CVE-2026-18577
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
Critical vulnerabilities, curated daily for security professionals
Enterprise middleware and network infrastructure carried the weight of yesterday's disclosures, with two Apache CXF flaws (CVE-2026-66909 and CVE-2026-57817, both CVSS 9.8) and CVE-2026-20272 (CVSS 9.8) in Cisco IOS XE Software affecting widely deployed server and routing stacks. The day produced 63 critical CVEs (CVSS 9.0+), up 142% from the prior day's 26, alongside 83 high-priority issues, a 12% increase from 74. Also at the top of the critical set: CVE-2026-16940 (CVSS 10) in the Custom Fields WordPress plugin, CVE-2026-8709 (CVSS 9.9) in Progress Software MarkLogic Server, and CVE-2026-10090 (CVSS 9.9) in Red Hat Advanced Cluster Management for Kubernetes. Remote code execution and authentication bypass dominate the pattern, spanning industrial control software (thiagoralves OpenPLC_v3, CVE-2026-71268), IoT platforms, container orchestration, and the WordPress plugin ecosystem, with five CVEs showing confirmed active exploitation including N-able N-central, Apache Tomcat, IBM Langflow OSS, and JetBrains TeamCity. Patch data was unavailable for the disclosed set at collection time, so teams should verify fixed versions directly with vendors and prioritize internet-facing middleware, network devices, and management platforms.
Immediate action: Prioritize internet-facing Apache CXF services, Cisco IOS XE devices, and management platforms (N-able N-central, JetBrains TeamCity, MarkLogic Server) for immediate review, followed by Kubernetes management planes and WordPress installations running the affected plugins. Patch availability was recorded at 0% for this disclosure set, so check vendor advisories directly for fixed builds and apply documented mitigations or access restrictions where no update exists yet. The five actively exploited CVEs, including Apache Tomcat and IBM Langflow OSS, warrant compromise assessment on exposed instances rather than patching alone.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
N-able N-central is affected by an authentication bypass vulnerability using an alternate path or channel, potentially allowing unauthorized access.
Apache Tomcat contains a vulnerability involving missing encryption of sensitive data, which is currently being actively exploited in the wild.
A critical code injection vulnerability in IBM Langflow OSS allows unauthenticated attackers to gain superuser privileges and execute arbitrary code on the host system.
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
Apache CXF is vulnerable to remote code execution due to insecure native Java deserialization of inbound JMS ObjectMessages without type restrictions.
OpenPLC Runtime v3 contains a path traversal vulnerability in its compile_program function, allowing remote authenticated users to write arbitrary files to the filesystem.
The Custom Fields WordPress plugin before version 1.5.1 is vulnerable to path traversal, allowing unauthenticated attackers to delete arbitrary files on the server.
A CRLF injection vulnerability in boringproxy allows authenticated users to manipulate the SSH authorized_keys file, leading to persistent unauthorized access and credential theft.
Apache CXF fails to validate the c_hash parameter in OpenID Connect Hybrid Flow, allowing for Authorization Code Substitution or Injection attacks when integrated with certain Identity Providers.
Cisco IOS XE Software contains multiple injection vulnerabilities due to improper neutralization of special elements, addressed in recent software hardening releases.
The Spider Analyser WordPress plugin contains an unauthenticated Remote Code Execution vulnerability, allowing attackers to execute arbitrary code on the underlying server.
Progress MarkLogic Server contains an improper privilege management vulnerability in its REST API, allowing low-privileged users to perform unauthorized operations against the Security database.
The rust-iot-platform software lacks authentication on a calc rule creation endpoint, allowing unauthenticated attackers to execute arbitrary JavaScript code via unsanitized input.
A privilege escalation vulnerability in the Red Hat Advanced Cluster Management Application Subscription controller allows authenticated users to gain cluster-admin privileges.
The IOTSmartHome platform is vulnerable to SQL injection via the lastLogin cookie, allowing unauthenticated attackers to bypass authentication and extract sensitive database information.
PraisonAI versions prior to 4.6.40 contain a command injection vulnerability in its GitHub Actions workflow, allowing unauthenticated attackers to execute arbitrary shell code.
Progress Software MarkLogic Server contains an improper privilege management flaw in its Hadoop integration, enabling authenticated users to escalate privileges and compromise the Security database.
The Ajax Search Lite plugin for WordPress is susceptible to unauthenticated PHP object injection, which can lead to remote code execution or unauthorized data manipulation.
