CVE-2026-63030
WordPress is affected by a REST API batch endpoint route confusion issue which, when combined with other vulnerabilities, can lead to SQL injection and Remote Code Execution.
Critical vulnerabilities, curated daily for security professionals
Oracle Platform Security for Java and the Linux Kernel lead Thursday's disclosures, with two Oracle flaws (CVE-2026-60366 at CVSS 10 and CVE-2026-60369 at CVSS 9.9) and two kernel memory issues (CVE-2026-64035 and CVE-2026-64037, both CVSS 9.8) carrying near-maximum severity. The brief covers 11 critical CVEs, down 77% from the prior day's 48, and 29 high-priority CVEs, down 71% from 100. Additional critical entries affect the WordPress Kirki framework (CVE-2026-13147, CVSS 9.1) and the Perl Mojo::JWT library (CVE-2026-9537, CVSS 9.8). The disclosures span enterprise middleware, kernel-level components, and widely deployed web plugins, with remote code execution and authentication weaknesses recurring across the set. No patches were confirmed available at disclosure, so teams should track vendor advisories and prioritize exposed Oracle and Linux systems while validating fixes as they ship.
Immediate action: Prioritize Oracle Platform Security for Java and Linux Kernel systems, which hold the highest-severity flaws, and review WordPress installations running the Kirki framework. No patches were confirmed available at disclosure, so monitor vendor advisories and apply fixes for critical issues as soon as they are released.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
WordPress is affected by a REST API batch endpoint route confusion issue which, when combined with other vulnerabilities, can lead to SQL injection and Remote Code Execution.
A critical vulnerability in Langflow allows unauthenticated remote attackers to execute arbitrary code via the /validate endpoint's exec_globals parameter.
DD-WRT is vulnerable to a stack-based buffer overflow in the UPnP service, which could allow an unauthenticated attacker to achieve remote code execution.
An improper authentication vulnerability in Check Point SmartConsole allows unauthenticated attackers to potentially bypass security controls.
A deserialization vulnerability in Microsoft SharePoint allows an unauthenticated attacker to execute code over a network.
WordPress Core is affected by a SQL injection vulnerability that allows unauthenticated attackers to execute unauthorized database queries.
An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory.
A critical vulnerability in Oracle Platform Security for Java allows unauthenticated, remote attackers to achieve a full takeover of the application via HTTP.
A critical vulnerability in Oracle Platform Security for Java allows low privileged attackers to compromise the environment via HTTP.
The Kirki WordPress plugin fails to validate user-supplied URLs, enabling unauthenticated attackers to perform Server-Side Request Forgery (SSRF) and target arbitrary hosts.
The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.
Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recomputed HMAC with Perl's eq operator, which stops at the first differing byte, so the comparison time varies with the number of ma
A memory corruption vulnerability in the Linux kernel Intel Gigabit Ethernet driver (igc) allows for potential system instability or code execution.
A flaw in the Linux kernel iwlwifi MLD driver causes a TSO segmentation explosion when AMSDU is disabled, potentially leading to system instability, memory corruption, or remote code execution.
An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component
An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior.
django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system() in pyas2/utils.py without sanitization, allowing an authenticated admin user to execute arbitrary commands on the server when
A use after free vulnerability exists in the Google Chrome UI component, potentially allowing a remote attacker to execute arbitrary code via a crafted webpage.
A vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java allows a low privileged attacker to compromise the platform via SOAP requests.
A vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java allows a low privileged attacker to compromise the platform via HTTP requests.
A critical vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java allows low privileged attackers to achieve full system compromise.
A critical vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java allows low privileged attackers to achieve full system compromise.
A critical vulnerability in the Centralized Thirdparty Jars component of Oracle Platform Security for Java allows low privileged attackers to achieve full system compromise.
The servereye Windows Agent (Sensorhub) contains vulnerabilities related to insecure file permissions and improper privilege management, potentially leading to local privilege escalation.
The Product Addons and Product Options With Custom Fields WordPress plugin is vulnerable to Cross-Site Scripting (XSS) due to insufficient input sanitization.
Dell PowerProtect Data Manager is vulnerable to an incorrect security token generation flaw, which may allow an authenticated attacker to bypass security controls.
A lack of rate limiting and insecure storage of authentication codes in the Social Login, Passkeys, Magic Link & Email OTP plugin allows unauthenticated attackers to brute-force user accounts.
The SlimStat Analytics WordPress plugin fails to sanitize geolocation data, enabling unauthenticated cross-site scripting (XSS) attacks against administrators.
The LearnPress WordPress plugin is vulnerable to reflected cross-site scripting (XSS) via an unescaped search parameter.
The Tag Groups WordPress plugin before 2.2.0 is vulnerable to reflected Cross-Site Scripting (XSS) via improper escaping of an AJAX parameter.
Apache Traffic Server is vulnerable to uncontrolled resource consumption, which may lead to a denial of service via stalled HTTP/2 flow-control.
n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler, allowing for potential expression language injection.
n8n is susceptible to a privilege escalation vulnerability via improper token exchange management.
n8n is vulnerable to remote code execution via a time-of-check time-of-use race condition during Git clone operations.
A double free vulnerability exists in the FFmpeg NVDEC hardware decoder, which may allow an unauthenticated attacker to achieve arbitrary code execution via a crafted file.
An out-of-bounds write vulnerability in the FFmpeg ADX audio decoder allows an unauthenticated attacker to cause memory corruption via a specially crafted audio file.
A heap-based buffer overflow vulnerability in the FFmpeg VOBSUB subtitle demuxer allows an unauthenticated attacker to trigger memory corruption via a malicious subtitle file.
A stack-based buffer overflow exists in the FFmpeg Vulkan HEVC decoder, potentially allowing for arbitrary code execution.
An insecure direct object reference vulnerability exists in the Onlook repo, allowing authenticated users to bypass authorization checks.
An improper privilege management vulnerability in the Grav Login plugin allows authenticated attackers to escalate their privileges.
The Joomla extension Events Booking prior version 5.
The Crypt::Password Perl module is susceptible to timing attacks due to the use of the non-constant time 'eq' operator when verifying passwords.
A local privilege escalation vulnerability exists in the Linux kernel cgroup/rstat component due to improper validation of CPU arguments.
HTTP::Date versions before 6.
A memory address mismatch in the PCPI instruction logic of the RISC-V PicoRV32 core (commit 87c89a) can cause unexpected system behavior.
Xenforo 2.