CVE-2026-20316
A hard-coded password vulnerability in Cisco Secure Firewall Management Center allows unauthenticated attackers to potentially bypass security controls.
Critical vulnerabilities, curated daily for security professionals
Adobe Campaign Classic accounts for a large share of yesterday's critical disclosures, with five CVSS 9.8+ flaws including two rated 10.0, alongside three maximum-severity vulnerabilities in the SiYuan open-source note-taking platform. Critical CVEs rose to 44 from 16 the prior day (175%), while high-priority CVEs reached 75, up 36%. Notable entries include CVE-2026-48330 and CVE-2026-48331 (Adobe Campaign Classic, CVSS 10), CVE-2026-69085 and CVE-2026-69084 (siyuan-note SiYuan, CVSS 10), and CVE-2026-69240 in the Sequelize ORM at CVSS 9.8. Remote code execution and authentication bypass patterns dominate, spanning enterprise marketing platforms, healthcare software (CVE-2026-39932 in OpenEMR, CVSS 9.1), and widely used JavaScript libraries such as Baileys and Sequelize. Two vulnerabilities have confirmed active exploitation, in Cisco Secure Firewall Management Center (CVE-2026-20316, CVSS 9.5) and N-able N-central (CVE-2026-18577, CVSS 8.2); with patch availability recorded at 0% across the set, teams should verify vendor advisories directly and apply mitigations where fixes are pending.
Immediate action: Prioritize Cisco Secure Firewall Management Center and N-able N-central, both under active exploitation and often internet-reachable management planes, then move to Adobe Campaign Classic instances exposed to untrusted input. Patch data is unavailable for these entries, so check vendor advisories for fixed builds and apply access restrictions or network segmentation on SiYuan, OpenEMR, and Sequelize-based applications until versions are confirmed.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A hard-coded password vulnerability in Cisco Secure Firewall Management Center allows unauthenticated attackers to potentially bypass security controls.
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
OpenEMR contains a remote code execution vulnerability via eval injection in the CategoryTree component, allowing authenticated administrators to execute arbitrary OS commands.
SiYuan contains a SQL injection vulnerability in the searchDocs endpoint, allowing unauthenticated attackers to read and modify database content via stacked queries.
A critical SQL injection vulnerability in the SiYuan /api/search/searchEmbedBlock endpoint allows unauthenticated remote attackers to execute arbitrary SQL commands on the underlying database.
The Baileys WhatsApp API allows unauthenticated remote attackers to spoof messages and corrupt the application state by sending malicious payloads to the placeholderResendMessage function.
Adobe Campaign Classic is vulnerable to SQL injection, which allows an unauthenticated remote attacker to execute arbitrary SQL commands and achieve arbitrary code execution.
Adobe Campaign Classic is affected by a Server-Side Request Forgery (SSRF) vulnerability that enables unauthenticated attackers to escalate privileges.
A critical SQL injection vulnerability in the SiYuan fullTextSearchAssetContent endpoint allows unauthenticated attackers to read, modify, or delete data across multiple notebooks.
Adobe Campaign Classic is vulnerable to SQL injection, which allows a low-privileged authenticated attacker to execute arbitrary code.
Adobe Campaign Classic is vulnerable to an Incorrect Authorization flaw allowing unauthenticated attackers to perform privilege escalation.
Sequelize ORM versions prior to 6.37.4 contain an SQL injection vulnerability in the Oracle dialect when processing specific date strings, allowing unauthenticated attackers to execute arbitrary SQL.
Telenia Software TVox contains an authentication bypass vulnerability via set_env.php, allowing unauthenticated attackers to access restricted PHP scripts by manipulating the requested path.
Adobe Campaign Classic contains a template engine vulnerability that allows unauthenticated remote attackers to execute arbitrary code.
Adobe Campaign Classic is vulnerable to Eval Injection, allowing a low-privileged attacker to execute arbitrary code.
An authentication bypass vulnerability in Check Point Security Management Server allows unauthenticated remote attackers to execute arbitrary commands.
The go-base boilerplate template contains a hardcoded JWT signing secret, allowing unauthenticated attackers to forge authentication tokens and bypass security controls.
The ChamaWP WordPress plugin contains a missing authorization flaw in the password reset process, allowing unauthenticated attackers to reset the passwords of any user.
