CVE-2026-16812
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
Critical vulnerabilities, curated daily for security professionals
Yesterday's disclosures centered on widely deployed client and server software, with FreeRDP, ArcadeData ArcadeDB, and Mozilla Firefox accounting for the highest-severity entries. The set includes 23 critical CVEs (CVSS 9.0+), down 4% from the prior day, and 43 high-priority CVEs, down 44%. CVE-2026-66402 (CVSS 9.8) and CVE-2026-67305 (CVSS 9.4) affect FreeRDP, the RDP client library embedded in numerous remote access tools, while CVE-2026-67340, CVE-2026-67341, and CVE-2026-67342 (all CVSS 9.8) hit ArcadeDB, and CVE-2026-16379 and CVE-2026-16377 (both CVSS 9.8) affect Firefox. WordPress and Joomla extensions make up a further cluster, including CVE-2026-8457 in WooCommerce Social Login and CVE-2026-65431 in the Regular Labs GeoIP extension, both authentication and access control weaknesses in internet-facing sites. Three CVEs have confirmed active exploitation in network edge products from Arista, Cisco, and Fortinet, and no patch availability was recorded for the disclosed set, so confirm fixed versions directly with vendor advisories before scheduling remediation.
Immediate action: Prioritize the network edge appliances under active exploitation first: Arista VeloCloud Orchestrator On-Prem, Cisco Secure Firewall Management Center, and Fortinet FortiOS. Next, inventory systems bundling FreeRDP, internet-reachable ArcadeDB instances, and Firefox deployments, then update WordPress and Joomla sites running WooCommerce Social Login, Single Sign On For TNG, or the Regular Labs GeoIP extension. No patch data was recorded for these disclosures, so check vendor advisories for fixed builds and apply access restrictions or network segmentation where a fix is not yet published.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An OS command injection vulnerability in Arista VeloCloud Orchestrator On-Prem allows unauthenticated remote attackers to execute arbitrary commands with elevated privileges.
A hard-coded password vulnerability in Cisco Secure Firewall Management Center allows unauthenticated attackers to potentially bypass security controls.
A sensitive information disclosure vulnerability exists in Fortinet FortiOS, allowing unauthenticated attackers to access restricted system data.
FreeRDP contains multiple TLS certificate validation flaws allowing attackers to bypass server identity verification due to improper handling of Common Name and DNS SAN strings.
A heap-based buffer overflow in the FreeRDP Windows client's clipboard virtual channel allows remote code execution when processing malicious clipboard responses from an RDP server.
The WooCommerce - Social Login plugin is vulnerable to authentication bypass via forged Apple ID tokens and exposed security nonces, allowing attackers to hijack any user account.
ArcadeDB allows authenticated users to execute arbitrary OS commands via malicious JavaScript triggers due to improper package filtering within the script executor.
ArcadeDB fails to enforce authorization checks on SQL DEFINE FUNCTION statements, allowing users with database access to execute arbitrary JavaScript code.
ArcadeDB suffers from an authorization bypass in multiple HTTP handlers, allowing unauthorized users to access or modify databases by manipulating endpoint parameters.
Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
The Single Sign On For TNG WordPress plugin suffers from an unauthenticated password reset vulnerability due to insufficient validation of AJAX requests.
A path traversal vulnerability in the Regular Labs GeoIP extension for Joomla allows for arbitrary file writes during the extraction of database update archives.
Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153.
Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153.
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 153.
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.
GitPython fails to properly filter joined short-option arguments, allowing attackers to bypass security gates and execute arbitrary commands during repository cloning.
FreeRDP is vulnerable to HTTP request header injection because it fails to sanitize control characters in RDP redirection addresses when using an HTTP proxy.
Wazuh workflows contain a shell injection vulnerability in GitHub Actions, allowing attackers to execute arbitrary commands via crafted VERSION.json files in pull requests.
The Perl module Image::WebP bundles a vulnerable version of libwebp, which allows remote attackers to trigger heap corruption and potential code execution via a specially crafted WebP image.
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
An authorization bypass in the @better-auth/scim plugin allows authenticated users to mint SCIM tokens that collide with existing provider namespaces, resulting in unauthorized account takeover.
The axios library in Node.js is vulnerable to prototype pollution when handling certain inputs via the Node.js HTTP adapter, potentially leading to unauthorized information exposure.
The Pronamic Pay plugin for WordPress contains an improper privilege management vulnerability, allowing authenticated users to perform unauthorized actions.
The CubeWP Framework plugin for WordPress is susceptible to directory traversal, which may allow unauthenticated attackers to access sensitive files on the server.
The User Access Manager plugin for WordPress is vulnerable to directory traversal, enabling unauthenticated attackers to access restricted files on the underlying server.
The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values.
LuCI app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter, allowing authenticated users to inject active HTML.
