CVE-2026-18577
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
Critical vulnerabilities, curated daily for security professionals
Google Chrome accounts for three of the day's critical entries (CVE-2026-17676, CVE-2026-17681 and CVE-2026-17666, all CVSS 9.1 to 9.6), alongside a cluster of unauthenticated WordPress plugin flaws and server-side deserialization in Apache Fory. The set totals 73 CVEs: 11 rated critical, down 45% from the prior day, and 62 rated high, up 94%. Notable critical items include CVE-2026-71558 (CVSS 9.8) in Apache Fory, CVE-2026-16258 (CVSS 9.8) in the WordPress Ajax Search Lite plugin, and CVE-2026-19264 (CVSS 9.8) in gitroomhq postiz-app. Six CVEs carry confirmed active exploitation, covering remote management and CI/CD infrastructure such as N-able N-central, Apache Tomcat, JetBrains TeamCity, IBM Langflow OSS and Progress LoadMaster. No vendor patch was recorded for any entry at collection time, so teams should prioritize compensating controls and exposure reduction while tracking vendor advisories for updates.
Immediate action: Prioritize the actively exploited stack first: N-able N-central, Apache Tomcat, JetBrains TeamCity, IBM Langflow OSS and Progress LoadMaster, all of which are typically internet-reachable management or build systems. Follow with Chrome browser updates across endpoints and an audit of the affected WordPress plugins (Ajax Search Lite, WP Events Manager, AI Copilot Content Generator), which are unauthenticated and remotely reachable. No vendor patches were recorded for this set at collection time, so restrict external access, apply WAF or network controls where possible, and monitor vendor advisories for fixed releases.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
N-able N-central is affected by an authentication bypass vulnerability using an alternate path or channel, potentially allowing unauthorized access.
Apache Tomcat contains a vulnerability involving missing encryption of sensitive data, which is currently being actively exploited in the wild.
A critical code injection vulnerability in IBM Langflow OSS allows unauthenticated attackers to gain superuser privileges and execute arbitrary code on the host system.
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
The Ajax Search Lite WordPress plugin is vulnerable to PHP object injection due to improper deserialization of untrusted input, which can lead to remote code execution.
A path traversal vulnerability in the Postiz social media scheduling tool allows unauthenticated remote attackers to read sensitive files and compromise system secrets.
An inappropriate implementation in the ANGLE graphics library allows a sandbox escape in Google Chrome on Android.
A sandbox escape vulnerability exists in Google Chrome on Android due to insufficient input validation in Web Authentication, potentially allowing a remote attacker to compromise the renderer process.
A heap type confusion vulnerability in Apache Fory C++ allows remote attackers to trigger denial of service or arbitrary code execution via crafted payloads during polymorphic smart-pointer deserialization.
A cryptographic flaw in the enterprise component of Google Chrome allows unauthorized access control bypass via malicious network traffic.
An authorization bypass in the AI Copilot WordPress plugin allows unauthenticated attackers to create administrator accounts and achieve full site takeover.
The WP Events Manager WordPress plugin contains a vulnerability that allows authenticated users to bypass payment requirements when registering for paid events.
Weaver E-cology 9.0 contains a file upload vulnerability allowing remote, unauthenticated attackers to execute arbitrary code via malicious JSP files.
LightRAG versions through 1.5.4 expose an unauthenticated API server, allowing remote attackers to manipulate knowledge graphs, access documents, and consume LLM resources.
Plesk before 18.0.80.1 contains an improper privilege management vulnerability in its XML-RPC API that allows resellers to escalate to administrative root access.
A use after free vulnerability in the HTML component of Google Chrome allows for potential arbitrary code execution.
A use after free vulnerability in the Resources component of Google Chrome on Android allows for potential arbitrary code execution.
A use after free vulnerability in the Aura component of Google Chrome on Linux allows for potential arbitrary code execution.
WordPress contains a reflected cross-site scripting vulnerability on the login screen that allows unauthenticated attackers to execute malicious scripts in the context of a user session.
