CVE-2026-20349
Cisco Secure Firewall ASA and FTD contain a heap inspection vulnerability due to improper memory clearing, which is currently being exploited in the wild.
Critical vulnerabilities, curated daily for security professionals
WordPress plugin and authentication components dominate the day's disclosures, with authentication bypass and remote code execution flaws in WPManageNinja Fluent Forms Pro, miniOrange Headless Single Sign On, and rtCamp Log in with Google, joined by infrastructure issues in Budibase Server and OpenWrt LuCI. The set disclosed yesterday includes 32 critical CVEs (up 3 percent from the prior day) and 80 high-priority CVEs (up 90 percent), a marked widening of the high-severity tier. CVE-2026-72851 in Budibase Server carries a CVSS of 10, CVE-2026-72841 in OpenWrt LuCI scores 9.9, and CVE-2026-73649 in the shepherdwind velocity.js library scores 9.8, giving attackers server-side execution paths in widely deployed management and templating components. Three vulnerabilities have confirmed active exploitation: Cisco Secure Firewall ASA and FTD (CVE-2026-20349), Metabase (CVE-2026-72898), and the Microsoft Windows Ancillary Function Driver for WinSock (CVE-2026-68820), spanning perimeter, analytics, and endpoint layers. Patch data is unavailable for the tracked set (0 percent confirmed), so teams should verify fix availability directly with vendors and prioritize internet-facing WordPress installs, Budibase instances, and edge network devices.
Immediate action: Prioritize Cisco Secure Firewall ASA and FTD, Metabase, and Windows systems for immediate patching given confirmed exploitation, then move to internet-facing WordPress sites running Fluent Forms Pro, Ninja Tables Pro, miniOrange SSO, or Wishlist Member, followed by Budibase Server and OpenWrt LuCI deployments. Fix availability is not confirmed for the tracked critical issues, so check vendor advisories directly and apply mitigations such as restricting administrative interfaces and disabling affected plugins where updates are not yet published.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Cisco Secure Firewall ASA and FTD contain a heap inspection vulnerability due to improper memory clearing, which is currently being exploited in the wild.
Metabase contains a critical SQL injection vulnerability in the password reset endpoint that allows unauthenticated remote attackers to gain full administrative control over the instance.
A use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock is currently being exploited in the wild.
A code injection vulnerability in velocity.js prior to 2.1.7 allows attackers to execute arbitrary shell commands via crafted templates.
WebErpMesv2 versions 1.19 and prior are vulnerable to unauthenticated remote code execution via arbitrary PHP file uploads in the HR Expense scan_file parameter.
Fluent Forms Pro version 6.2.7 contained a malicious backdoor injected via a tampered plugin build, allowing unauthorized administrative access and persistent system compromise.
Ninja Tables Pro version 5.2.11 contained a malicious backdoor injected via a tampered plugin build, enabling unauthorized administrative access and persistent system compromise.
Budibase server versions before 3.40.0 contain an unauthenticated SQL injection vulnerability in webhook-triggered automations, allowing remote attackers to exfiltrate or modify database data.
The miniOrange Headless Single Sign On plugin for WordPress contains an unauthenticated PHP object injection vulnerability in versions 1.6 and earlier.
The rtCamp Log in with Google plugin for WordPress versions 1.4.2 and earlier contains an unauthenticated broken authentication vulnerability.
The Customer Email Verification for WooCommerce plugin allows unauthenticated users to hijack accounts due to a loose comparison in the email verification process.
The Wishlist Member plugin for WordPress is vulnerable to unauthenticated account takeover due to improper validation of registration data, allowing attackers to hijack any user account.
The luci-app-openvpn package for OpenWrt is vulnerable to path traversal during file uploads, enabling authenticated users to write arbitrary files and achieve root code execution.
CyberPanel versions prior to 3.0.0 contain a hard-coded JWT secret in the WebTerminal service, allowing unauthenticated attackers to forge tokens and gain root access via an interactive shell.
Apache Lucy is vulnerable to a deserialization of untrusted data issue, potentially allowing remote code execution due to improper input handling.
A stack-based buffer overflow vulnerability exists in Apache Lucy, potentially allowing attackers to execute arbitrary code.
QuarkA QA Analytics plugin for WordPress contains an unauthenticated remote code execution vulnerability due to improper control of code generation.
