CVE-2026-63030
WordPress is affected by a REST API batch endpoint route confusion issue which, when combined with other vulnerabilities, can lead to SQL injection and Remote Code Execution.
Critical vulnerabilities, curated daily for security professionals
Google Chrome accounted for four of the day's critical disclosures (CVE-2026-15899 through CVE-2026-15902, all CVSS 9.6), alongside remotely reachable flaws in Microsoft identity and device management services. Volume dropped sharply from the prior day, with 8 critical CVEs (down 81%) and 24 high-priority CVEs (down 81%). The highest-scored issue is CVE-2026-66012 (CVSS 10.0) in siyuan-note siyuan, followed by CVE-2026-54120 (CVSS 9.9) in Microsoft Surface Management Services and CVE-2026-56165 (CVSS 9.8) in Microsoft Account. Remote code execution and authentication bypass dominate the critical set, with exposure concentrated in end-user browsers, Microsoft cloud services, and self-hosted open-source platforms such as openremote and siyuan. No vendor patches were recorded as available for the critical items at disclosure time, so teams should prioritize exposure mapping, compensating controls, and monitoring for vendor releases.
Immediate action: Prioritize Chrome browser fleets, Microsoft Account and Surface Management Services tenants, and internet-facing WordPress, SharePoint, Check Point SmartConsole, and Langflow instances, where active exploitation is confirmed. No patches were recorded as available for the eight critical CVEs at disclosure, so apply vendor mitigations, restrict network exposure of self-hosted openremote and siyuan deployments, and track vendor advisories for update releases. Increase monitoring on the actively exploited products until fixes are deployed.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
WordPress is affected by a REST API batch endpoint route confusion issue which, when combined with other vulnerabilities, can lead to SQL injection and Remote Code Execution.
A critical vulnerability in Langflow allows unauthenticated remote attackers to execute arbitrary code via the /validate endpoint's exec_globals parameter.
DD-WRT is vulnerable to a stack-based buffer overflow in the UPnP service, which could allow an unauthenticated attacker to achieve remote code execution.
An improper authentication vulnerability in Check Point SmartConsole allows unauthenticated attackers to potentially bypass security controls.
A deserialization vulnerability in Microsoft SharePoint allows an unauthenticated attacker to execute code over a network.
WordPress Core is affected by a SQL injection vulnerability that allows unauthenticated attackers to execute unauthorized database queries.
A critical use-after-free vulnerability in the CameraCapture component of Google Chrome on Mac permits remote attackers to achieve a sandbox escape through a crafted HTML page.
A critical use-after-free vulnerability in the GPU component of Google Chrome on Android allows remote attackers to trigger a sandbox escape via a crafted HTML page.
A critical use-after-free vulnerability exists in the Network component of Google Chrome, which could allow a remote attacker to exploit heap corruption via a crafted HTML page.
A use-after-free vulnerability in the Cast component of Google Chrome allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
SiYuan before 3.7.2 is vulnerable to missing authorization in the POST /mcp endpoint, allowing unauthenticated remote attackers to achieve full system compromise via arbitrary file operations.
A heap-based buffer overflow in Microsoft Account allows an unauthenticated attacker to execute arbitrary code over a network.
Improper input validation in Microsoft Surface Management Services allows an authorized attacker to execute code over a network.
OpenRemote before 1.26.2 contains an authentication bypass in the console registration API, allowing unauthenticated attackers to overwrite console metadata and push notification tokens.
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection, which could allow an attacker to execute arbitrary code.
A memory safety vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A time-based blind SQL injection vulnerability in the bpost-shipping-platform plugin allows unauthenticated attackers to extract sensitive database information during WooCommerce order submission.
The Free Theme Builder for Elementor plugin fails to sanitize input, allowing unauthenticated attackers to execute Stored Cross-Site Scripting (XSS) attacks in the administrator dashboard.
The Apereo CAS Client improperly validates server certificates, allowing connections to untrusted hostnames if they match a configured allowlist or regex.
Apache Neethi before 3.2.3 is susceptible to a denial of service attack if a large remote policy is manually retrieved via the API, causing uncontrolled resource consumption.
Apache NimBLE is affected by a classic buffer overflow vulnerability due to improper input size validation, potentially allowing code execution or system instability.
The EventON Action User plugin for WordPress contains an authorization bypass vulnerability, potentially allowing unauthenticated attackers to perform unauthorized actions.
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is susceptible to a stored cross-site scripting (XSS) vulnerability via the vbfX parameter.
A double free vulnerability exists in Redis versions prior to 8.8.0, which could be leveraged to crash the service or potentially execute arbitrary code.
Apache NimBLE contains a reachable assertion vulnerability that can be triggered by unauthenticated attackers to cause a denial of service.
A NULL pointer dereference vulnerability in the Apache NimBLE LE Long Term Key Request event may allow an attacker to cause a denial of service.
Apache Neethi is susceptible to uncontrolled recursion when parsing specific policy structures, potentially leading to a denial of service via memory exhaustion.
Apache Neethi contains a flaw that allows attackers to bypass the established maximum number of normalized policy alternatives, potentially causing resource exhaustion.
An integer underflow vulnerability in libssh2 during AES-GCM cipher negotiation can lead to a denial of service condition.
A heap-based out-of-bounds read in libssh2 occurs during the processing of the public key subsystem, potentially leading to memory disclosure or application crashes.
A heap-based buffer overflow in libssh2, occurring during ETM cipher negotiation, allows remote attackers to cause a crash or potentially execute arbitrary code.
An improper control of code generation (code injection) vulnerability exists in datamodel-code-generator, allowing attackers to inject malicious code via the customBasePath schema field.
The Visual Studio Code Ansible Lightspeed extension is vulnerable to OS command injection via improper neutralization of special elements in configuration settings.
An OS command injection vulnerability in sysPass allows an authenticated administrator to execute arbitrary system commands via the backup path parameter.
Microweber CMS versions through 2.0.20 contain a code injection vulnerability, allowing authenticated administrators to execute arbitrary code via mail templates.
The hulumi toolkit for Pulumi contains a vulnerability due to insufficient technical documentation and improper configuration, which can lead to unauthorized infrastructure modifications.
sysPass through version 3.2.11 is vulnerable to an authorization bypass, allowing authenticated users to access and decrypt accounts via the PublicLinkController.
A vulnerability in Grafana IRM allows authenticated users to perform unauthorized actions, potentially impacting system integrity and availability.