CVE-2026-16812
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
Critical vulnerabilities, curated daily for security professionals
Apache Software Foundation products account for the heaviest critical exposure in yesterday's disclosures, with three separate CVSS 10 flaws in Apache Traffic Server alongside CVSS 9.8 issues in Axis2/Java and Syncope. The day brought 23 critical vulnerabilities (down 23% from 30) and 58 high-priority CVEs (down 36% from 91), with 2 entries carrying confirmed active exploitation. Notable critical items include CVE-2026-33267, CVE-2026-57834 and CVE-2026-58150 in Apache Traffic Server (all CVSS 10), CVE-2026-66713 in Apache Axis2/Java (CVSS 9.8), and CVE-2026-63227 in Koollab LMS (CVSS 9.9). WordPress and Joomla extensions make up a large share of the remainder, including Advanced Responsive Video Embedder, TrueBooker, and the Balbooa Forms component at CVSS 9.8 to 10, a pattern that puts unmanaged CMS installations at the highest practical risk. Patch availability data is not yet recorded for these disclosures (0%), so treat vendor advisories as the authoritative source and prioritize compensating controls where fixes are pending.
Immediate action: Prioritize internet-facing Apache Traffic Server deployments and Apache Axis2/Java or Syncope instances, then sweep WordPress and Joomla sites for the affected plugins and components (Advanced Responsive Video Embedder, TrueBooker, Balbooa Forms). Arista VeloCloud Orchestrator On-Prem and Fortinet FortiOS should be treated as immediate given confirmed exploitation. Patch availability is unconfirmed for this batch, so check vendor advisories for fixed builds and apply access restrictions or WAF rules on exposed services until updates are validated.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
A sensitive information disclosure vulnerability exists in Fortinet FortiOS, allowing unauthenticated attackers to access restricted system data.
A deserialization vulnerability in the Apache Axis2/Java clustering component allows unauthenticated attackers to execute arbitrary code if the Tribes clustering feature is enabled.
An improper privilege management vulnerability in Apache Syncope allows unauthenticated users to gain administrative roles via REST API calls under specific workflow configurations.
Koollab LMS 5.3.2 contains an unrestricted file upload vulnerability allowing authenticated module designers to upload PHP webshells and execute arbitrary code on the server.
A SQL injection vulnerability in the Hypequery TypeScript semantic layer for ClickHouse allows unauthenticated attackers to execute arbitrary SQL commands via improper escaping of query parameters.
A hardcoded backdoor in the Advanced Responsive Video Embedder WordPress plugin allows unauthenticated attackers to authenticate as an administrator using a static, publicly known token.
The TrueBooker WordPress plugin fails to validate account ownership during password resets, allowing unauthenticated attackers to hijack any user account, including administrative accounts.
Apache Traffic Server is affected by an improper input validation vulnerability that may lead to significant security impacts depending on the configuration and environment.
Apache Traffic Server is susceptible to request smuggling attacks when processing malformed chunked HTTP messages.
Apache Traffic Server fails to properly reject Transfer-Encoding headers in HTTP/2 requests, enabling downgrade-based request smuggling.
The Balbooa Forms component for Joomla contains a critical code injection vulnerability that allows unauthenticated remote code execution via insecure form processing logic.
IBM WebSphere Application Server versions 9.0 and 8.5 are susceptible to pre-authentication unsafe deserialization, enabling remote attackers to bypass authentication or execute arbitrary code.
The Vacron VIN-DS783E-E6 device contains hidden functionality that allows unauthenticated remote attackers to retrieve administrator credentials.
An unauthenticated SQL injection vulnerability in the GetGridData endpoint of PROCON-WEB SCADA allows remote attackers to execute arbitrary SQL commands.
Koollab LMS contains a SQL injection and unsafe deserialization vulnerability in the assessment reinforcement endpoint, allowing authenticated attackers to achieve remote code execution.
Koollab LMS contains a SQL injection and unsafe deserialization vulnerability in the assessment overall answer endpoint, allowing authenticated attackers to achieve remote code execution.
Koollab LMS contains a SQL injection and unsafe deserialisation vulnerability in the manual mark assessment endpoint, allowing authenticated attackers to execute arbitrary code.
IBM WebSphere Application Server versions 9.0 and 8.5 contain a broken access control vulnerability in the administrative console that allows for privilege escalation.
