CVE-2026-18556
N-able N-central is affected by an authentication bypass vulnerability using an alternate path or channel, potentially allowing unauthorized access.
Critical vulnerabilities, curated daily for security professionals
Vulnerabilities disclosed yesterday center on enterprise management and application infrastructure, with N-able N-central, Apache Tomcat, JetBrains TeamCity, IBM Langflow OSS, and Progress LoadMaster all carrying CVSS 9.5 issues under confirmed exploitation. Volume dropped sharply against the prior day: 2 critical CVEs (down 93% from 27) and 38 high-priority CVEs (down 31% from 55), for 40 total. The two critical entries are CVE-2026-19348 (CVSS 9.8) in the Shenzhen Aitemi M300 Wi-Fi Repeater and CVE-2026-15360 (CVSS 9.1) in the Ajax Load More WordPress plugin. Remote code execution and authentication bypass against internet-reachable management planes, CI/CD servers, and web application stacks dominate the set, with consumer networking gear and WordPress extensions adding externally exposed attack surface. No patch data is currently confirmed for any of the 40 CVEs (0% availability), so verify fix status directly with each vendor and apply compensating controls where updates are not yet published.
Immediate action: Prioritize internet-facing N-able N-central, Progress LoadMaster, JetBrains TeamCity, Apache Tomcat, and IBM Langflow OSS deployments, since these carry CVSS 9.5 flaws with active exploitation and typically sit at the network edge or inside build pipelines. Patch availability is unconfirmed for all 40 CVEs, so check each vendor advisory for released updates and, where none exist, restrict management interface exposure, enforce network segmentation, and monitor authentication logs for anomalies. WordPress sites running Ajax Load More and networks using Shenzhen Aitemi M300 repeaters should be inventoried and isolated from sensitive segments until fixes ship.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
N-able N-central is affected by an authentication bypass vulnerability using an alternate path or channel, potentially allowing unauthorized access.
Apache Tomcat contains a vulnerability involving missing encryption of sensitive data, which is currently being actively exploited in the wild.
A critical code injection vulnerability in IBM Langflow OSS allows unauthenticated attackers to gain superuser privileges and execute arbitrary code on the host system.
An unauthenticated remote code execution vulnerability exists in the JetBrains TeamCity agent polling protocol.
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
The Ajax Load More WordPress plugin before 8.0.1 contains a SQL injection vulnerability allowing unauthenticated attackers to extract sensitive database information.
A command injection vulnerability in the Shenzhen Aitemi M300 Wi-Fi Repeater allows remote attackers to execute arbitrary commands via the /protocol.csp interface.
A vulnerability in LINE for Windows allows for local privilege escalation or arbitrary code execution by leveraging improper file path handling during the installation process.
The miniOrange 2FA WordPress plugin fails to bind second factors correctly during pre-login challenges, allowing attackers who know a user password to rebind the second factor to their own device.
The Passster WordPress plugin before 4.3.6 fails to enforce category-based content protection on the WordPress REST API, allowing unauthorized access to restricted posts.
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count rmi_f30_map_gpios() allocates gpioled_key_map with min(gpioled_count, TRACKSTICK_RANGE_END) == at most 6 entries, but rmi_f30_attention() iterates the full f30->gp.
The WP 2FA WordPress plugin before 4.1.0 allows attackers who know a user password to bypass two-factor authentication, granting them full account access.
The Contest Gallery WordPress plugin bypasses standard authentication flows, failing to trigger brute-force protection or two-factor authentication for front-end logins.
The Sunshine Photo Cart WordPress plugin contains a missing access control vulnerability in an AJAX action, allowing unauthorized access to restricted image comments.
The Bit Form WordPress plugin before 3.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization of uploaded signature images.
The Passster WordPress plugin before 4.3.6 allows unauthenticated users to disclose private post content via a vulnerable REST API endpoint.
The Passster WordPress plugin fails to verify passwords before outputting protected content, allowing unauthenticated users to access restricted information.
A debugging web server remains enabled in certain ECOVACS DEEBOT models, potentially allowing unauthorized access to sensitive device information.
A stack-based buffer overflow in the libril_sem component of Samsung mobile devices allows privileged local attackers to execute arbitrary code.
A Server-Side Request Forgery vulnerability exists in adafap api-mcp, which could allow an unauthenticated attacker to manipulate internal requests.
