CVE-2026-8037
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
Critical vulnerabilities, curated daily for security professionals
Adobe and Microsoft account for the bulk of yesterday's high-impact disclosures, with maximum-severity flaws in Adobe Campaign Classic and ColdFusion 2025 alongside a cluster of CVSS 9.8 issues across Windows and Windows Server. The day produced 24 critical vulnerabilities (down 54% from 52) and 88 high-priority vulnerabilities (down 12% from 100). CVE-2026-27302 and CVE-2026-71398 in Adobe Campaign Classic and CVE-2026-48362 in Adobe ColdFusion 2025 all carry CVSS 10, while CVE-2026-62815, CVE-2026-62893, and CVE-2026-65791 affect Microsoft Windows at CVSS 9.8. Open-source web platforms are also represented through CVE-2026-46670 in YesWiki and CVE-2026-73211 in PeerTube, both scored 9.8. Four vulnerabilities have confirmed active exploitation, including CVE-2026-20349 in Cisco Secure Firewall ASA and FTD and CVE-2026-72898 in Metabase; patch data is not yet recorded for any of yesterday's entries, so treat vendor advisories as the authoritative source.
Immediate action: Prioritize internet-facing Adobe Campaign Classic and ColdFusion 2025 servers along with Microsoft Windows and Windows Server systems carrying the CVSS 9.8 remote code execution flaws. Address the actively exploited issues in Progress LoadMaster, Cisco Secure Firewall ASA and FTD, Metabase, and the Windows Ancillary Function Driver for WinSock in the same pass, since these are being used against live targets. No patch status is recorded for this set, so confirm fixed versions against each vendor's advisory and apply mitigations where updates are not yet published.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Progress LoadMaster and associated products are vulnerable to command injection, which allows unauthenticated attackers to execute arbitrary commands on the underlying system.
Cisco Secure Firewall ASA and FTD contain a heap inspection vulnerability due to improper memory clearing, which is currently being exploited in the wild.
Metabase contains a critical SQL injection vulnerability in the password reset endpoint that allows unauthenticated remote attackers to gain full administrative control over the instance.
A use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock is currently being exploited in the wild.
An unauthenticated SQL injection vulnerability in the YesWiki Bazar form-import path allows remote attackers to execute arbitrary SQL commands and extract sensitive database contents.
A deserialization vulnerability in the Microsoft High Performance Computing Pack allows unauthenticated remote attackers to execute arbitrary code on affected systems.
A stack-based buffer overflow in the Windows DNS service enables unauthenticated remote attackers to execute arbitrary code on vulnerable Windows systems.
An SQL injection vulnerability in the PeerTube ActorFollowModel allows unauthenticated remote servers to execute arbitrary database queries and take over administrator accounts.
A use after free vulnerability in Microsoft QUIC allows unauthenticated, remote attackers to execute arbitrary code.
A use after free vulnerability in Windows Deployment Services allows unauthenticated, remote attackers to execute arbitrary code.
A heap-based buffer overflow in the Windows iSCSI Target Service allows unauthenticated, remote attackers to execute arbitrary code.
Adobe Campaign Classic is vulnerable to an incorrect authorization flaw that allows unauthenticated remote attackers to execute arbitrary code without user interaction.
Adobe Campaign Classic contains an incorrect authorization vulnerability that permits unauthenticated remote attackers to achieve arbitrary code execution.
Adobe ColdFusion is susceptible to an OS command injection vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the underlying system.
Typebot.io versions prior to 3.17.0 contain an authorization bypass vulnerability allowing low-privilege users to perform cross-workspace OAuth credential takeover.
DB-GPT v0.8.1 is vulnerable to an unauthenticated path traversal attack that allows remote attackers to write arbitrary files to the server via the user_id HTTP header.
The Formidable Digital Signatures plugin for WordPress up to 3.0.6 contains a path traversal vulnerability that allows unauthenticated attackers to delete arbitrary files on the server.
A deserialization of untrusted data vulnerability in the SIMULIA Execution Engine allows unauthenticated remote code execution.
A buffer overflow vulnerability in the PROFINET service of Phoenix Contact controllers allows unauthenticated remote attackers to cause a device reboot or execute arbitrary code.
