CVE-2026-20349
Cisco Secure Firewall ASA and FTD contain a heap inspection vulnerability due to improper memory clearing, which is currently being exploited in the wild.
Critical vulnerabilities, curated daily for security professionals
Saturday's disclosures center on unauthenticated remote code execution and access-control failures in open-source platforms and WordPress plugins, including MindsDB Minds Platform (CVE-2026-73678, CVSS 10) and the SiYuan note-taking application (CVE-2026-72811, CVSS 10). The brief covers 24 critical CVEs, down 25% from the prior day, and 52 high-priority CVEs, down 35%. Notable entries include CVE-2026-19626 (CVSS 9.9) in Tenable Security Center, CVE-2026-48528 (CVSS 9.8) in NCEAS Metacat, and CVE-2026-15826 (CVSS 9.8) in the cozmoslabs User Profile Builder plugin. WordPress ecosystem components account for a large share of the critical set, with authentication bypass and privilege escalation flaws in User Session Synchronizer, TrueBooker, and MStore API exposing site takeover paths. Three CVEs have confirmed active exploitation, affecting Cisco Secure Firewall ASA/FTD, Metabase, and the Windows Ancillary Function Driver for WinSock. Vendor patch data was not resolved for this set (0% confirmed availability), so verify fixed versions directly against vendor advisories before scheduling remediation.
Immediate action: Prioritize the actively exploited issues first: Cisco Secure Firewall ASA/FTD, Metabase, and the Windows Ancillary Function Driver for WinSock, then move to internet-facing WordPress installations running User Profile Builder, User Session Synchronizer, TrueBooker, or MStore API. Patch status is unconfirmed for this data set, so check each vendor advisory for a fixed version and apply the vendor's mitigation or access restriction where no patch exists. Tenable Security Center (CVE-2026-19626, CVSS 9.9) and any exposed MindsDB or SiYuan instances should be reviewed in the same pass given their administrative reach.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Cisco Secure Firewall ASA and FTD contain a heap inspection vulnerability due to improper memory clearing, which is currently being exploited in the wild.
Metabase contains a critical SQL injection vulnerability in the password reset endpoint that allows unauthenticated remote attackers to gain full administrative control over the instance.
A use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock is currently being exploited in the wild.
Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in its REST API, allowing attackers to exfiltrate or modify database content via unsanitized input.
A flaw in the emlog installation script allows unauthenticated attackers to overwrite the configuration file and create a new administrator account via a forced reinstallation.
The User Profile Builder plugin for WordPress is vulnerable to an authentication bypass via type confusion, allowing unauthenticated attackers to log in as the site administrator.
MindsDB Minds Platform versions 26.1.0 and earlier contain an unauthenticated remote code execution vulnerability via the /api/v1/responses/ endpoint and the Anton agent's scratchpad tool.
SiYuan versions up to v3.7.2 are vulnerable to SQL injection via the backlink/mention search query due to improper sanitization of single quotes in client-supplied search keywords.
The 6Storage Rentals plugin for WordPress contains an authentication bypass vulnerability that allows unauthenticated attackers to log in as any user, including administrators.
The User Session Synchronizer plugin for WordPress is vulnerable to an authentication bypass via improper cryptographic validation, allowing unauthenticated attackers to hijack any user account.
The TrueBooker WordPress plugin is vulnerable to account takeover due to an insecure AJAX handler that allows unauthenticated users to modify any account email address.
The MStore API WordPress plugin fails to validate payments with the gateway before marking orders as paid, allowing unauthenticated attackers to obtain goods or services for free.
Tenable Security Center is vulnerable to remote code execution during report generation, allowing an authenticated, non-administrative user to execute arbitrary code on the server.
The Grav API plugin contains an authorization bypass in PagesController that allows unauthenticated attackers to achieve server-side template injection and remote code execution.
The Grav API plugin fails to enforce API key scopes in the ConfigController, allowing attackers to inject and execute arbitrary OS commands via the scheduler configuration.
The Haiwell IoT Cloud HMI Gateway contains a critical OS command injection vulnerability in the Net Check feature, allowing remote unauthenticated attackers to execute commands as root.
IBM Db2 Mirror for i is vulnerable to remote command injection, allowing unauthenticated attackers to execute arbitrary CL commands via improper neutralization of special elements.