GitPython is vulnerable to OS Command Injection via improper neutralization of special elements in option prefix abbreviations, allowing authenticated attackers to execute arbitrary commands.
GitPython is vulnerable to Command Injection via improper neutralization of unguarded Git options, potentially allowing an attacker to execute arbitrary commands on the system.
GitPython is vulnerable to the unauthorized exposure of sensitive information, such as environment variables, via improper handling of clone operations.
GitPython is vulnerable to improper input validation, allowing for potential newline injection via the config writer section.
A stored cross-site scripting vulnerability in AWS Ops Wheel allows authenticated remote users to steal session tokens via crafted participant_url values containing dangerous URI schemes.
N-able N-central is affected by an authentication bypass vulnerability using an alternate path or channel, potentially allowing unauthorized access.
ArcadeDB is vulnerable to the exposure of sensitive information, specifically cluster tokens, via the get API v1 server endpoint.
The better-auth library contains a vulnerability related to the use of insecure cryptographic defaults within its OIDC provider, which could allow for unauthorized cryptographic operations.
A flaw in the better-auth library allows for account takeover via magic link or email OTP mechanisms due to improper authentication validation.
An authorization bypass vulnerability exists in the better-auth SCIM implementation where user-controlled keys can lead to unauthorized access.
A cryptographic signature verification flaw in Ueberauth Guardian allows unauthenticated attackers to revoke user sessions by forging tokens.
A cross-site scripting vulnerability in Better-auth SSO allows authenticated users to perform account takeovers.
A race condition in the Linux kernel Mellanox mlx5e network driver allows for unlocked access to the ICOSQ during NAPI polling, resulting in potential denial-of-service.
A path traversal vulnerability in Traefik version 3.7.0 and later allows unauthenticated attackers to bypass authentication and access restricted directories.
A NULL pointer dereference vulnerability exists in FreeRDP before version 3.29.0, which can be triggered via specially crafted smartcard cache data.
An out-of-bounds read vulnerability exists in FreeRDP before version 3.29.0, which can be triggered via the TSMF (Transport Stream Multimedia Framework) component.
An out-of-bounds read vulnerability exists in FreeRDP before version 3.29.0, specifically within the glyph fragment addition functionality.
FreeRDP is susceptible to a denial of service vulnerability due to improper input validation within the RDPEI PDU handling process, allowing remote attackers to crash the service.
FreeRDP is vulnerable to resource exhaustion through improper handling of chunked HTTP responses, which can be exploited by an unauthenticated attacker to cause a denial of service.
An integer underflow vulnerability exists in FreeRDP within the RAIL order length processing, potentially leading to heap buffer overflows and remote code execution or crashes.
A use after free vulnerability exists in FreeRDP versions prior to 3.29.0, potentially allowing for denial of service via window icon asynchronous messages.
A use after free vulnerability in FreeRDP prior to 3.29.0 allows for potential denial of service through the asynchronous message proxy.
An out of bounds read vulnerability in FreeRDP versions before 3.29.0 may allow for denial of service via polygon asynchronous messages.
A NULL pointer dereference vulnerability in FreeRDP allows for service disruption during smartcard cleanup operations.
An incorrect authorization vulnerability in the http_request tool of Strands Agents Tools allows unauthorized data access.
A prototype pollution vulnerability in the defaults-deep library allows attackers to modify object attributes.
The better-auth library is susceptible to a stored Cross-Site Scripting (XSS) vulnerability caused by improper neutralization of input during web page generation.
Certain Hikvision wireless access points contain a command execution vulnerability due to insufficient input validation that can be triggered by an authenticated user.
The better-auth library is vulnerable to an open redirect attack, allowing attackers to redirect users to untrusted sites via a bypassed trust check.
An authorization bypass vulnerability in @better-auth/stripe allows authenticated users to manipulate subscription access via user-controlled keys.
The coturn TURN and STUN server implementation is susceptible to an authorization bypass vulnerability, potentially allowing unauthorized access to server resources.
An out-of-bounds read vulnerability exists in the Linux kernel mac80211 Wi-Fi subsystem due to incorrect handling of negotiated TTLM elements during parsing.
A use-after-free vulnerability in the Linux kernel spi: ti-qspi driver occurs when DMA setup fails, allowing for potential memory corruption or code execution.
Logto fails to invalidate IdP-initiated SAML sessions after use, enabling session replay attacks within the session validity window.
The Regular Labs GeoIP extension for Joomla leaks sensitive MaxMind credentials in request URLs, exposing them to unauthorized parties.
A boundary condition error in the Linux kernel ASoC simple-mux codec driver allows for improper validation of enum control values, leading to potential memory corruption.
A double free vulnerability in the Linux kernel OcteonTX2 network driver's pool management subsystem during Admin Queue initialization can lead to system instability.