Fosowl AgenticSeek suffers from an unauthenticated remote code execution vulnerability in its query API, allowing attackers to execute arbitrary commands via crafted POST requests.
Trigger.dev contains an authorization bypass vulnerability allowing authenticated users to manipulate deployments across different projects by providing unauthorized deployment identifiers.
IBM Documentation Offline 1.0.0 through 1.4.1 contains a path traversal vulnerability that permits unauthenticated remote attackers to execute arbitrary code.
A command injection vulnerability in the ATE Module of various Tenda devices allows unauthenticated remote attackers to execute arbitrary system commands via the CAte::HandleCmd function.
An unauthenticated privilege escalation vulnerability in the miniOrange OTP Verification plugin for WordPress versions 5.5.1 and below allows attackers to gain unauthorized elevated access.
An unauthenticated privilege escalation vulnerability in the SMS Alert Order Notifications plugin for WordPress versions 3.9.7 and below allows attackers to improperly assign privileges.
The WP BASE Booking plugin for WordPress contains an unauthenticated arbitrary code execution vulnerability, allowing remote attackers to execute malicious code on the host server.
The Portal Generator addon to Priority ERP is vulnerable to improper authentication, which may allow unauthorized access to the application infrastructure.
An ACL inconsistency in the OpenWrt LuCI LXC application allows authenticated users with low privileges to bypass authorization and execute arbitrary code as root on the host.
Filebrowser through 2.63.16 contains an incorrect privilege assignment vulnerability that allows unauthenticated attackers to register accounts with full administrative access to the server root.
The miniOrange OAuth Single Sign On plugin for WordPress contains an unauthenticated authentication bypass vulnerability that allows attackers to spoof identities.
The miniOrange Headless Single Sign On plugin for WordPress contains an unauthenticated bypass vulnerability due to improper cryptographic signature verification.
A critical authentication bypass vulnerability exists in the Dimitri Grassi Salon booking system plugin for WordPress, allowing unauthenticated attackers to gain unauthorized system access.
A critical broken authentication vulnerability in the AgniHD Cartify WordPress theme allows unauthenticated attackers to perform account takeover operations on the target site.
A critical broken access control vulnerability exists in the scriptsbundle Nokri WordPress theme, which allows unauthenticated attackers to manipulate password recovery mechanisms.
Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.
Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and gain unauthorized access to the victim’s account.
In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg When the server answers an RTRS READ, rdma_write_sg() builds the source scatter/gather entry for the IB_WR_RDMA_WRITE that returns data to the peer. Its length
A heap buffer overflow in PostgreSQL regular expression processing allows an authenticated database user to execute arbitrary code with the privileges of the database operating system user.
A heap buffer overflow in the PostgreSQL to_char(timestamptz) function allows an authenticated user to execute arbitrary code via a malicious POSIX timezone abbreviation.
A heap-based buffer overflow in the PostgreSQL plperl module allows authenticated function owners to execute arbitrary code with the privileges of the database operating system user.
A heap-based buffer overflow in the PostgreSQL pg_stat_statements module allows authenticated users to execute arbitrary code by crafting queries containing array constants.
An integer wraparound vulnerability in PostgreSQL tsvector and tsquery functions allows authenticated users to trigger out-of-bounds writes via crafted large inputs.
A type confusion vulnerability in the PostgreSQL refint module allows authenticated object creators to execute arbitrary code as the operating system user running the database.
A type confusion vulnerability in PostgreSQL internal data type arguments allows authenticated users to execute arbitrary code with the privileges of the database service account.
An integer wraparound vulnerability in the PostgreSQL fuzzystrmatch module allows authenticated users to execute arbitrary code via specially crafted inputs to specific string functions.
A type confusion vulnerability in the pg_restore_attribute_stats function allows an authenticated object creator to execute arbitrary code on the PostgreSQL server.
A type confusion vulnerability in the PostgreSQL portal and cursor lifecycle allows authenticated users to execute arbitrary code as the system user running the database.
An authorization bypass in the Microsoft Container Migration Solution Accelerator allows authenticated users to manipulate keys, potentially leading to unauthorized system access or data modification.
An unauthenticated PHP object injection vulnerability in the Booking Activities plugin for WordPress allows attackers to execute arbitrary code.
The shescape JavaScript library is vulnerable to uncontrolled resource consumption, which can lead to a denial of service.
