CVE-2025-62593
Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.
Critical vulnerabilities, curated daily for security professionals
Oracle enterprise middleware, Microsoft cloud and collaboration services, and Mozilla browser products account for the highest-impact vulnerabilities disclosed yesterday, several carrying maximum CVSS 10 ratings. The set includes 54 critical CVEs (up 29% from the prior day) and 101 high-priority CVEs (up 6%), for 155 scored vulnerabilities overall. CVE-2026-66803 (CVSS 10) in Microsoft Azure Cosmos DB, CVE-2026-70921 (CVSS 10) in Oracle Hyperion Financial Management, and CVE-2026-75874 (CVSS 10) in Mozilla Firefox and Thunderbird are the most severe individual entries, alongside CVE-2026-75843 and CVE-2026-75851 (CVSS 9.9) in ArcadeData ArcadeDB. Remote code execution and authentication bypass against internet-reachable management and identity components dominate the pattern, with Oracle Identity Manager Connector, Oracle Workflow, Apple macOS, and TRENDnet TEW-WLC100 wireless controllers also affected. Vendor patch data was unavailable for these records at collection time, so teams should verify fix status directly with vendors and prioritize by exposure; five vulnerabilities, including issues in Microsoft Windows, Microsoft SharePoint, VMware Cloud Foundation, Ray-Project Ray, and Apple macOS, have confirmed active exploitation.
Immediate action: Prioritize Oracle middleware and identity components, Microsoft Azure Cosmos DB and SharePoint, VMware Cloud Foundation and vCenter, and Mozilla Firefox and Thunderbird deployments, starting with any instance reachable from untrusted networks. Vendor fix data was not recorded for these entries, so check the relevant advisories directly and apply available updates or documented mitigations; where no fix exists, restrict management interface access and increase monitoring on the affected services.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.
A double-free vulnerability in the Windows IKE Extension allows unauthenticated attackers to execute arbitrary code over a network.
VMware vCenter contains a directory traversal vulnerability in the Syslog server, which may allow an unauthenticated attacker with network access to execute arbitrary code on the system.
A weak authentication vulnerability in Microsoft SharePoint allows unauthenticated remote attackers to bypass security controls and access sensitive information.
An improper authentication flaw in Apple macOS Screen Sharing allows unauthenticated network attackers to bypass credentials and gain remote access.
An improper privilege management vulnerability in ArcadeDB allows authenticated users to execute unauthorized JavaScript commands, leading to privilege escalation to administrator.
A sandbox escape vulnerability exists in the Remote Settings Client component of Mozilla Firefox and Thunderbird, potentially allowing full system compromise.
A privilege management flaw in ArcadeDB allows authenticated users to escalate privileges to administrator by exploiting asynchronous command worker threads.
A critical security vulnerability in Oracle Hyperion Financial Management allows unauthenticated attackers to gain unauthorized access to or modify sensitive financial data via network exploitation.
A critical vulnerability in the Oracle Identity Manager Connector allows a low privileged attacker to achieve full system takeover via network exploitation.
A critical vulnerability in the Oracle Identity Manager Connector allows a low privileged attacker to achieve full system takeover via network exploitation.
An unauthenticated, remotely exploitable vulnerability in the Oracle Workflow Notification Mailer component allows for a full system takeover via SMTP.
Improper access control in Azure Cosmos DB allows an unauthenticated remote attacker to potentially execute arbitrary code.
A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.
A stack-based buffer overflow in the TRENDnet TEW-WLC100 HTTP Header Handler allows remote unauthenticated attackers to execute arbitrary code.
GP Premium allows authenticated contributors to perform arbitrary file uploads, potentially leading to remote code execution.
A critical vulnerability in the Oracle BI Publisher Web Service API allows a low-privileged attacker to achieve full system takeover and cross-scope impact.
An unauthenticated remote vulnerability in the Oracle Helidon Imperative Web Server allows for data manipulation and partial denial of service via HTTP.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious SMB server may lead to unexpected system termination.
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.
A critical vulnerability in the Oracle Internet Directory LDAP server allows an unauthenticated remote attacker to achieve a full system takeover.
A critical vulnerability in Oracle Hyperion Data Relationship Management allows an unauthenticated remote attacker to gain complete system control via TCP.