The Simple Membership WordPress plugin contains an authorization bypass vulnerability allowing unauthenticated attackers to overwrite administrator account data and perform account takeovers.
The GeoVision GV-AS1620 AS-Manager firmware contains a hard-coded RSA private key, allowing attackers to decrypt HTTPS traffic and spoof the server.
The GeoVision GV-AS1620 GV-Cloud firmware contains a hard-coded RSA private key, which allows attackers to decrypt HTTPS traffic and spoof the server.
Quest KACE Systems Deployment Appliance uses a hardcoded symmetric encryption key to protect secrets in MySQL databases, allowing unauthorized decryption by attackers with access to database backups.
The @fastify/aws-lambda package in version 6.4.0 allows unauthenticated attackers to forge API Gateway proxy events, leading to a complete authentication and authorization bypass.
A critical authentication bypass vulnerability in WAPT Server allows remote, unauthenticated attackers to forge session tokens via specially crafted packets.
An unrestricted file upload vulnerability in HUMANIST Digital Human Resources allows remote, unauthenticated attackers to upload and execute malicious web shells on the server.
A command injection vulnerability in the nas-web component of GL.iNet GL-MT3000 allows remote, unauthenticated attackers to execute arbitrary system commands via the add_user function.
A command injection vulnerability in the set_upgrade function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers to execute arbitrary system commands.
A command injection vulnerability in the remove_profile function of the GL.iNet GL-MT3000 modem.so component allows remote, unauthenticated attackers to execute arbitrary system commands.
A command injection vulnerability in the server.set_peer function of the GL-iNet GL-MT3000 wg-server.so plugin allows remote, unauthenticated attackers to execute arbitrary commands.
A command injection vulnerability in the s2s.so plugin of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary commands via the s2s.enable_echo_server function.
An unauthenticated remote command injection vulnerability in the GL-iNet GL-MT3000 allows attackers to execute arbitrary commands via the wg-server.generate_publickey function.
A command injection vulnerability in the plugins.so component of the GL-iNet GL-MT3000 allows unauthenticated remote attackers to execute arbitrary commands via the package management functions.
A remote injection vulnerability exists in the plugins.set_config function of the GL-iNet GL-MT3000 router firmware, allowing unauthenticated attackers to execute arbitrary code.
A command injection vulnerability in the ovpn-client.get_recommend_config function of GL.iNet GL-MT3000 routers allows unauthenticated remote attackers to execute arbitrary system commands.
A missing authentication vulnerability in the Krayin CRM installer middleware allows unauthenticated remote attackers to overwrite the administrator account and gain full CRM access.
A command injection vulnerability in the GL.iNet GL-MT3000 ovpn-client.so plugin allows unauthenticated remote attackers to execute arbitrary code via the filename argument in /cgi-bin/glc.
Tenable Sensor Proxy is vulnerable to remote code execution, allowing an unauthenticated attacker to gain elevated privileges if an operator connects the sensor to a malicious host.
HUMANIST Digital Human Resources contains a cleartext storage vulnerability that facilitates SQL injection, allowing unauthenticated attackers to compromise sensitive application data.
Net::SAML2 fails to verify cryptographic signatures on encrypted SAML assertions, allowing unauthenticated attackers to bypass authentication and impersonate arbitrary users.
An authorization bypass vulnerability in Menulux Software Mobile App allows attackers to access unauthorized data by manipulating record identifiers.
osTicket 1.18.3 uses insecure MD5 hashing with predictable inputs to generate API keys, allowing attackers to brute-force authentication credentials.
Misskey fails to properly validate JSON-LD signatures, enabling attackers to spoof activities on the federated social media platform.
Bilin Software and Informatics Consultancy HUMANIST Digital Human Resources versions 26.0 before 26.1 contain a hard-coded cryptographic key, allowing for unauthorized access to sensitive constants.
The XML::Sig library for Perl, in versions before 0.71, is vulnerable to XPath injection due to improper neutralization of URI data during the document verification process.
XML::Sig versions before 0.71 for Perl are vulnerable to signature wrapping attacks because the library fails to detect duplicate ID attributes during the XML verification process.
Quest KACE SMA 11.0.273 fails to enforce IP-based access restrictions on API endpoints, allowing bypass of console security.