A command injection vulnerability exists in Tenable Security Center, allowing remote authenticated attackers to execute arbitrary system commands via an insecurely handled input parameter.
An authentication bypass vulnerability in IBM Db2 Mirror for i allows unauthenticated remote attackers to access or modify sensitive data by manipulating request URI path segments.
IBM Db2 Mirror for i contains a path traversal vulnerability that allows remote, unauthenticated attackers to execute arbitrary code through external control of file names or paths.
The mcp-memory-service package contains a critical authentication bypass vulnerability in the /api/documents/* routes, allowing unauthenticated remote access to document stores.
A critical authentication bypass vulnerability in the getgrav/grav-plugin-api package allows unauthorized users to disable two-factor authentication on target accounts.
The getgrav grav-plugin-api fails to validate API key scopes during creation, allowing attackers to mint unauthorized, full-access super keys.
The Grav API plugin contains a flaw in UsersController that allows attackers to bypass scope caps and promote accounts to super-user status.
A critical Remote Code Execution vulnerability in WGDashboard versions 0 through 4.3.2 allows for OS command injection via insufficient input validation in API endpoints.
An authenticated command injection vulnerability exists in Tenable Security Center during file upload processing, allowing arbitrary command execution.
A Server-Side Request Forgery (SSRF) vulnerability in WGDashboard allows authenticated attackers to perform arbitrary HTTP requests and retrieve responses via the webhook functionality.
The Paymob for WooCommerce plugin for WordPress is vulnerable to unauthenticated SQL injection, allowing attackers to execute arbitrary database queries.
The Wholesale Market plugin for WordPress contains a privilege escalation vulnerability that allows authenticated users to gain unauthorized administrative access.
The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to privilege escalation, allowing authenticated users to elevate their permissions to administrative levels.
The Propovoice WordPress plugin is vulnerable to privilege escalation in versions up to 1.7.8, allowing authenticated users to elevate their access levels.
The Estatik Real Estate Plugin fails to bind OAuth social login flows to user sessions, enabling login CSRF attacks where victims are logged into attacker-controlled accounts.
The MaxUpload WordPress plugin is vulnerable to arbitrary file uploads in versions up to 1.4.0, which could allow an authenticated attacker to execute arbitrary code.
In the Linux kernel, the following vulnerability has been resolved: pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next() pwrseq_debugfs_seq_next() declares 'next' with __free(put_device), which causes put_device() to be called on the returned pointer when the variable goes out of scope.
A denial of service vulnerability in SQLite 3 may allow an unauthenticated attacker to crash the database engine.
The Password Protected WordPress plugin fails to restrict REST API access, allowing unauthenticated users to bypass sitewide password protection and read protected content.
The Netis NC63 Wireless AC1200 Router firmware contains a vulnerability that allows for unauthenticated firmware updates due to missing authentication for critical functions.
The Grav API plugin is vulnerable to improper privilege management, allowing authenticated users to escalate privileges via scoped API keys.
Tenable Security Center contains an OS command injection vulnerability, allowing authenticated local users to execute arbitrary commands with elevated privileges.
A redundant CPU sync in the Linux kernel dma-buf/udmabuf component triggers a spurious cacheline EEXIST warning when debugging is enabled.
Semaphore contains an argument injection vulnerability, allowing authenticated users to execute arbitrary OS commands via crafted Git repository URLs.
Cockpit CMS is vulnerable to OS command injection via improper neutralization of special elements in filenames during file handling operations.
IBM Db2 Mirror for i contains an improper authorization vulnerability that allows an authenticated user to perform unauthorized actions.
A use-after-free vulnerability exists in the Zephyr RTOS dynamic kernel-object disposal path, specifically within the unref_check function in the userspace kernel component.
Tenable Security Center is vulnerable to OS command injection due to insufficient sanitization of filenames during file upload operations.
A stack-based buffer overflow in the TOTOLINK A800R web interface allows remote attackers to achieve arbitrary code execution via the setWiFiWpsConfig function.
A stack-based buffer overflow vulnerability in the TOTOLINK A800R router allows authenticated attackers to trigger memory corruption via the setUrlFilterRules function.
A stack-based buffer overflow in the TOTOLINK A800R web interface allows remote attackers to execute arbitrary code via the setRadvdCfg function.