OpenChamber contains an unauthenticated remote code execution flaw in the /api/fs/exec endpoint, allowing attackers to execute arbitrary shell commands on the host system.
The Export User Data WordPress plugin is vulnerable to PHP object injection, which allows unauthenticated attackers to execute arbitrary code or manipulate data via deserialization of untrusted input.
The WPBruiser {no- Captcha anti-Spam} WordPress plugin is vulnerable to unauthenticated PHP object injection, enabling attackers to execute arbitrary code via the deserialization of untrusted data.
The 69 Clothing WordPress theme is affected by an unauthenticated PHP object injection vulnerability, which enables attackers to execute arbitrary code through the deserialization of untrusted input.
The Axiomthemes A.Williams WordPress theme is vulnerable to unauthenticated PHP object injection, which may allow remote code execution.
The ThemeREX Abelle WordPress theme is susceptible to unauthenticated PHP object injection, potentially enabling remote code execution.
The AncoraThemes Abogado WordPress theme contains an unauthenticated PHP object injection vulnerability, which could lead to remote code execution.
The AncoraThemes Accalia WordPress theme is vulnerable to unauthenticated PHP Object Injection, allowing remote code execution via deserialization of untrusted user input.
The AncoraThemes Adrena WordPress theme is susceptible to unauthenticated PHP Object Injection, enabling remote attackers to execute arbitrary code by manipulating serialized data.
The AncoraThemes Advice WordPress theme contains an unauthenticated PHP Object Injection flaw that could allow remote attackers to execute arbitrary code.
An unauthenticated PHP Object Injection vulnerability exists in AncoraThemes Agora versions 1.9 and earlier, allowing for potential remote code execution.
An unauthenticated PHP Object Injection vulnerability exists in the axiomthemes Agricola theme, specifically affecting versions 1.21.0 and earlier.
A critical PHP Object Injection vulnerability exists in the Axiomthemes AI ANN theme, allowing unauthenticated attackers to potentially execute arbitrary code.
The WSO2 JWT authentication mechanism incorrectly validates tokens using unsupported algorithms, potentially allowing unauthenticated attackers to bypass security controls and gain unauthorized access.
The My Safetipin Android application version 5.2.1 contains hardcoded credentials and predictable OTP values, allowing for unauthorized account access.
An OS command injection vulnerability exists in the Dell Virtual Storage Integrator for VMware vSphere Client, allowing unauthenticated remote attackers to execute arbitrary code as root.
The NASA-AMMOS ANMS reference implementation exposes its REST API directly to the network without authentication, allowing remote attackers to send unauthorized commands to DTNMA agents.
Multiple Zbtlink router models contain an embedded remote control implant that enables unauthenticated remote code execution with root privileges via a cleartext command channel.
An out-of-bounds write vulnerability in Apple macOS allows an application to cause unexpected system termination due to insufficient bounds checking.
An out-of-bounds read vulnerability in Apple macOS, addressed via improved bounds checking, allows an application to cause unexpected system termination.
An integer overflow vulnerability exists in Apple macOS that may allow a malicious application to cause unexpected system termination.
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153.
Cisco Catalyst SD-WAN components are vulnerable to improper input validation, which could allow an authenticated attacker to compromise the system.
Cisco Catalyst SD-WAN components are vulnerable to improper access control, which could allow an authenticated attacker to gain unauthorized privileges.
Apache CXF contains a flaw in the removeCodeGrant functionality, allowing an authorization code to be redeemed multiple times in violation of RFC specifications.
A critical remote code execution vulnerability exists in the Betheme WordPress theme, allowing authenticated contributors to execute arbitrary code on the underlying server.
Progress MarkLogic Server contains an authentication bypass vulnerability in the ODBC App Server, allowing unauthenticated attackers to execute queries with administrative privileges.
IoTSharp fails to enforce authorization on its BlobStorageController, allowing unauthenticated remote attackers to perform arbitrary file operations via path traversal.
An out-of-bounds write vulnerability in nanoMODBUS allows unauthenticated attackers to corrupt memory and potentially achieve remote code execution via a malformed Modbus request.
WSO2 API Manager suffers from improper privilege management where low-privileged tokens can access administrative REST APIs, potentially leading to full account takeover.
The Kadence WooCommerce Email Designer plugin for WordPress contains a missing authorization vulnerability that allows unauthenticated attackers to escalate privileges.
The AIWU plugin for WordPress is susceptible to an unauthenticated privilege escalation vulnerability due to incorrect privilege assignment.