A critical vulnerability in Oracle Hyperion Financial Management allows a low-privileged attacker to achieve a full system takeover via SQL.
A critical vulnerability in Oracle WebLogic Server allows a low privileged attacker with network access to compromise the server via T3 or IIOP protocols.
A critical vulnerability in the Oracle Identity Manager Legacy UI allows a low privileged, network-authenticated attacker to gain full control of the application.
A critical vulnerability in the Composer component of Oracle WebCenter Portal allows a low privileged attacker with network access to achieve a full system compromise.
An unauthenticated remote code execution or data manipulation vulnerability exists in Oracle WebCenter Enterprise Capture, allowing unauthorized access to critical data and partial system disruption.
A critical vulnerability in the Oracle Managed File Transfer runtime server allows authenticated attackers with low privileges to achieve a full system takeover via T3 or IIOP protocols.
A critical vulnerability in Oracle WebCenter Sites allows low-privileged, authenticated attackers to achieve a full system takeover via HTTP.
A critical vulnerability in Oracle Identity Manager allows low privileged attackers to achieve full system compromise via RMI.
A critical security flaw in Oracle Hyperion Calculation Manager enables authenticated, low privileged attackers to compromise the system via HTTP.
A critical vulnerability in Oracle Internet Directory allows low privileged, authenticated attackers to compromise the system via LDAP.
A critical vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows low privileged attackers to compromise the system via network access.
An unauthenticated vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows remote attackers to access, modify, or delete sensitive data.
A critical vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows low privileged attackers to compromise the application via network access.
A critical vulnerability in Oracle Siebel CRM Integration allows low privileged attackers to achieve full system takeover via HTTP requests.
A critical vulnerability in Oracle Reports Developer enables low privileged attackers to compromise the system via CORBA.
A critical vulnerability in Oracle Access Manager allows unauthenticated attackers to achieve full system takeover via SAML.
A critical vulnerability in the Oracle Commerce Platform Dynamo Application Framework allows unauthenticated remote attackers to achieve full system takeover via TCP.
A critical vulnerability in the Oracle Commerce Platform Dynamo Application Framework allows unauthenticated remote attackers to achieve full system takeover via HTTP.
A critical vulnerability in the Oracle WebCenter Portal Runtime Tools component allows unauthenticated remote attackers to achieve full system takeover via HTTP.
A critical vulnerability in the Endeca Application Controller component allows unauthenticated, remote attackers to achieve full system takeover via HTTP.
A critical security vulnerability in the Oracle Agile PLM component allows unauthenticated, remote attackers to compromise the system via HTTP.
A flaw in the submariner-operator component allows a compromised cluster to perform MITM attacks across a cluster mesh by overwriting endpoint information due to excessive permissions.
The TRENDnet TV-IP751WIC contains a stack-based buffer overflow vulnerability in the alphapd component that can be triggered remotely by an authenticated user.
A stack-based buffer overflow in the Comfast CF-N1-S URI parameter parsing component allows remote, unauthenticated attackers to execute arbitrary code.
An unauthenticated remote code execution vulnerability exists in the WP Compress WordPress plugin due to improper control of code generation, allowing attackers to execute arbitrary commands.
The UTT HiPER 1200GW router contains a stack-based buffer overflow vulnerability in the strcpy function, reachable via the timestart argument in /goform/formGroupConfig, allowing remote code execution.
The UTT HiPER 1250GW router contains a stack-based buffer overflow in the /goform/aspApBasicConfigUrcp component, reachable via the pvid argument, allowing remote code execution.
A stack-based buffer overflow exists in the TRENDnet TEW-823DRU router due to improper input validation in the wan_l2tp_password argument within the wan.cgi file.
A remote code execution vulnerability exists in the Cwicly plugin for WordPress, allowing authenticated users with contributor-level access to execute arbitrary code.
Netflix Lemur contains a server-side request forgery (SSRF) and authorization bypass vulnerability that can lead to unauthorized access to cloud instance metadata and private keys.
The Templatiq WordPress plugin is vulnerable to an arbitrary file upload flaw, allowing authenticated contributors to execute malicious code on the server.
