CVE-2026-16812
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
Critical vulnerabilities, curated daily for security professionals
Yesterday's disclosures were dominated by memory-safety flaws in Mozilla Firefox and remote code execution in pgAdmin 4, alongside a critical issue in WebPros cPanel that exposes hosting control planes. The day brought 24 critical vulnerabilities (down 41% from the prior day's 41) and 77 high-priority CVEs (up 4%), for 101 total. CVE-2026-17566 (CVSS 9.9) and CVE-2026-17349 (CVSS 9.6) both affect pgAdmin 4, four Firefox CVEs (CVE-2026-16365, CVE-2026-16366, CVE-2026-16371, CVE-2026-16372) each carry CVSS 9.8, and CVE-2026-58048 (CVSS 9.4) affects cPanel. Web application and hosting infrastructure remain the largest affected categories, with WordPress plugins (wpwax FormGent), PHP frameworks (CodeIgniter4), and commercial PHP scripts contributing additional critical entries. Vendor patch data was not available for these records at collection time, so track vendor advisories directly; three CVEs affecting Arista VeloCloud Orchestrator, Cisco Secure Firewall Management Center, and Fortinet FortiOS have confirmed active exploitation.
Immediate action: Prioritize network edge and security appliances first: Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS all have confirmed exploitation. Follow with Firefox browser updates across endpoints and pgAdmin 4, cPanel, and CodeIgniter4 installations exposed to untrusted input. Patch availability was not captured for these records, so check vendor advisories directly and apply mitigations or access restrictions where fixes are not yet published.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
A hard-coded password vulnerability in Cisco Secure Firewall Management Center allows unauthenticated attackers to potentially bypass security controls.
A sensitive information disclosure vulnerability exists in Fortinet FortiOS, allowing unauthenticated attackers to access restricted system data.
The FormGent WordPress plugin is vulnerable to unauthenticated arbitrary file deletion via the REST API, potentially allowing attackers to delete critical files such as wp-config.php.
A SQL injection vulnerability in the PHP Jabbers Car Rental Script allows unauthenticated attackers to execute malicious database queries through improperly sanitized sorting parameters.
A vulnerability in the pgAdmin 4 Workspaces feature allows authenticated users to clone and inherit sensitive database credentials from other users, leading to unauthorized access.
A SQL injection vulnerability in cPanel allows authenticated users with low privileges to execute arbitrary SQL commands in the root context when renaming databases.
A SQL injection vulnerability in the deleteBatch method of CodeIgniter4 allows attackers to bypass escape flags and execute arbitrary SQL commands via user-controlled input.
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153.
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153.
An OS command injection vulnerability in the Import/Export Data tool of pgAdmin 4 allows authenticated users to execute arbitrary commands on the underlying host.
ComfyUI v0.23.0 contains an insecure deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code.
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153, Firefox ESR
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Integer overflow in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
A flawed fix in pgAdmin 4 allows for SQL injection via AI Assistant tool calls, enabling attackers to execute arbitrary multi-statement SQL commands.
A critical authentication bypass in the ShopMonitor.io WordPress plugin allows unauthenticated attackers to hijack administrator accounts via email redirection.
A logic flaw in the sentence-transformers library allows attackers to bypass security checks and achieve arbitrary code execution by loading malicious local models.
A vulnerability in Pterodactyl Wings allows authenticated users to read sensitive configuration tokens and registry credentials from daemon configuration files.
A server-side request forgery vulnerability in the bank-vaults vault-secrets-webhook allows attackers to redirect ServiceAccount JWTs to arbitrary, attacker-controlled Vault addresses.
A code injection vulnerability in Logsign SIEM allows unauthenticated attackers to execute arbitrary code due to improper control of code generation.
A stack-based buffer overflow in the Tenda W6-S web interface allows remote, unauthenticated attackers to trigger a crash or execute arbitrary code via the wifiSSIDset endpoint.
The REDAXO CMS core contains an unrestricted file upload vulnerability that allows authenticated users to execute arbitrary code on the server.
PHP contains a flaw involving improper escaping of backslashes in attacker-provided parameters, which enables trivial SQL injection attacks.
An incorrect authorization vulnerability in the Google mcp-toolbox HTTP API tool invocation endpoint allows unauthenticated users to perform unauthorized actions.
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to privilege escalation in versions up to 2.0.0, allowing authenticated users to gain unauthorized access.
Multiple PHP Jabbers scripts contain an authenticated SQL injection vulnerability, allowing privileged users to execute unauthorized database commands.
The PHP Jabbers PHP Poll Script is susceptible to a SQL injection vulnerability, allowing authenticated users to perform unauthorized database operations.