A missing authentication vulnerability in the Node-RED interface of Siemens SIMATIC IoT2050 Advanced devices allows unauthenticated remote attackers to execute arbitrary system commands.
The Mira cloud API login endpoint contains a critical authentication bypass vulnerability, allowing unauthenticated attackers to hijack user accounts and access sensitive health data.
An authentication bypass vulnerability in the ManageEngine DDI Central password reset workflow allows remote attackers to perform full account takeover.
LiquidJS versions prior to 10.26.0 are vulnerable to code injection, allowing unauthenticated attackers to execute arbitrary code via crafted templates.
Streambert versions prior to 2.5.0 contain an improper input validation flaw in the IPC handler, allowing a compromised renderer process to execute arbitrary local binaries.
SAP Commerce Cloud (Data Hub Adapter) is vulnerable to code injection, allowing unauthenticated attackers to execute arbitrary code by sending crafted input to certain functions.
An OS command injection vulnerability in wg-easy 15.3.0 allows authenticated users to execute arbitrary commands as root by injecting malicious directives into the client name field.
MaxKey contains a hard-coded JWT signing secret that allows unauthenticated attackers to forge valid tokens and gain full administrative access via the password-skipped login endpoint.
SeaweedFS prior to 4.24 fails to enforce authentication on the gRPC IdentityAccessManagement service when the signing key is unset, allowing unauthorized administrative control.
An execution with unnecessary privileges vulnerability exists in the Microsoft High Performance Computing (HPC) Pack, allowing an authenticated attacker to elevate privileges.
An out-of-bounds write vulnerability in the Windows DNS component allows an unauthenticated attacker to achieve remote code execution over an adjacent network.
A stack-based buffer overflow in the Windows Remote Desktop Client allows an unauthenticated attacker to execute code over a network via user interaction.
A stored cross-site scripting (XSS) vulnerability in GramSearch telegram-search allows remote attackers to execute arbitrary JavaScript by sending crafted messages containing unsanitized HTML.
A heap-based buffer overflow in the Microsoft Local Security Authority Server (lsasrv) allows an authenticated attacker to execute code over a network.
A heap-based buffer overflow in the Windows LDAP component allows unauthenticated attackers to achieve remote code execution via network-based vectors.
A heap-based buffer overflow in the Windows SMB Server allows an authenticated attacker to execute arbitrary code over a network.
A use-after-free vulnerability in the Windows LDAP component allows unauthenticated attackers to execute code via network-based vectors.
A heap-based buffer overflow in the Windows SMB Server allows an authenticated attacker to execute arbitrary code over a network.
A heap-based buffer overflow in the Reliable Multicast Transport Driver (RMCAST) allows an unauthenticated attacker to execute code over an adjacent network.
A use after free vulnerability in Active Directory Certificate Services (AD CS) allows an authenticated attacker to execute code over a network.
A heap-based buffer overflow in the Windows DHCP Server allows an unauthenticated attacker to achieve remote code execution via an adjacent network.
A heap-based buffer overflow in Microsoft Exchange Server allows an authenticated attacker to execute arbitrary code over a network.
A deserialization of untrusted data vulnerability in Microsoft SharePoint allows an authenticated attacker to execute code over a network.
An insecure deserialization vulnerability in Microsoft SharePoint allows an authenticated attacker to execute arbitrary code over the network.
An insecure deserialization vulnerability in Microsoft SharePoint allows an authenticated attacker to execute arbitrary code over the network.
An insecure deserialization vulnerability in Microsoft SharePoint allows an authenticated attacker to execute arbitrary code over the network.
A deserialization of untrusted data vulnerability in Microsoft SharePoint Server allows an authenticated attacker to execute arbitrary code over a network.
A deserialization of untrusted data flaw in Microsoft Dynamics 365 (on-premises) enables an authenticated attacker to execute arbitrary code over a network.
A deserialization of untrusted data vulnerability in Microsoft SharePoint Server allows an authenticated attacker to execute arbitrary code via a network request.
A deserialization of untrusted data vulnerability in Microsoft SharePoint allows an authenticated attacker to achieve remote code execution over a network.
A deserialization of untrusted data vulnerability in Microsoft SharePoint Server Subscription Edition allows an authenticated attacker to execute code over a network.
An SQL injection vulnerability in the Pimcore admin-ui-classic-bundle allows authenticated attackers to manipulate database queries through improper input sanitization.