CamaleonCMS contains a stored cross-site scripting vulnerability in the post title parameter, allowing authenticated users to execute arbitrary JavaScript in an administrator's browser.
A SQL query validation bypass in the OpenSearch SQL plugin allows authenticated actors to execute arbitrary code on Apache Spark workers via the direct query endpoint.
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Release the VGA arbiter client on register_device() failure The re-order in the Fixes commit below displaced vfio_pci_vga_init() as the last failure point of what is now vfio_pci_core_register_device() without introducin.
A SQL injection vulnerability in the PostgreSQL EXTRACT function allows an object owner to execute arbitrary SQL commands as a superuser.
A heap-based buffer overflow in the PostgreSQL pg_dump utility allows an authenticated user to achieve arbitrary code execution as the OS user running the utility via a crafted transform list.
OpenChoreo contains an authorization bypass vulnerability that allows authenticated users to access resources outside their intended scope.
OpenChoreo contains an OS command injection vulnerability allowing authenticated users to execute arbitrary commands on the underlying Kubernetes host.
Elasticsearch contains an out-of-range pointer offset vulnerability in its native machine learning inference process, potentially allowing unauthorized memory access.
An integer wraparound vulnerability in 32-bit PostgreSQL builds of pltcl and plperl enables authenticated attackers to cause undersized memory allocations and trigger out-of-bounds writes.
A vulnerability in PostgreSQL pg_dump allows a malicious superuser on an origin server to inject arbitrary code that executes during restoration on a client system via psql meta-commands.
A deserialization vulnerability in the Apache Airflow Task SDK allows remote code execution by importing arbitrary modules through a manipulated Callback object.
The MultiVendorX WordPress plugin contains a missing authorization vulnerability in its REST API, allowing authorized vendors to manipulate other vendors' store data.
Zimbra Collaboration (ZCS) is susceptible to remote code execution due to improper neutralization of OS commands.
GitPython is susceptible to OS command injection due to improper neutralization of special elements in kwarg values.
The User Registration & Membership WordPress plugin before 5.2.6 fails to enforce site registration settings, allowing unauthenticated users to create accounts when registration is disabled.
The frp reverse proxy is vulnerable to a denial of service attack via integer overflow and improper array index validation.
The Zalktis accounting application is vulnerable to SQL injection via malicious text fields within received electronic invoices.
A privilege escalation vulnerability in the Aonetheme Service Finder Booking WordPress plugin allows authenticated subscribers to elevate their privileges to higher roles.
ManageEngine Password Manager Pro and PAM360 are vulnerable to authentication bypass due to improper SAML signature verification, allowing unauthorized access to the application.
An improper privilege management vulnerability in IBM i versions 7.3 through 7.6 could allow an unauthenticated attacker to gain unauthorized system access.
A stack-based buffer overflow vulnerability in the TOTOLINK A800R router allows authenticated attackers to execute arbitrary code via the setMacQos function.
A stack-based buffer overflow vulnerability in the TOTOLINK A800R router allows authenticated attackers to execute arbitrary code via the setParentalRules function.
A stack-based buffer overflow in the setMacFilterRules function of the TOTOLINK A800R router allows remote code execution via manipulation of the Comment argument.
A stack-based buffer overflow in the UploadCustomModule function of the TOTOLINK A800R router allows remote code execution via manipulation of the File argument.
A stack-based buffer overflow in the setIpQosRules function of the TOTOLINK A800R router allows remote code execution via manipulation of the Comment argument.
A stack-based buffer overflow in the Tenda G0 httpd web management interface allows remote attackers to execute arbitrary code via the addStaticRoute function.
A remote buffer overflow vulnerability in the Tenda G0 web management interface allows code execution via the setPortMapping function in /goform/module.
A stack-based buffer overflow in the Tenda AC1206 web interface allows remote attackers to execute arbitrary code via the set_device_name function.
The Tenda AC1206 router is vulnerable to a stack-based buffer overflow, allowing memory corruption via specifically crafted input.
Tenda G0 devices are vulnerable to a stack-based buffer overflow, which can lead to memory corruption and potential system compromise.
Budibase is vulnerable to improper privilege management and authorization flaws, allowing authenticated users to perform unauthorized actions within the low-code platform.
IBM Documentation Offline is susceptible to improper output neutralization for logs, which may allow an attacker to inject malicious data into log files.