Angular is vulnerable to insufficient verification of data authenticity, which may allow attackers to bypass security checks.
Angular is susceptible to a Cross-site Scripting (XSS) vulnerability during web page generation, which can be triggered by malicious user interaction.
A use after free vulnerability in Microsoft Office Excel allows an unauthenticated attacker to achieve remote code execution through malicious file interaction.
A Cross-site Scripting (XSS) vulnerability exists in the Angular compiler and core, allowing for script injection during the web generation process.
A use after free vulnerability in Microsoft Edge allows an unauthenticated attacker to execute code over a network via a specially crafted web page.
A code injection vulnerability exists in the LINE Android application, which could allow an attacker to execute arbitrary code via malicious input.
Privilege escalation in the Data Loss Prevention component.
An origin validation error in Microsoft Edge allows an unauthenticated attacker to disclose sensitive information over a network.
FirmaCheck for Windows is vulnerable to DLL hijacking due to an untrusted search path, which could allow local attackers to execute arbitrary code.
Microsoft Edge for Android contains a vulnerability involving external control of file paths, which may allow an unauthenticated attacker to perform local information disclosure.
The ip-address library for JavaScript is vulnerable to improper input validation, leading to potential Server-Side Request Forgery (SSRF) attacks.
Adobe Campaign Classic is susceptible to a violation of secure design principles, which may result in a security feature bypass.
Quest KACE SMA 11.0.273 is shipped with publicly known default credentials for its MySQL database accounts.
The LogMyTrip WordPress plugin is vulnerable to unauthenticated SQL injection, allowing remote attackers to potentially extract sensitive information from the underlying database.
The sm page duplicator WordPress plugin contains a SQL injection vulnerability that allows authenticated users with low privileges to execute arbitrary database queries.
An issue in aiflowy <= 2.
Apache NiFi is affected by an improper handling of highly compressed data, which can lead to data amplification and potential resource exhaustion.
A command injection vulnerability in the OpenWrt luci-app-dockerman package allows authenticated users to execute arbitrary OS commands.
An improper access control vulnerability in Dell Display and Peripheral Manager for macOS allows local authenticated users to escalate privileges.
A missing authentication vulnerability for critical functions in Dell Display and Peripheral Manager for macOS allows local authenticated users to perform unauthorized operations.
An incorrect authorization vulnerability in Apache NiFi allows authenticated users to bypass validation checks for Parameter Context requests.
Apache Jena Fuseki is affected by a path traversal vulnerability that allows unauthenticated attackers to access restricted files on the server.
The Tablesome Table WordPress plugin fails to validate authentication for AJAX actions, allowing unauthenticated users to create or overwrite site content.
The pyca cryptography package is susceptible to an uncontrolled resource consumption vulnerability, potentially leading to a denial of service.
The jpillora chisel tool contains an incorrect authorization vulnerability that may allow authenticated users to bypass security controls.
The pyca cryptography package is vulnerable to timing discrepancies and sensitive information leakage in error messages.
Node.js is vulnerable to uncontrolled resource consumption, which may result in a denial of service condition when processing specific inputs.
TP-Link Omada devices use shared embedded certificates to establish trust between controllers and managed devices, creating a risk of unauthorized impersonation.
A certificate validation weakness in the communication between TP-Link Omada devices and cloud controllers enables potential interception of traffic.
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
A deserialization of untrusted data vulnerability in TUBITAK BILGEM eta-otp-lock allows for potential object injection attacks.
A race condition in the Misskey social media platform allows unauthenticated attackers to manipulate data integrity.
A prompt injection vulnerability in the shell tool of Amazon Strands Agents Tools allows unauthorized manipulation of LLM interactions.
Multiple Wavlink networking devices are vulnerable to stack-based buffer overflows and memory corruption, potentially allowing remote code execution.
Krayin Laravel CRM is vulnerable to SQL injection via the lead datagrid, allowing authenticated attackers to execute arbitrary SQL commands.
A command injection vulnerability exists in the GL.iNet GL-MT3000 router that allows authenticated users to execute arbitrary system commands via the network switch information RPC interface.
A command injection vulnerability exists in the GL.iNet GL-MT3000 router, allowing authenticated users to execute arbitrary commands through the system log retrieval RPC interface.