The PraisonAI platform is susceptible to authorization bypass and missing authorization checks, allowing authenticated users to perform unauthorized actions.
The Subscriptions for WooCommerce WordPress plugin is vulnerable to improper privilege management, potentially allowing authenticated users to perform unauthorized actions.
A sandbox escape vulnerability in Google Chrome on Android caused by insufficient input validation in the GPU subsystem.
A resource leak vulnerability in Bouncy Castle for Java FIPS (BC-FJA) allows for potential denial of service due to failure to release resources after their effective lifetime.
An infinite loop vulnerability in Bouncy Castle for Java FIPS (BC-FJA) exists, which can be triggered by unauthenticated attackers to cause denial of service.
Google Chrome on Android contains an input validation vulnerability in WebAPKs that may allow for unintended execution or data handling.
Google Chrome on Linux is vulnerable to an out of bounds write in the GPU process, which could allow remote attackers to execute arbitrary code.
An insufficient policy enforcement vulnerability in Google Chrome navigation allows for potential security bypasses.
An out of bounds write vulnerability exists in the Skia graphics library within Google Chrome, potentially allowing for memory corruption.
Insufficient validation of untrusted input in Google Chrome Workers allows for potential security risks during background processing.
The MStore API WordPress plugin contains an improper authentication vulnerability that may allow unauthenticated attackers to bypass security controls.
The WP Maps WordPress plugin is vulnerable to path traversal, allowing authenticated users with low privileges to access sensitive files on the server.
The Creative Mail WordPress plugin contains an unauthenticated SQL injection vulnerability via an unsanitized parameter, allowing attackers to manipulate database queries.
The Content Views WordPress plugin contains a SQL injection vulnerability that allows authenticated users with low privileges to execute arbitrary SQL commands.
A use-after-free vulnerability exists in the Ruby JSON library, potentially allowing for memory corruption or arbitrary code execution by unauthenticated attackers.
Sonatype Nexus Repository 3 contains a type confusion vulnerability in the REST privileges API that allows authenticated users to perform unauthorized privilege escalation.
The DivvyPayHQ absinthe_federation library is vulnerable to resource exhaustion, allowing an unauthenticated remote attacker to crash the Erlang VM via crafted _entities representation keys.
Sonatype Nexus Repository 3 fails to restrict HikariCP connection-pool properties in the DataStore configuration API, allowing authenticated attackers to execute unauthorized code.
In the Linux kernel, the following vulnerability has been resolved: rust_binder: use a u64 stride when cleaning up the offsets array Allocation's Drop walks the offsets array (binder_size_t = u64 entries), cleaning up the objects, but it used usize instead of u64 for both the stride and the per-en.
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() Three IE/attribute parsing functions have missing bounds checks.
A missing authorization vulnerability in Sonatype Nexus Repository 3 allows authenticated users with privilege update permissions to escalate their access to full administrative rights.
Tobit TeamDavid Webbox contains a vulnerability where including the string (editini) in a file path triggers a function that can lead to an out-of-bounds read and potential service disruption.
Tobit TeamDavid Webbox uses hard-coded cryptographic keys, which could allow unauthorized parties to decrypt sensitive data or compromise communication security.
A cross-site scripting vulnerability in lakeFS allows authenticated users to execute arbitrary scripts via the web interface.
An improper authorization vulnerability in Pathling allows unauthenticated attackers to access sensitive clinical data.
Pathling contains multiple vulnerabilities, including SSRF and insufficient credential protection, allowing unauthenticated attackers to compromise systems.
Pathling versions prior to 2.0.0 are vulnerable to insufficiently protected credentials and server-side request forgery, allowing potential unauthorized access.
Pathling versions prior to 2.0.0 are susceptible to path traversal, which may allow an unauthenticated attacker to access or manipulate restricted files on the server.
Pathling versions prior to 2.0.0 are affected by path traversal and server-side request forgery, enabling unauthenticated attackers to potentially read files or perform unauthorized requests.