The Sync Post With Other Site WordPress plugin is vulnerable to an arbitrary file upload flaw, allowing authenticated contributors to execute malicious code on the server.
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.
A vulnerability in the Web Services Security component of Oracle Agile Engineering Data Management allows an authenticated attacker to gain unauthorized control of the application.
A vulnerability in the Web Service API component of Oracle BI Publisher allows a low-privileged authenticated attacker to compromise the application.
A vulnerability in the Security API of Oracle Sales Foundation enables an authenticated attacker to compromise the integrity and availability of the application.
Joomla! CMS and Framework Filesystem are vulnerable to unrestricted file uploads, potentially allowing attackers to upload SHTML files.
The HashBar WordPress plugin contains a Cross-Site Request Forgery (CSRF) vulnerability, which may allow unauthorized actions to be performed on behalf of an authenticated user.
A security vulnerability in the Access and security component of Oracle Hyperion Data Relationship Management allows for potential system takeover.
A vulnerability in the Outbound Data component of Oracle Product Hub allows an authenticated attacker to achieve full system compromise via network access.
A vulnerability in the Web UI component of Oracle Financial Services Enterprise Case Management allows an authenticated attacker to compromise the system via network access.
A vulnerability in the Security component of Oracle Hyperion Financial Management allows an authenticated attacker to compromise the system via SQL-based network access.
A security vulnerability in Oracle Hyperion Financial Management allows a low privileged, network-authenticated attacker to achieve a full system takeover.
An easily exploitable vulnerability in Oracle Payroll within E-Business Suite allows an attacker with local infrastructure access to compromise the system and potentially impact other products.
A security vulnerability in Oracle Hyperion Financial Management allows a low privileged, network-authenticated attacker to achieve a full system takeover via TCP.
An easily exploitable vulnerability in Oracle Purchasing allows a low privileged, network-based attacker to fully compromise the application.
A vulnerability in the Siebel CRM Deployment component allows a low privileged attacker with network access to compromise the server infrastructure.
A critical flaw in the Siebel CRM End User Document Management component allows low-privileged attackers to achieve full system takeover.
A vulnerability in the Oracle Hyperion Infrastructure Technology component allows an authenticated attacker to gain full control of the affected system.
An authenticated vulnerability in the Oracle Hyperion Infrastructure Technology Installation and Configuration component enables system takeover by low privileged attackers.
A critical flaw in the Oracle Hyperion Infrastructure Technology Installation and Configuration module allows low privileged users to gain full system control.
A vulnerability in the Oracle Agile PLM Application Server allows a low privileged, network-based attacker to fully compromise the system.
A vulnerability in the Export component of Oracle Agile PLM allows a low privileged attacker to achieve full system compromise via HTTP.
An unauthenticated, network-based vulnerability in the Oracle Agile PLM Security component allows for system takeover through human interaction.
A vulnerability in the security component of Oracle Agile PLM 9.3.6 allows an authenticated, low privileged attacker with local access to the infrastructure to compromise the application.
A vulnerability in the installation component of Oracle Product Lifecycle Analytics 3.6.1 allows a low privileged local attacker to compromise the application and potentially impact other systems.
A vulnerability in the platform security component of Oracle Business Intelligence Enterprise Edition 12.2.1.4.0 allows a low privileged network attacker to compromise the application via HTTP.
An easily exploitable vulnerability in the Oracle Agile PLM MCAD Connector CAX Client allows a low privileged attacker to achieve full product takeover via HTTP.
An easily exploitable vulnerability in the Oracle Hospitality OPERA 5 Opera Servlet allows an unauthenticated attacker to compromise the system through user interaction.
A security vulnerability in the Oracle Hyperion Financial Management component allows a low-privileged, network-adjacent attacker to achieve full system takeover.
A vulnerability in the OIM Legacy UI component of Oracle Identity Manager allows an authenticated attacker with network access via HTTP to potentially take over the application.
A vulnerability in the OIM Legacy UI component of Oracle Identity Manager allows an authenticated attacker with network access via T3 or IIOP protocols to potentially take over the application.
A vulnerability in the OIM Legacy UI component of Oracle Identity Manager allows an authenticated attacker with network access via T3 or IIOP protocols to potentially take over the application.
A vulnerability in the Authentication Engine of Oracle Access Manager allows a low privileged attacker with network access via HTTP to compromise the system.