The Frontend Admin by DynamiApps plugin for WordPress contains an unauthenticated privilege escalation vulnerability caused by incorrect privilege assignment.
An SQL injection vulnerability exists in Loca Software Informatics Technology Ltd. CMS, allowing unauthenticated attackers to execute arbitrary SQL commands.
A stack buffer overflow exists in rxi microtar due to improper boundary checks when copying filenames into the header structure.
An unauthenticated arbitrary file upload vulnerability exists in the Brandexponents Type Hub plugin for WordPress, allowing remote code execution.
Progress MarkLogic Server contains an improper privilege management vulnerability in its query interfaces allowing authenticated users with low-privileged roles to escalate to administrator.
nanoMODBUS contains an out-of-bounds stack read and wild-pointer write vulnerability in its Modbus identification response handling, which can be triggered by a malicious server.
A heap-based buffer overflow in lib60870-C 2.4.0 allows unauthenticated attackers to potentially achieve arbitrary code execution.
In the Linux kernel, the following vulnerability has been resolved: block: recompute nr_integrity_segments in blk_insert_cloned_request blk_insert_cloned_request() already recomputes nr_phys_segments against the bottom queue, because "the queue settings related to segment counting may differ from
In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived file reference at submit handshake_nl_accept_doit() needs the file pointer backing req->hr_sk->sk_socket to survive the window between handshake_req_next() and the subsequent FD_PREPARE() and get_f
In the Linux kernel, the following vulnerability has been resolved: spi: fsl-lpspi: terminate the RX channel on TX prepare failure path When dmaengine_prep_slave_sg() fails for the TX channel, the error path terminates the TX DMA channel but leaves the RX channel running. Since the RX channel was
In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination. For native XDP, that clone path copies only the linear xdp_frame data, while fragmented frames keep skb_shared_
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails before the next send, cleanup retains the previous buffer type an
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_info_init() fails before the next send, cleanup retains the previous buffer type
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_directory_init() fails before the next send, cleanup retains the previous buf
In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore call VFS xattr helpers which recheck inode permissions and LSM policy using the c
In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests using the same file handle can overwrite
Open Library Foundation VuFind v11.0.3 and v4.1 suffer from an incorrect access control vulnerability where requests continue processing despite failed authorization checks.
A vulnerability in the BEEP feature of Cisco IOS XE Software allows an unauthenticated remote attacker to trigger a denial of service condition on affected devices.
A vulnerability in the Extensible Messaging Client Protocol of Cisco IOS and IOS XE Software allows an unauthenticated remote attacker to cause a denial of service on an affected device.
An internal security review identified a memory buffer vulnerability in Cisco IOS XE Software that could allow an unauthenticated remote attacker to cause a denial of service on an affected device.
A resource management vulnerability in Cisco IOS XE Software identified during an internal review could allow an unauthenticated remote attacker to cause a denial of service on an affected device.
A vulnerability in Cisco IOS XE Software involves an incorrect calculation flaw, potentially leading to a denial of service condition.
A vulnerability in Cisco IOS XE Software involving insufficient control flow management may allow an unauthenticated attacker to trigger a denial of service.
A vulnerability in Cisco IOS XE Software stemming from improper input validation may allow an unauthenticated attacker to cause a denial of service.
Bolt CMS is vulnerable to a security flaw where content field values are rendered through the Twig environment without a SandboxExtension, potentially allowing unauthorized code execution.
An origin validation error in livebook allows untrusted notebook output to execute session-wide keyboard shortcuts, enabling unauthorized cell evaluation or runtime restarts.
A Server-Side Request Forgery vulnerability in the DownloadBookmark function of go-shiori allows authenticated attackers to perform unauthorized requests.
A vulnerability in Thermo Fisher Applied Biosystems software allows potential unauthorized modification of data files due to a lack of digital signature verification.
The Checkimate WooCommerce plugin for WordPress is vulnerable to improper access control, allowing unauthenticated attackers to potentially perform unauthorized actions.
A command injection vulnerability in the Cisco IMC management interface allows authenticated, low-privilege users to execute arbitrary commands and escalate to root privileges.
The WPMU DEV Dashboard plugin for WordPress contains an authentication bypass vulnerability that allows unauthenticated attackers to gain unauthorized access to the application.
An access control vulnerability in Apple macOS allows an application to potentially access sensitive user data due to insufficient restrictions.
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient authorization checks in the connector function.