IBM i contains a vulnerability related to improper privilege management that may allow a local authenticated user to escalate privileges or impact system security.
IBM i is affected by an out-of-bounds write vulnerability that could potentially allow an authenticated remote attacker to execute arbitrary code or cause a system crash.
IBM i is susceptible to an external control of file name or path vulnerability, which may allow an authenticated local attacker to manipulate file operations.
IBM i contains an out-of-bounds write vulnerability in the 5770-JV1 component, which could allow an authenticated local user to execute arbitrary code or cause system instability.
IBM i is affected by an untrusted search path vulnerability, which could allow an authenticated user to achieve arbitrary code execution via manipulated search paths.
IBM i is susceptible to an improper privilege management vulnerability, which could allow a low privileged authenticated user to elevate their privileges within the system.
IBM i contains an out-of-bounds write vulnerability that could be exploited by an authenticated attacker to execute arbitrary code or cause a system crash.
The PostGIS address_standardizer extension contains an out-of-bounds write vulnerability that can be triggered during address standardization processes.
The Silabs WiseConnect platform fails to include maximum encryption key size information in SMP security requests, leading to potential weaknesses in Bluetooth Low Energy pairing.
A vulnerability in Silicon Labs WiseConnect allows unauthenticated attackers to spoof bonded devices, forcing RS9116W or SiWx917 hardware to re-pair with a rogue device.
A vulnerability in Silicon Labs WiseConnect allows Bluetooth re-pairing with existing devices to occur at a lower security level, facilitating potential authentication bypass.
A vulnerability in Silicon Labs WiseConnect allows re-pairing with a lower security level, making the Long Term Key (LTK) susceptible to brute-force attacks.
A memory handling vulnerability in the Linux kernel KVM subsystem for s390 architecture allows for improper AISB location management when registering IRQs without a summary bit.
The ClaudeHookBridge component in Network-AI allows for a deny-pattern bypass via truncation, enabling unauthorized access to restricted network pathways.
The SandboxPolicy component in Network-AI contains a blocklist bypass vulnerability caused by a quote mismatch during input processing.
The fast-xml-parser library is vulnerable to XML Entity Expansion, which could allow an attacker to cause a denial of service via specially crafted XML input.
Absolute Security Secure Access servers prior to version 14.57 contain an out-of-bounds read vulnerability that could lead to system instability or information disclosure.
The sigstore fulcio certificate authority is vulnerable to Server-Side Request Forgery, which could allow unauthorized certificate issuance.
IBM Security Verify Access and Identity Access are susceptible to a format string vulnerability that could allow an authenticated administrator to compromise the system.
An OS command injection vulnerability in NVIDIA LXD instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives.
A cross-site scripting vulnerability exists in GitLab CE/EE that allows a logged-in user to execute arbitrary scripts in the context of the victim's session.
A cross-site scripting vulnerability in GitLab CE/EE allows an authenticated attacker to execute arbitrary malicious scripts in the context of a victim's session.
A stored cross-site scripting vulnerability in the CamaleonCMS contact form plugin allows authenticated attackers to inject arbitrary HTML via the before_html field.
Eclipse RDF4J fails to restrict XML External Entity (XXE) processing in several XML parser entry points, allowing unauthorized data access via external entity references.
JupyterLab is vulnerable to Cross-site Scripting (XSS) due to improper neutralization of input and output encoding, allowing attackers to execute arbitrary scripts in a user's browser session.
The FreePBX backup module contains an access control vulnerability that allows authenticated users with high privileges to perform unauthorized actions due to improper privilege management.
The FreePBX framework is susceptible to external control of system configuration settings, which allows low-privileged users to modify critical system parameters.
IBM i 7 contains an out-of-bounds write vulnerability that could allow an unauthenticated remote attacker to cause a system crash or potentially execute arbitrary code.
IBM i 7 is susceptible to an out-of-bounds write vulnerability that may allow unauthenticated remote attackers to disrupt services or compromise system memory.
Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks.
Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions.
In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert wacom_wac_queue_insert() calls kfifo_skip() in a loop when the kfifo doesn't have enough space for the incoming report.
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: fix UAF in bt_accept_dequeue() bt_accept_get() takes a temporary reference before dropping the accept queue lock.
An issue in OhSoft CoffeeZip v4.
An issue in Unistal Systems Pvt.