A vulnerability in the Composer component of Oracle WebCenter Portal allows a low privileged attacker with network access via HTTP to compromise the system.
A vulnerability in the Composer component of Oracle WebCenter Portal allows a low privileged attacker with network access via RMI to compromise the system.
A vulnerability in the Marketing component of Oracle Siebel CRM allows a low privileged attacker with network access to compromise the application.
A vulnerability in the Marketing component of Oracle Siebel CRM allows a low privileged attacker with network access to compromise the application.
A vulnerability in the Configuration Manager component of Oracle PeopleSoft Enterprise PeopleTools allows a low privileged attacker to compromise the system via SQL.
A vulnerability in the nVision component of Oracle PeopleSoft Enterprise PeopleTools allows an unauthenticated attacker to compromise the system via network-based HTTP interaction.
A vulnerability in the Internal Operations component of Oracle Scripting within E-Business Suite allows a low-privileged attacker to compromise the application via network-based HTTP requests.
A vulnerability in the B2B Engine of Oracle SOA Suite allows a low-privileged attacker to achieve system takeover through network-based HTTP interaction.
An easily exploitable vulnerability in Oracle WebCenter Sites allows a low privileged attacker with network access to achieve a full system compromise via HTTP.
A critical vulnerability in Oracle WebCenter Sites allows a low privileged attacker with network access to perform a full compromise of the affected component.
An easily exploitable flaw in Oracle WebCenter Sites permits a low privileged attacker to compromise the platform via network access.
A high-severity vulnerability in Oracle WebCenter Sites allows a low-privileged, authenticated attacker with network access to compromise the application.
A high-severity vulnerability in Oracle WebCenter Sites enables authenticated, low-privileged network attackers to compromise the application.
A high-severity vulnerability in Oracle WebCenter Sites allows authenticated, low-privileged network attackers to achieve total system compromise.
A vulnerability in the OIM Legacy UI component of Oracle Identity Manager allows an authenticated attacker with network access to achieve full system takeover.
A vulnerability in the Runtime Tools component of Oracle WebCenter Portal allows an authenticated attacker to gain complete control of the application.
A vulnerability in the Virtual Directory Server component of Oracle Virtual Directory allows an authenticated attacker to achieve full system takeover via LDAP.
A vulnerability in the Installation Security component of Oracle JD Edwards EnterpriseOne Tools allows authenticated network attackers to achieve a full system takeover.
A security vulnerability in Oracle Hyperion Calculation Manager allows an authenticated remote attacker to compromise the application via network-based HTTP requests.
A vulnerability in the Application Config Console of Oracle Enterprise Manager Base Platform allows an authenticated remote attacker to compromise the system.
A critical vulnerability in Oracle U.S. Federal Financials allows an authenticated, low privileged attacker to achieve full system takeover via network-based HTTP requests.
A vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows a low privileged attacker to achieve system takeover via network-based HTTP requests.
A vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM Cloud Applications allows a low privileged attacker to achieve system takeover via network-based HTTP requests.
A vulnerability in the Internal Operations component of Oracle Flow Manufacturing allows an authenticated attacker with network access to achieve a full system takeover.
A vulnerability in the Internal Operations component of Oracle Work in Process allows an authenticated attacker with network access to achieve a full system takeover.
A vulnerability in the Common Events component of Oracle Hyperion Infrastructure Technology allows an authenticated attacker with network access to achieve a full system takeover.
A security and authentication vulnerability in Oracle Reports Developer allows an authenticated attacker with network access to achieve a full system takeover.
A security vulnerability in Oracle Reports Developer allows an unauthenticated attacker to compromise the system through a user-interaction based attack vector.
An unauthenticated vulnerability in Oracle Reports Developer allows attackers with physical segment access to compromise the system.
A security vulnerability in Oracle Reports Developer allows an unauthenticated attacker on the local network segment to achieve a full system takeover.
A security flaw in Oracle Reports Developer enables unauthenticated attackers on the local network segment to perform a complete takeover of the application.
A flaw in Oracle General Ledger allows low-privileged users to achieve a full system takeover via network-based HTTP requests.
A critical vulnerability in the Oracle Essbase Calculator component allows a low privileged, network-based attacker to fully compromise the application.