The Newsletters WordPress plugin is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation, allowing unauthenticated attackers to perform unauthorized requests.
The SirenGPS Android Application 2.19.44 contains an access control vulnerability that allows authenticated users to access data belonging to other users.
A security vulnerability in the Jenkins Multijob Plugin allows for unauthorized actions or information disclosure, affecting versions up to 669.v9d96a_d9c71b_0.
A cross-site request forgery (CSRF) vulnerability in the Jenkins Multijob Plugin allows attackers to perform unauthorized actions on behalf of authenticated users.
A vulnerability in Cisco Catalyst SD-WAN components allows for the cleartext storage of sensitive information, potentially exposing credentials or configuration data to unauthorized access.
An improper access control vulnerability in SecureAge CatchPulse allows local, non-administrative attackers to bypass security policy enforcement via an unrestricted kernel filter communication port.
A NULL pointer dereference vulnerability in the H5Pget_fill_value function of HDF5, prior to version 2.3.1, can lead to application crashes or potential denial of service conditions.
A race condition in Apache CXF's JCacheCodeDataProvider allows for the repeated redemption of authorization codes, resulting in the issuance of multiple valid access tokens.
Jenkins is vulnerable to an improper handling of case-insensitivity in user and group names, which could allow unauthorized impersonation.
An authorization bypass vulnerability exists in multiple API endpoints of Scripta eScriptorium, allowing authenticated users to perform unauthorized operations on data records.
A server-side request forgery vulnerability exists in the Stirling-PDF ConvertWebsiteToPDF endpoint, allowing unauthenticated attackers to potentially access internal resources.
A server-side request forgery vulnerability in the Foxit PDF Services API allows authenticated users to manipulate external file references during PDF creation.
A Server-Side Request Forgery (SSRF) vulnerability exists in the IBM Application Gateway Operator, allowing an authenticated attacker to perform unauthorized requests.
An inefficient regular expression complexity vulnerability in the CSS scrubber of html_sanitize_ex allows unauthenticated remote attackers to trigger CPU exhaustion via crafted CSS declarations.
An inefficient algorithmic complexity vulnerability in the traversal engine of html_sanitize_ex allows unauthenticated remote attackers to trigger CPU and memory exhaustion via flat sibling elements.
An improper privilege management vulnerability in the REST API document processing pipeline of MarkLogic Server allows authenticated users to escalate privileges.
The WPMU DEV Forminator plugin for WordPress contains an incorrect privilege assignment vulnerability, allowing authenticated contributors to escalate their privileges.
The Constant Contact Creative Mail plugin for WordPress is susceptible to SQL injection, allowing authenticated subscribers to execute unauthorized database queries.
The WP Job Portal plugin for WordPress contains an SQL injection vulnerability that allows authenticated subscribers to execute arbitrary database queries.
A broken authentication vulnerability in the Super Socializer plugin allows unauthenticated attackers to bypass security controls via an alternate path or channel.
A path traversal vulnerability in GitHub Enterprise Server allows unauthenticated attackers to delete arbitrary files and directories on the host instance.
IBM Langflow OSS is affected by a code injection vulnerability, allowing an authenticated attacker to execute arbitrary code within the application environment.
A code injection vulnerability in IBM Langflow OSS allows an authenticated attacker to execute arbitrary code, potentially resulting in full system compromise.
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a vulnerability involving inadequate encryption strength, which could allow unauthorized access to sensitive information.
IBM Langflow OSS versions 1.0.0 through 1.10.3 are susceptible to a code injection vulnerability, which could allow an authenticated attacker to execute arbitrary code.
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain an OS command injection vulnerability, allowing an authenticated attacker to execute arbitrary commands on the host system.
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain an incorrect privilege assignment vulnerability that allows authenticated users to gain elevated access.
A type confusion flaw in the Dynamic Client Registration security policy management of the Red Hat build of Keycloak allows authenticated users to impact system security.
Mistral Vibe is vulnerable to arbitrary command execution due to the inclusion of functionality from an untrusted control sphere within its git-fsmonitor-hook.
The LoRA-GA and CorDA initialization modules in Hugging Face peft are vulnerable to deserialization of untrusted data, which may lead to arbitrary code execution.
The sanitize_sql_column function in Cacti is vulnerable to SQL injection, potentially allowing an authenticated attacker to manipulate database queries.
Koha's guided report builder contains a SQL injection vulnerability that allows authenticated users to execute arbitrary database commands.
