated users to manipulate database queries via crafted input.
The OPSWAT AppRemover kernel driver fails to validate privileges in its IOCTL handler, allowing local users to terminate arbitrary processes.
A stack overflow in the evaluate() function of BusyBox allows unauthenticated attackers to cause a Denial of Service (DoS) via a crafted AWK script.
A heap overflow in the ifsbreakup() function (shell/ash.
A heap overflow in the evalcommand() function (shell/ash.
A use-after-free in the awk_sub() function (editors/awk.