A server-side request forgery (SSRF) vulnerability exists in the PDF-generation functionality of the MISP cti-transmute tool, potentially allowing unauthorized data access.
CTI-Transmute is vulnerable to a cross-site request forgery attack within the administrative user deletion functionality, potentially allowing unauthorized account removal.
The Digest authentication component in Eclipse Jetty incorrectly uses ISO-8859-1 encoding for passwords, which can lead to authentication bypass or credential handling issues.
CTI-Transmute is vulnerable to an uncontrolled resource consumption attack at the unauthenticated activity_timeline endpoint, which could lead to a denial of service.
The refirio freo2 application is vulnerable to an unrestricted file upload flaw, allowing authenticated users with high privileges to upload malicious files.
The SiYuan application contains an authentication bypass vulnerability via content endpoints, allowing unauthenticated remote attackers to access sensitive data.
The SiYuan application contains a missing authorization vulnerability, allowing unauthenticated remote attackers to access sensitive information via specific API endpoints.
SiYuan versions before 3.7.3 contain a missing authorization vulnerability that allows unauthenticated attackers to access sensitive information.
ASUSTOR ABP and AES services utilize a vulnerable inter-process communication mechanism that allows local privilege escalation to NT AUTHORITY\SYSTEM.
Q00 Ouroboros versions before 0.42.1 are vulnerable to code injection and unauthorized configuration changes due to improper validation of user-defined policies.
Q00 Ouroboros is vulnerable to an untrusted search path flaw, which could allow a local attacker to execute arbitrary code or manipulate agent behavior.
A heap-based buffer overflow vulnerability in the Zephyr RTOS hawkBit device management client allows for potential memory corruption during HTTP response processing.
OpenEMR is vulnerable to a missing authentication flaw in its OAuth2 dynamic client registration, allowing unauthorized access to sensitive FHIR resources.
OpenEMR is susceptible to an authentication bypass vulnerability involving the OAuth2 password grant flow due to insufficient security controls.
The Net::SAML2 library fails to properly verify cryptographic signatures, allowing for potential identity assertion manipulation.
Grav CMS is vulnerable to arbitrary method invocation, which may lead to code injection via manipulated blueprints.
A heap-based buffer overflow in the MediaTek WLAN AP driver, caused by a missing bounds check, permits an attacker to potentially write out-of-bounds memory.
A command injection vulnerability in the GL.iNet GL-MT3000 router allows authenticated attackers to execute arbitrary system commands.
An improper privilege management vulnerability in the Razer RzUpdateService allows local authenticated users to escalate privileges.
Telenia Software TVox contains a privilege escalation vulnerability due to an insecure sudoers configuration that allows local users to execute commands with unnecessary privileges.
SiYuan note-taking software contains a path traversal vulnerability that allows authenticated users to access restricted directories via unvalidated input.
MediaTek chipsets contain a privilege escalation vulnerability in the Telephony component due to a missing permission check, allowing unauthorized operations.
An unauthenticated path traversal vulnerability exists in Rocket.Chat when CustomSounds storage is configured to FileSystem, allowing potential local file access.
A vulnerability in the socket.io library allows for improper input validation, which can lead to a denial of service condition.
The brace-expansion library is susceptible to uncontrolled resource consumption, allowing attackers to trigger excessive resource usage through specifically crafted input.
XML::Sig fails to properly verify cryptographic signatures, allowing for potential signature bypass.
Net::SAML2 fails to properly validate cryptographic signatures and certificates, which may allow for the bypass of security assertions.
Grav CMS is vulnerable to path traversal, which may allow an unauthenticated attacker to access restricted files on the server.
Admidio prior to version 5.0.11 contains a missing authentication vulnerability that allows unauthenticated attackers to access critical functions.
The OpenWrt luci-app-bmx7 package is vulnerable to path traversal via the bmx7-info CGI script, allowing unauthenticated attackers to read arbitrary files.
A missing bounds check in the MediaTek modem firmware leads to an out-of-bounds read, potentially causing system instability or information disclosure.
Data::SpatialHash::Shared versions before 0.
Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.
A norm.
Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.
An issue in DayuanJiang next-ai-draw-io 0.
An issue in exo-explore exo 1.
An issue in NCH Software ExpressZip v11.