An improper input validation vulnerability in Adobe ColdFusion allows an authenticated attacker to escalate privileges via a web-based attack.
A command injection vulnerability in Windows Active Directory allows unauthenticated attackers to execute arbitrary code over a network.
A cross-site scripting vulnerability in Microsoft Azure Storage Explorer allows an unauthenticated attacker to elevate privileges over a network.
A missing authorization vulnerability in Microsoft Visual Studio Code enables an unauthenticated attacker to execute arbitrary code over a network.
A heap-based buffer overflow and integer overflow in Windows GDI+ could allow an unauthenticated attacker to execute arbitrary code via a malicious file.
An improper authentication vulnerability in Microsoft SharePoint allows an authenticated attacker to elevate privileges over the network.
An incorrect authorization vulnerability exists in Microsoft .NET Framework, which may allow an authenticated user to perform unauthorized actions.
A missing authentication vulnerability in Microsoft SharePoint allows an authenticated attacker to elevate privileges over the network.
A cross-site scripting (XSS) vulnerability in Microsoft Teams for Android allows an authenticated attacker to perform spoofing attacks over a network.
A path traversal vulnerability in Microsoft Teams for Android allows an unauthenticated, remote attacker to execute arbitrary code.
A type confusion vulnerability in Microsoft Excel allows an unauthorized attacker to achieve remote code execution via a specially crafted file.
Improper input validation in Microsoft Power BI Report Server allows an authenticated attacker to execute arbitrary code over a network.
Visual Studio Code is vulnerable to OS command injection, allowing an unauthorized attacker to execute arbitrary code via specially crafted elements.
Microsoft SharePoint is susceptible to a server-side request forgery (SSRF) vulnerability that allows an authenticated attacker to elevate privileges over a network.
A server-side request forgery vulnerability in Microsoft SharePoint Server Subscription Edition allows an authenticated attacker to perform unauthorized actions and elevate privileges over a network.
An integer overflow vulnerability in Microsoft Outlook allows an unauthenticated attacker to achieve arbitrary code execution over a network via user interaction.
A code injection vulnerability in Visual Studio Code allows an unauthenticated attacker to execute arbitrary code over a network via malicious user interaction.
A relative path traversal vulnerability in Microsoft PowerShell Core allows an unauthenticated attacker to achieve remote code execution over a network.
A Cross-site Scripting (XSS) vulnerability in Adobe ColdFusion could allow an attacker to execute arbitrary code in the context of the current user.
An incorrect authorization vulnerability in Adobe ColdFusion could allow an attacker to execute arbitrary code in the context of the current user.
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that allows a low-privileged attacker to inject malicious scripts into vulnerable form fields.
SQL Injection vulnerability in aiflowy <= 2.
The Frontend Admin by DynamiApps plugin for WordPress contains an authorization bypass vulnerability, allowing authenticated users to perform unauthorized actions due to missing capability checks.
The AcyMailing plugin for WordPress is vulnerable to an authorization bypass flaw that allows low-privileged users to perform actions exceeding their intended permissions.
Information disclosure in the DOM: Security component.
MongoDB Server is affected by an algorithm downgrade vulnerability in intra-cluster communication that allows unauthorized influence over authentication mechanism selection.
A use after free vulnerability in the timeseries bucket lifecycle management of MongoDB Server allows authenticated users with write access to potentially corrupt memory and execute arbitrary code.
A command injection vulnerability in the electerm client allows attackers to execute arbitrary OS commands through improper neutralization of special elements.
A vulnerability in the electerm terminal client allows authenticated users to execute arbitrary code due to improper control of dynamically managed code resources.
Fusio contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary system commands on the underlying host.
ZoneMinder suffers from an OS command injection vulnerability that permits authenticated remote attackers to execute arbitrary commands on the host system.
The security-ninja-premium WordPress plugin before 5.
Rapid7 Velociraptor is vulnerable to an improper permission handling flaw within its multi-tenant Org deployment functionality, which may allow for unauthorized privilege escalation.
Portainer CE is affected by an authentication bypass vulnerability that allows an authenticated user to achieve unauthorized access to restricted functions.
Authentik Security authentik is vulnerable to an improper privilege management flaw, allowing authenticated users to escalate their permissions within the application.