Sonatype Nexus Repository 3 fails to invalidate existing user sessions or cached permissions following account deletion, deactivation, or password changes.
The SP Page Builder extension for Joomla is vulnerable to improper access control and cross-site scripting, allowing unauthenticated attackers to potentially impact system integrity.
The Kakoune code editor contains an injection vulnerability due to improper neutralization of special elements in output used by a downstream component.
Pathling contains multiple vulnerabilities including input validation failures and server-side request forgery (SSRF) issues.
Element Call contains an information exposure vulnerability that allows an authenticated attacker to access sensitive data.
TeamDavid contains an absolute path traversal vulnerability in its archive creation functionality that could impact system integrity.
The Webbox application in TeamDavid is vulnerable to arbitrary file writes, allowing unauthenticated attackers to create or modify files on the server.
Tobit Laboratories AG TeamDavid Webbox contains a local file inclusion vulnerability in the email, fax, and SMS transmission functions.
Tobit Laboratories AG TeamDavid Webbox contains an arbitrary file deletion vulnerability within the email, fax, and SMS transmission functions.
Sonatype Nexus Repository 3 contains an incorrect authorization vulnerability that may allow authenticated users to perform unauthorized actions.
A use-after-free and race condition vulnerability in llama.cpp allows potential remote code execution via the llama server component.
A use-after-free and TOCTOU race condition in llama.cpp tokenization endpoints may allow for memory corruption and potential remote code execution.
A stored cross-site scripting (XSS) vulnerability in OpenReception appointment booking software allows an authenticated attacker to execute malicious scripts in the context of other users.
Contiki-NG is vulnerable to an out-of-bounds write in the MQTT client parse_publish_vhdr function, potentially leading to memory corruption.
Statamic CMS is vulnerable to authentication bypass and spoofing issues, allowing unauthorized access to restricted areas of the platform.
TimescaleDB is vulnerable to out-of-bounds read and improper array index validation, which may lead to information disclosure.
ZenML versions 0 through 0.94.6 contain a deserialization vulnerability that allows authenticated users with low privileges to execute arbitrary code via the cloudpicklematerializer component.
OpenReception's appointment booking software versions below 1.0.2 contain a vulnerability that permits high-privileged users to access sensitive information due to improper exposure.
NexTOR_IP_CHANGER versions before 2.0.0 contain vulnerabilities including OS command injection and NULL pointer dereference, allowing local users to execute arbitrary commands or cause crashes.
V-Secure Jingyun Antivirus version 2.4.2.39 is vulnerable to improper access controls and incorrect privilege assignment, allowing local attackers to achieve high impact.
StableBit DrivePool 2.3.13.1687 is susceptible to local privilege escalation due to permission issues and insecure deserialization flaws.
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay A response-bearing attempt can return a replayable error and free its response buffer.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation When a blocking byte-range lock request is deferred in the FILE_LOCK_DEFERRED path, ksmbd registers the asynchronous work into the connection's async_reque.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref l2cap_chan_timeout() runs asynchronously and accesses chan->conn.
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() The VF2PF interrupt handler queues PF-side response work that stores a raw pointer to per-VF state (struct adf_accel_vf_info).
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: hyper-v: Bound the bank index when querying sparse banks When checking if a VP ID is included in a sparse bank set, explicitly check that the ID can actually be contained in a sparse bank (the TLFS allows for a maximum o.
In the Linux kernel, the following vulnerability has been resolved: ALSA: virtio: Validate control metadata from the device virtio-snd control handling trusts the device-provided control type and value count returned by the device.
In the Linux kernel, the following vulnerability has been resolved: smb: client: restrict implied bcc[0] exemption to responses without data area smb2_check_message() has a long-standing quirk that accepts a response whose calculated length is one byte larger than the bytes actually received ("ser.
In the Linux kernel, the following vulnerability has been resolved: x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines With CONFIG_CALL_DEPTH_TRACKING enabled on an x86 retbleed-affected platform (eg: Skylake), with retbleed=stuff, registering a dynamic ftrace trampoline crashes.