Telnet servers are left enabled in DEEBOT PRO M1 and K1VAC devices, exposing them to potential unauthorized access by authenticated users.
A command injection vulnerability in Tenda CH22 allows authenticated attackers to execute arbitrary system commands via the formCertListInfo function.
A permissive regular expression in Nishishi Tegalog allows unauthenticated attackers to bypass authentication and gain unauthorized access to the management console.
ECOVACS DEEBOT PRO M1 and K1VAC devices contain an authentication vulnerability in WebSocket communications due to the use of weak cryptographic algorithms.
Kingston FURY CTRL RGB Control Software version 2.0.65.0 contains an improper privilege management vulnerability that could allow local attackers to escalate privileges.
A heap out-of-bounds write vulnerability in the GStreamer gst-plugins-bad adpcmdec element allows attackers to trigger crashes or potentially execute code via maliciously crafted audio files.
SourceCodester Simple Doctors Appointment System version 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries.
The EFM ipTIME AX8004M router is vulnerable to OS command injection, allowing unauthenticated remote attackers to execute arbitrary system commands.
Uasoft Badaso version 3.0.0-alpha is affected by a permission and privilege assignment vulnerability, enabling unauthenticated remote attackers to bypass security controls.
MingSoft MCMS versions 3.0.0 through 3.0.6 are vulnerable to SQL injection, allowing unauthenticated remote attackers to execute arbitrary database queries.
A SQL injection vulnerability exists in the dresende node-sql-query package, allowing unauthenticated attackers to execute arbitrary SQL commands.
A SQL injection vulnerability in code-projects Task Management System version 1.0 allows unauthenticated attackers to execute arbitrary SQL commands via unsanitized input.
In the Linux kernel, the following vulnerability has been resolved: HID: hid-goodix-spi: validate report size to prevent stack buffer overflow goodix_hid_set_raw_report() builds a protocol frame in a 128-byte stack buffer (tmp_buf), writing an 11-12 byte header followed by the caller-supplied repo.
A local privilege escalation vulnerability due to incorrect default permissions in Samsung Bixby allows an authenticated user to gain elevated privileges.
Multiple integer overflow and underflow vulnerabilities in the GStreamer gst-plugins-ugly ASF demuxer allow for potential denial of service via specially crafted media files.
An improper access control vulnerability in the Weaver component of Samsung mobile devices allows local attackers to cause device inoperability.
Samsung Smart Switch versions prior to 3.7.72.6 suffer from a lack of encryption for sensitive data, potentially exposing user information during synchronization.
In the Linux kernel, the following vulnerability has been resolved: exfat: bound uniname advance in exfat_find_dir_entry() In exfat_find_dir_entry(), each TYPE_EXTEND (file name) entry advances the output pointer by a fixed amount while the loop guard only tracks the accumulated name length: if.
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - validate RSA CRT component lengths The generic RSA key parser (rsa_helper.
In the Linux kernel, the following vulnerability has been resolved: crypto: loongson - Remove broken and unused loongson-rng The loongson-rng rng_alg has several vulnerabilities, including not providing forward security, and a use-after-free bug due to the use of wait_for_completion_interruptible(.
In the Linux kernel, the following vulnerability has been resolved: udf: validate sparing table length as an entry count, not a byte count udf_load_sparable_map() accepts a sparing table when sizeof(*st) + le16_to_cpu(st->reallocationTableLen) > sb->s_blocksize is false, i.
In the Linux kernel, the following vulnerability has been resolved: udf: validate free block extents against the partition length udf_free_blocks() checks the logical block number and count against the partition length, but drops the extent offset from that final bound.
In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix write buffer corruption The digi_write_inb_command() is supposed to wait for the write urb to become available or return an error, but instead it updates the transfer buffer and tries to resubmit.
In the Linux kernel, the following vulnerability has been resolved: bpf: Validate BTF repeated field counts before expansion btf_parse_struct_metas() walks user-supplied BTF during BPF_BTF_LOAD, and btf_repeat_fields() expands repeatable fields from array elements into the fixed BTF_FIELDS_MAX scr.
In the Linux kernel, the following vulnerability has been resolved: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation pcc_cpufreq_do_osc() calls acpi_evaluate_object() twice for the two-phase _OSC negotiation.