An authentication bypass and audience confusion vulnerability in the Google OAuth provider component of mcp-toolbox allows unauthenticated attackers to compromise authentication flows.
The Kali Forms plugin for WordPress is vulnerable to remote code execution in versions up to 2.4.20 due to improper control of code generation.
The Product Feed Manager For WooCommerce plugin for WordPress is vulnerable to SQL injection in versions before 7.6.1, allowing authenticated users to manipulate database queries.
A vulnerability in the bccomp function of PHP allows attackers to trigger an out-of-bounds write, potentially leading to memory corruption.
A Server-Side Request Forgery (SSRF) vulnerability in the generic HTTP source and tool components of Google mcp-toolbox allows unauthenticated attackers to perform unauthorized outbound requests.
Adobe Premiere Pro contains an out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code in the context of the current user.
A path traversal vulnerability in the CodeIgniter4 framework allows attackers to access restricted directories through improper input validation.
The AI Engine plugin for WordPress is vulnerable to Cross-Site Request Forgery, potentially allowing unauthorized actions to be performed on behalf of an authenticated user.
The Frontend Admin by DynamiApps WordPress plugin is vulnerable to Cross-Site Scripting (XSS) due to improper input sanitization, allowing unauthenticated attackers to execute malicious scripts.
The Kirki WordPress plugin is vulnerable to SQL Injection, which allows unauthenticated attackers to execute arbitrary SQL commands and potentially access sensitive database information.
The NEX-Forms plugin for WordPress is vulnerable to path traversal, which could allow an authenticated attacker to delete arbitrary files on the server.
The Ultimate Member WordPress plugin is vulnerable to improper privilege management, which could allow an attacker to gain unauthorized access or elevate their permissions.
The miniOrange 2FA WordPress plugin is susceptible to an improper authentication vulnerability that may allow unauthenticated attackers to bypass security controls.
Apache JSPWiki is vulnerable to a Cross-Site Request Forgery (CSRF) attack, which may allow an unauthorized actor to perform actions on behalf of a victim.
A vulnerability in Red Hat Advanced Cluster Security for Kubernetes (RHACS) allows for insufficient verification of data authenticity.
The Bit Integrations plugin for WordPress contains a path traversal vulnerability that could allow unauthenticated attackers to read sensitive files on the server.
The Kirki WordPress plugin contains a deserialization of untrusted data vulnerability that could lead to remote code execution or other malicious impacts.
The GiveWP WordPress plugin before 4.16.3 is vulnerable to an information exposure flaw, allowing unauthenticated attackers to access sensitive data.
The Demi WordPress plugin before 0.0.7 contains an improper privilege management vulnerability, which may allow unauthenticated attackers to gain unauthorized access or elevate privileges.
The FlxWoo WordPress plugin before 3.1.1 is affected by an improper authentication vulnerability, allowing unauthenticated attackers to potentially perform unauthorized actions.
The JS Help Desk WordPress plugin contains a missing authorization vulnerability that allows unauthenticated attackers to access sensitive information.
The Geeky Bot WordPress plugin is susceptible to an information exposure vulnerability allowing unauthenticated remote attackers to access sensitive data.
Apache Kyuubi contains an incomplete security fix for a path traversal vulnerability, potentially allowing authenticated users to access unauthorized files.
VMware products, including Cloud Foundation, ESX, Workstation, and Fusion, are affected by an out-of-bounds read vulnerability that could be exploited by an authenticated user.
A code injection vulnerability in the Savon Ruby SOAP client allows attackers to execute arbitrary code through improper generation of code during SOAP processing.
The SSH service on Bosch BSH ELP modules is vulnerable to incorrect user management due to an insecure default configuration.
TP-Link AXE75 V1 routers are susceptible to OS command injection in the VPN module, enabling remote code execution by high-privileged users.
A flaw in the aap-gateway component of Red Hat Ansible Automation Platform 2 allows unauthenticated attackers to bypass mTLS authentication for event streams.
A cross-site scripting (XSS) vulnerability in ComfyUI allows attackers to execute malicious scripts in the context of a user session.
ComfyUI contains a Cross-site Scripting (XSS) vulnerability that allows for the execution of arbitrary scripts in the context of a user session.
The IRIS web application contains a Stored Cross-site Scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts.
A stored cross-site scripting (XSS) vulnerability in iris-web version 2.4.26 allows authenticated users with low privileges to execute arbitrary scripts in the context of other users.
A stored cross-site scripting (XSS) vulnerability exists in iris-web version 2.4.26, which may be exploited by authenticated users to execute malicious scripts against other users.
A vulnerability in gnome-remote-desktop allows for uncontrolled resource consumption, potentially leading to a denial of service condition.