A privilege escalation vulnerability in Authentik Security authentik allows authenticated users to gain unauthorized elevated access.
An SQL injection vulnerability in CiviCRM allows authenticated users to execute arbitrary database commands via improper input sanitization.
A protection mechanism failure in Intel Data Center Attestation Primitives (DCAP) may allow an unprivileged attacker to perform unauthorized information disclosure via network access.
A weak password recovery mechanism in n8n-io n8n allows authenticated attackers to potentially bypass authentication protocols via token exchange.
A missing authentication vulnerability in Quanovate Mira hormone monitor firmware allows adjacent attackers to compromise device integrity and availability.
An OS command injection vulnerability in FileRun allows authenticated users to execute arbitrary commands on the underlying host system via crafted thumbnail generation requests.
An unrestricted file upload vulnerability in the Malcolm network traffic analysis suite allows authenticated attackers to upload malicious files, potentially leading to remote code execution.
The claude-code-templates CLI tool is vulnerable to OS command injection, missing authentication, and cross-site request forgery, potentially allowing unauthorized command execution.
CamaleonCMS contains an authorization bypass vulnerability via user-controlled keys, allowing authenticated users to escalate privileges and access unauthorized functions.
A code injection vulnerability exists within the DBI component of Red Hat Enterprise Linux, potentially allowing authenticated users to inject and execute arbitrary code.
Craft CMS is affected by a Twig sandbox escape vulnerability, which allows an authenticated attacker to execute arbitrary code on the server.
Craft CMS is vulnerable to remote code execution due to improper control of dynamically determined object attributes during configuration processing.
A legacy endpoint in the Commvault Cloud Command Center is vulnerable to unauthenticated server-side request forgery (SSRF).
An unrestricted file upload vulnerability in Cockpit CMS 2 allows authenticated users to upload arbitrary files, including PHP scripts, leading to remote code execution.
A broken access control vulnerability in Peppermint allows authenticated non-administrative users to reconfigure global OIDC and SSO settings, enabling potential credential harvesting.
A deserialization vulnerability in Red Hat JBoss Enterprise Application Platform allows unauthorized remote code execution via untrusted data.
Flawfinder is vulnerable to an injection attack due to improper neutralization of special elements in output generated by the tool.
Activepieces is vulnerable to OS Command Injection, allowing authenticated users to execute arbitrary commands on the underlying operating system.
n8n is vulnerable to a sandbox escape that allows authenticated users to perform remote code execution.
n8n is vulnerable to OS command injection via the Git node, which allows authenticated users to execute arbitrary commands on the underlying host.
The cti-transmute tool by MISP is vulnerable to Server-Side Request Forgery (SSRF) in its /fetch_misp_event and /misp_search_events endpoints.
A missing permission check in the MediaTek Bluetooth driver allows local, low-privilege users to escalate privileges and access restricted interfaces without user interaction.
In the Linux kernel, the following vulnerability has been resolved: hwrng: virtio: clamp device-reported used.
In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - restore callback for non-parallel fallback pcrypt installs pcrypt_aead_done() on the child AEAD request before trying to submit it through padata.
In the Linux kernel, the following vulnerability has been resolved: netfilter: handle unreadable frags sashiko reports: When an skb with unreadable fragments (such as from devmem TCP, where skb_frags_readable(skb) returns false) is processed by the u32 module, skb_copy_bits() will safely return.
In the Linux kernel, the following vulnerability has been resolved: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC POSIX requires write permission to truncate a file, so an open() that specifies O_TRUNC must be authorized for write access regardless of the O_ACCMODE access mode.
In the Linux kernel, the following vulnerability has been resolved: smb: client: mask server-provided mode to 07777 in modefromsid When modefromsid is active, parse_dacl() applies the server-provided sub_auth[2] value from the NFS mode SID to cf_mode without masking to 07777.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate option length before reading conf opt value l2cap_get_conf_opt() derives the option length from the attacker-controlled opt->len field and immediately dereferences opt->val (as u8, get_unaligned_le16() o.
An incorrect access control vulnerability in NASA cFS v7.0.1 allows unauthenticated attackers to manipulate telemetry subscriptions and data streams via TO_LAB commands.
Directory traversal vulnerability in knowns-dev/knowns 0.