A stack-based buffer overflow vulnerability exists in TOTOLINK A800R that allows an authenticated attacker to trigger memory corruption.
A stack-based buffer overflow vulnerability in Tenda W20E allows an authenticated attacker to cause memory corruption via the device management interface.
A stack-based buffer overflow in the Tenda W20E QoS component allows remote attackers to trigger memory corruption via the formQOSRuleDel function.
A stack-based buffer overflow vulnerability in Tenda W20E allows authenticated users to trigger memory corruption via specifically crafted inputs.
An improper control of code generation vulnerability in Grav CMS allows authenticated attackers to execute arbitrary code via malicious ZIP file uploads.
A template engine injection vulnerability in Grav CMS allows authenticated attackers to execute arbitrary code via the Twig template engine.
The Flex Objects plugin in Grav is vulnerable to an authorization bypass, allowing authenticated low privilege users to perform unauthorized actions.
File Browser contains an improper access control vulnerability that enables authenticated users to escalate privileges via proxy authentication.
The Tenda AC12 router is susceptible to a buffer overflow and memory corruption vulnerability, which can be triggered by an authenticated attacker.
OpenWrt LuCI contains an overly permissive ACL in the system-mounts module, allowing low-privileged users to modify root crontabs for remote code execution.
The iCagenda extension for Joomla contains a SQL injection vulnerability that allows an authenticated administrator to execute arbitrary SQL commands.
Emlog is vulnerable to SQL injection, allowing authenticated administrators to execute arbitrary SQL commands via the application.
Prospero Flow CRM contains an authorization bypass vulnerability in the payroll module, allowing low-privileged users to access or create cross-tenant payroll data.
SiYuan note-taking software is susceptible to a missing authorization vulnerability, which can be exploited via websockets to bypass security boundaries.
A Cross-site Scripting (XSS) vulnerability in the wetty terminal application allows remote attackers to execute arbitrary scripts via improper input neutralization.
A Server-Side Request Forgery (SSRF) vulnerability in next-ai-draw-io allows remote, unauthenticated attackers to perform unauthorized requests by exploiting DNS rebinding in the URL parsing logic.
An authorization bypass vulnerability in the Prospero Flow CRM product management component allows authenticated users to access or modify data belonging to other tenants.
Flowise is susceptible to a sandbox escape vulnerability via improper input validation in specific pandas methods, allowing authenticated attackers to execute arbitrary code.
A missing authorization vulnerability exists in the development branch of SiYuan, allowing unauthenticated attackers to access restricted endpoints.
The Portal Generator addon for Priority ERP contains an improper access control vulnerability that allows unauthenticated attackers to bypass security restrictions.
The Portal Generator addon for Priority ERP is susceptible to an information disclosure vulnerability that allows unauthenticated remote attackers to access sensitive data.
IBM Db2 Mirror for i is susceptible to OS command injection, allowing an authenticated user to execute arbitrary commands on the host system.
LimeSurvey version 7.0.5 contains a cross-site scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation.
In the Linux kernel, the following vulnerability has been resolved: fuse-uring: make a fuse_req on SQE commit only findable after memcpy Bad userspace might try to trick us and send commit SQEs request unique / commit-id of requests that are not even send to fuse-server (io_uring_cmd_done() not ca.
In the Linux kernel, the following vulnerability has been resolved: iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read The bound-check in iommufd_veventq_fops_read() for the normal vEVENT path uses sizeof(hdr) where the surrounding code uses sizeof(*hdr): if (!vevent_for_lost_event.
Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest.
In the Linux kernel, the following vulnerability has been resolved: crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks Change the krb5 crypto library to provide facilities to precheck the length of the message about to be decrypted or verified.
In the Linux kernel, the following vulnerability has been resolved: ksmbd: require source read access for duplicate extents FSCTL_DUPLICATE_EXTENTS_TO_FILE passes the source file directly to vfs_clone_file_range() or vfs_copy_file_range() without checking the SMB access mask granted to the source.
The Event-Driven Ansible server is vulnerable to event injection due to insufficient verification of data authenticity and reliance on spoofable HTTP headers.
A denial of service vulnerability exists within the schreibfaul1 ESP32-audioI2S library, potentially allowing remote attackers to disrupt service.
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits Move the handling of fastpath userspace exits into vendor code to ensure KVM runs vendor specific operations that need to run before userspace gains contr.