ComfyUI is vulnerable to a path traversal flaw, allowing an unauthenticated attacker to access restricted files on the host system.
A path traversal vulnerability in ComfyUI allows unauthenticated remote attackers to access unauthorized files on the server.
The FTC E-Commerce Management Panel contains a missing authentication flaw that allows unauthorized parties to access critical administrative functions.
A stack-based buffer overflow vulnerability exists in the 389 Directory Server (389-ds-base) component, which may allow for a denial of service.
An SQL injection vulnerability exists in pgAdmin 4 due to an incomplete fix for a previous security issue, allowing authenticated users to execute unauthorized database commands.
A path traversal vulnerability in the Thumbor image processing service allows remote attackers to access sensitive files on the server filesystem.
A Server-Side Request Forgery (SSRF) vulnerability in dssrf-js allows unauthenticated attackers to perform unauthorized requests.
A path traversal and injection vulnerability in hashi-vault-js allows unauthenticated attackers to access unauthorized files or influence downstream components.
An out-of-bounds read and signed-to-unsigned conversion error in coturn allows unauthenticated attackers to potentially read sensitive memory.
Thumbor contains an improper verification of cryptographic signatures vulnerability, which allows an unauthenticated attacker to bypass security controls.
Thumbor is susceptible to a Server-Side Request Forgery vulnerability, allowing unauthenticated attackers to force the application to make unauthorized requests.
A provisioning script in the ANDRITZ HIPASE-250 and 250 SCALA engineering workstations sets a hard-coded x11vnc password, allowing unauthorized remote access.
A heap use-after-free vulnerability in the TransferSubscriptions service of open62541 allows an authenticated attacker to cause a denial of service or potentially execute arbitrary code.
IBM Langflow OSS contains a .NET impersonation misconfiguration that may allow authenticated users to perform unauthorized actions.
MaxKey contains a permissive input validation vulnerability that allows for unauthorized OAuth authorization code theft.
Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data.
Multiple Regular Labs extensions for Joomla are vulnerable to an authentication bypass via spoofable forwarded headers, allowing remote attackers to circumvent IP and GeoIP-based access restrictions.
Tigera Calico fails to perform URL path normalization in its Application Layer Policy, potentially allowing attackers to bypass security rules.
An argument injection vulnerability in the yggdrasil-worker-package-manager allows local authenticated users to execute arbitrary commands.
A use-after-free vulnerability in the Zephyr Bluetooth GATT client handler can lead to memory corruption when processing specific responses.
A missing authorization vulnerability in OpenProject allows authenticated users to perform unauthorized actions due to improper capability checks.
A Server-Side Request Forgery vulnerability in the Cost Management Metrics Operator allows authenticated users to exfiltrate sensitive cluster-global bearer tokens.
A Server-Side Request Forgery vulnerability in the Red Hat Cost Management Metrics Operator allows authenticated users to steal Kubernetes service-account bearer tokens.
Copier is vulnerable to path traversal and incorrect validation order, allowing unauthenticated attackers to manipulate file paths during template rendering.
Thumbor contains an input validation vulnerability that can result in a divide-by-zero error, leading to a denial-of-service condition.
Thumbor is susceptible to uncontrolled resource consumption, allowing unauthenticated attackers to cause a denial-of-service.
Thumbor is vulnerable to uncontrolled resource consumption, allowing unauthenticated attackers to cause a denial of service via specifically crafted requests.
A vulnerability in the Pterodactyl Wings server control plane allows unauthenticated remote attackers to trigger service crashes via improper error and array index handling.
pgAdmin 4 is vulnerable to OS command and argument injection via the MASTER_PASSWORD_HOOK setting, allowing authenticated users to execute arbitrary commands.
The fast-uri library is susceptible to an interpretation conflict vulnerability due to improper URI parsing, which may lead to security bypasses.
Red Hat Directory Server is vulnerable to LDAP injection, allowing unauthenticated attackers to manipulate query logic.
ANDRITZ HIPASE-250 exposes its configuration endpoint without authentication, allowing unauthenticated remote access and permissive cross-domain policies.
ANDRITZ HIPASE-250 and 250 SCALA store and transmit user passwords in a reversible format instead of utilizing secure one-way hashing.
A privilege escalation and remote code execution vulnerability exists in ZipGenius v6.3.2.3116 and earlier due to an issue within the zipgenius.exe binary.
OIDC::Lite for Perl allows an ID Token signature verification bypass due to a token-controlled algorithm allowlist in the verification process.
A local privilege escalation vulnerability in the Protegent 360 kernel driver allows unprivileged users to gain SYSTEM-level execution.
A path traversal vulnerability in the unrar.dll component of IZArc v4.6 allows attackers to write files to unauthorized locations on the host system.