The Audio::openai_speech function in schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to a heap buffer overflow due to improper validation of externally controllable input during string concatenation.
The schreibfaul1 ESP32-audioI2S 3.4.5 library contains a heap-based buffer overflow in its HTTP header construction logic due to insufficient size validation of network parameters.
The schreibfaul1 ESP32-audioI2S 3.4.5 library is susceptible to a heap-based buffer overflow in the URL path concatenation module, allowing for remote code execution or system compromise.
A buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote attackers to execute code via crafted MP3 metadata.
A cross-tenant credential reuse vulnerability in HashiCorp terraform-mcp-server before 1.1.0 allows unauthorized access to tool calls by using a previous user's Terraform token.
An integer overflow in the buffer size calculation for schreibfaul1 ESP32-audioI2S 3.4.5 results in heap memory corruption, enabling denial of service or potential remote code execution.
The WordPress Coding Standards package is vulnerable to eval injection via improper neutralization of directives in dynamically evaluated code.
The Events Manager WordPress plugin before 7.3.7 is vulnerable to unauthenticated PHP object injection and SQL injection when configured for No-User-Account Booking Mode.
The Appium Java Client is vulnerable to Server-Side Request Forgery and confused deputy attacks due to improper handling of the W3C WebDriver protocol.
The Wholesale for WooCommerce plugin for WordPress is vulnerable to improper privilege management, allowing an authenticated attacker to escalate privileges.
A buffer overflow in Apple operating systems, caused by connecting to a malicious NFS server, can lead to kernel memory corruption and arbitrary code execution.
Adobe Bridge is affected by an incorrect authorization vulnerability that allows for privilege escalation.
Koollab LMS contains a post-authentication SQL injection vulnerability in the face-to-face runs update endpoint that can lead to database compromise and account takeover.
Apple iOS, iPadOS, and macOS are affected by an integer overflow vulnerability that can lead to arbitrary code execution when processing malicious images.
An out-of-bounds write vulnerability in various Apple operating systems allows for potential system compromise through improved bounds checking failures.
A memory corruption vulnerability in Safari and associated Apple platforms could lead to an unexpected browser crash or potential exploitation when processing malicious web content.
A use-after-free vulnerability in Apple Safari allows for potential system compromise or crashes when processing maliciously crafted web content.
Adobe Bridge is affected by an Untrusted Search Path vulnerability that may allow a local attacker to execute arbitrary code in the context of the current user.
Adobe Bridge is affected by an incorrect authorization vulnerability that could allow an attacker to execute arbitrary code in the context of the current user.
An integer overflow vulnerability in Apple operating systems allows a malicious application to potentially escape its sandbox.
Adobe Bridge is vulnerable to an untrusted search path flaw that can lead to arbitrary code execution in the context of the current user.
A path traversal vulnerability in Apple macOS allows a malicious application to potentially escape its sandbox environment.
An authorization vulnerability in Apple macOS allows a malicious application to potentially escape its sandbox due to improper state management.
The WP Password Policy plugin for WordPress contains an improper privilege management vulnerability that permits authenticated users to escalate their privileges.
The Eazy Plugin Manager WordPress plugin is vulnerable to privilege escalation, allowing authenticated users to potentially gain unauthorized administrative access.
Apache Traffic Server is vulnerable to out-of-bounds writes and integer overflows during the parsing of MIME and HTTP headers.
Apache Traffic Server improperly handles HTTP/2 origin trailers when converting to HTTP/1, leading to potential inconsistent interpretation of HTTP requests.
Apache Traffic Server is susceptible to a Regular Expression without Anchors vulnerability, which may allow for unauthorized access or security bypass.
The Ruby OAuth2 gem is susceptible to open redirection and sensitive information exposure, allowing attackers to redirect users to malicious sites or intercept authorization data.
The datamodel-code-generator library is vulnerable to Server-Side Request Forgery (SSRF) when processing schema definitions, potentially allowing unauthorized external requests.
MikroTik RouterOS API authentication handling is vulnerable to excessive login attempts, which may lead to unauthorized system access or service degradation.
The nebula-mesh control plane for Slack Nebula contains authorization bypass and missing authorization flaws that allow authenticated users to perform unauthorized actions.