Eclipse Theia is affected by multiple vulnerabilities including cross-site request forgery and path traversal, potentially leading to unauthorized access.
The Magistrala Rules Engine allows authenticated users to execute arbitrary Go or Lua scripts server-side, leading to code injection.
The backmeup npm package is vulnerable to OS command injection due to insecure concatenation of input parameters when constructing shell commands.
HashBrown CMS is susceptible to OS command injection, allowing authenticated attackers to execute unauthorized commands via improper handling of system inputs.
HashBrown CMS contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary system commands.
OMICRON StationGuard is vulnerable to a timing discrepancy attack, which could allow an unauthenticated remote attacker to gain unauthorized access or influence system operations.
InvoiceNinja v5.0.0 is susceptible to Stored Cross-site Scripting (XSS) due to the unsafe rendering of the terms field in the client portal via the Laravel Blade raw output directive.
A path traversal vulnerability in rclone versions 1.40.0 through 1.74.9 allows authenticated users to read or write files outside of the intended directory via malicious path manipulation.
The get_resource tool in AWS aws-transform-mcp-server versions 0.1.0 through 0.1.4 is vulnerable to path traversal, allowing unauthorized file access.
ESPHome through 2026.7.0 contains a vulnerability related to incomplete validation of data, which may allow for significant system impact.
A buffer overflow vulnerability exists in nanoMODBUS versions up to 1.23.0, potentially allowing for arbitrary code execution or denial of service.
A Server-Side Request Forgery (SSRF) vulnerability in the METS and IIIF import URI handling of Scripta eScriptorium allows authenticated attackers to perform unauthorized requests.
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a code injection vulnerability that can be exploited by authenticated users to execute arbitrary code.
IBM Langflow OSS is vulnerable to improper control of code generation, which may allow an authenticated attacker to perform code injection attacks.
IBM Langflow OSS contains a security flaw involving reliance on untrusted inputs for security decisions, which may allow an authenticated attacker to bypass intended security controls.
A server-side request forgery vulnerability exists in Progress MarkLogic Server that may allow an authenticated user to perform unauthorized requests.
A server-side request forgery vulnerability exists in the Memos webhook URL validation logic, specifically within the isReservedIP function.
A race condition vulnerability exists in the Memos webhook dispatch function within the safeDialContext implementation.
A cross-site scripting vulnerability exists in the CHANNEL_SetLabel() function of OpenBK7231T_App, which may allow for unauthorized script execution.
A timing discrepancy vulnerability in OMICRON StationScout versions prior to 3.05 may allow for unauthorized information disclosure or system manipulation.
An authentication bypass vulnerability in the @neo4j/graphql library allows attackers to manipulate assumed-immutable data.
The Total Upkeep plugin for WordPress contains a broken access control vulnerability that allows unauthenticated attackers to perform unauthorized actions.
Nuxt contains vulnerabilities related to improper handling of case sensitivity and incorrect authorization, which may lead to unauthorized access or information disclosure.
IBM QRadar is susceptible to XML External Entity (XXE) injection, which may allow an unauthenticated attacker to read arbitrary files from the server.
The WLED project contains a broken access control vulnerability in the GET /json/cfg endpoint that allows unauthenticated modification of configuration settings.
Crater fails to verify company ownership when accessing notes, allowing authenticated users to bypass authorization checks and view or manage notes belonging to other companies.
The toner-management application contains missing authorization checks in its administrative state-changing handlers, allowing unauthorized users to modify system states.
The Login with phone number WordPress plugin contains an authentication bypass vulnerability, allowing unauthenticated attackers to spoof identity and gain unauthorized access.
An unauthenticated Local File Inclusion vulnerability in the E2Pdf WordPress plugin allows attackers to include arbitrary files on the server.
Nuxt is susceptible to code and output injection due to improper neutralization of special elements, potentially allowing unauthorized code execution.
The KARR Security System and SWDS automotive anti-theft systems use shared Bluetooth authentication keys, allowing unauthorized access to vehicle security functions.
Spacebar Server contains a missing authorization vulnerability that allows authenticated attackers to join arbitrary group direct message channels without verification.
IBM Langflow OSS is vulnerable to code injection, allowing an authenticated user to execute arbitrary code via improper control of code generation.
IBM WebSphere Application Server is vulnerable to unsafe reflection, allowing remote, unauthenticated attackers to potentially influence application behavior.
Flarum Framework contains a vulnerability involving the use of expired keys, which allows attackers to bypass password reset token expiration mechanisms.