The ads-tec Industrial IT DVG-IRF1401 series is affected by an authorization flaw allowing low-privileged users to perform unauthorized administrative configuration changes.
A missing authorization vulnerability in the configuration table insert path of various ads-tec Industrial IT devices allows low-privileged remote attackers to gain administrative system access.
Improper access control in the Devolutions Server role management endpoint allows authenticated non-administrative users with specific permissions to escalate privileges to administrator via API requests.
The ninenines cowlib library contains a resource allocation vulnerability where HTTP/2 or HTTP/3 peers can cause memory exhaustion, leading to a denial of service.
ELECOM wireless LAN routers are affected by an OS command injection vulnerability in the WebUI, which allows authenticated administrative users to execute arbitrary commands.
Multiple ELECOM wireless LAN access points contain an OS command injection vulnerability in the Restore Settings function, allowing administrative users to execute arbitrary system commands.
A flaw in the Red Hat OpenShift oauth-proxy component allows for interpretation conflicts, potentially impacting security controls.
Litestar is vulnerable to a cross-site scripting (XSS) attack due to improper neutralization of input during web page generation.
The HashiCorp Terraform MCP server contains a session fixation vulnerability that may allow attackers to hijack user sessions.
The datamodel-code-generator is vulnerable to code injection when processing malicious input to generate Pydantic models or other data classes.
SuperPlane is vulnerable to an authorization bypass via user-controlled keys, allowing authenticated users to access unauthorized objects.
The AT&T Arris BGW210-700 firmware contains a missing authentication vulnerability in critical functions, allowing unauthorized access from the local network.
Camaleon CMS is vulnerable to remote code execution via authenticated injection in the select_eval custom field functionality.
Anchore Enterprise contains a vulnerability where incorrect use of privileged APIs allows authenticated users to perform unauthorized actions.
A missing authentication flaw exists in Universal Software UKBS, allowing unauthenticated attackers to perform unauthorized actions on critical functions via adjacent network access.
IBM WebSphere Application Server is vulnerable to HTTP Request Smuggling due to inconsistent interpretation of HTTP requests.
IBM WebSphere Application Server is vulnerable to HTTP request smuggling due to inconsistent interpretation of HTTP requests, potentially allowing an unauthenticated attacker to bypass security controls.
The openhole utility contains a path traversal vulnerability that can be leveraged to expose local host resources to the public internet, potentially bypassing intended access controls.
A Server-Side Request Forgery (SSRF) vulnerability exists in the HashiCorp Terraform MCP Server, allowing remote attackers to send unauthorized requests to internal resources.
A Cross-Site Scripting vulnerability exists in the BlackBerry UEM Management Console due to improper neutralization of user-supplied input during web page generation.
The QTINeon library is vulnerable to uncontrolled resource consumption and network amplification due to insufficient throttling of network messages.
A Server-Side Request Forgery vulnerability exists in datamodel-code-generator, allowing attackers to force the application to make unauthorized requests to internal or external resources.
IBM Aspera Faspex 5 contains an insufficient session expiration vulnerability that could allow an unauthenticated attacker to hijack active user sessions.
NVIDIA DCGM Exporter is vulnerable to uncontrolled resource consumption via unauthenticated profiling requests sent to the debug endpoints.
Pivotick fails to sanitize SVG markup provided in per-node styles, exposing the application to stored cross-site scripting attacks.
Pivotick is susceptible to an uncontrolled recursion vulnerability when processing specific graph and node data, which can result in a denial of service.
IBM WebSphere Application Server is susceptible to a deserialization of untrusted data vulnerability, which could allow an unauthenticated attacker to achieve remote code execution.
The Events Booking extension for Joomla prior to version 5.8.2 fails to properly verify authorization for downloading invoice information.
A heap-based buffer overflow in the ID3v2 SYLT parser of ESP32-audioI2S allows remote code execution via a crafted MP3 file.
A heap-based buffer overflow in the ID3v2 APIC frame parser of ESP32-audioI2S allows remote code execution via a crafted MP3 file.
A heap-based buffer overflow in the connecttospeech function of ESP32-audioI2S allows remote code execution via crafted speech text inputs.
A directory traversal vulnerability in Menyoo 2.0 allows a local attacker to execute arbitrary code via multiple file management functions.