A vulnerability in the Internal Operations component of Oracle Sales for Handhelds allows low privileged, network-based attackers to compromise the application.
An unauthenticated vulnerability in the Trace File Analyzer component of Oracle Autonomous Health Framework allows local network attackers to achieve system takeover.
A vulnerability in the Service Request Form component of Oracle Teleservice allows a low privileged attacker with network access to compromise the application.
A vulnerability in the Storage Server Management component of Oracle Enterprise Manager for Systems Infrastructure allows a low privileged attacker to compromise the system.
A vulnerability in the Server component of Oracle Hyperion Financial Reporting allows a low privileged attacker to compromise the application.
A vulnerability in the Customer Tab of Oracle Customers Online allows a low privileged, network-based attacker to fully compromise the component.
A vulnerability in the Internal Operations component of Oracle Risk Management allows a low privileged, network-based attacker to fully compromise the component.
A vulnerability in the Server component of Oracle Hyperion Financial Reporting allows a low privileged, network-based attacker to fully compromise the component.
A vulnerability in the Oracle Yard Management component of Oracle E-Business Suite allows a low-privileged attacker to achieve a full system takeover via network access.
A vulnerability in the Oracle Call Center Technology component of Oracle E-Business Suite allows a low-privileged attacker to achieve a full system takeover via network access.
A vulnerability in the Oracle Call Center Technology component of Oracle E-Business Suite allows a low-privileged attacker to achieve a full system takeover via network access.
A security vulnerability in Oracle Hyperion Financial Management allows a low privileged attacker to achieve full system compromise via network-based SQL injection.
A security vulnerability in Oracle Hyperion Financial Management allows a low privileged attacker to achieve full system compromise via network-based SQL injection.
A security vulnerability in Oracle Hyperion Financial Management allows a low privileged attacker to achieve full system compromise via network-based SQL injection.
A vulnerability in the Oracle Application Testing Suite allows attackers with specific low-level privileges to compromise the application via HTTPS.
A security vulnerability in Oracle Hyperion Data Relationship Management allows a low-privileged network attacker to perform a complete system takeover.
A vulnerability in the Oracle Hyperion Data Relationship Management access and security component allows an authenticated attacker with network access to achieve full system compromise.
A use-after-free vulnerability in the Valkey key-value database allows an authenticated attacker to potentially execute arbitrary code or cause a system crash.
A PHP object injection vulnerability exists in the TaxoPress WordPress plugin, allowing authenticated users to perform unauthorized operations via deserialization of untrusted data.
A broken authentication and session management vulnerability in Atlassian Crowd Data Center version 7.2.1 allows for potential unauthorized access and session manipulation.
A security vulnerability in the Dell Watchdog Timer Driver allows for privilege escalation due to an exposed IOCTL with insufficient access control.
The Login & Register Forms WordPress plugin fails to properly enforce password reset attempt limits, allowing unauthenticated attackers to bypass rate limiting and brute force account credentials.
An authorization vulnerability in the Netflix Lemur certificate management tool allows authenticated users to perform unauthorized actions during the TLS certificate creation process.
The UsersWP WordPress plugin before 1.
A Time-of-check Time-of-use (TOCTOU) race condition exists in the n8n workflow automation platform that could allow authenticated users to impact system integrity.
A path traversal vulnerability in the 4gaBoards real-time project management system allows authenticated users to access or modify restricted files on the host system.
An authentication bypass vulnerability in 4gaBoards allows unauthenticated attackers to gain unauthorized access to the system through improper authentication mechanisms.
Streambert contains path traversal and improper file path handling vulnerabilities, allowing local attackers to access restricted files.
Streambert contains improper input validation and OS command injection vulnerabilities, enabling local attackers to execute arbitrary system commands.
The goauthentik identity provider contains authorization bypass vulnerabilities, allowing authenticated users to perform unauthorized actions due to improper key handling.
A vulnerability in the Vvveb CMS allows authenticated users to bypass authorization controls, potentially leading to unauthorized data modification or administrative actions.
A vulnerability in the Vvveb CMS allows authenticated users to bypass authorization controls, potentially leading to unauthorized data modification or administrative actions.
An integer overflow vulnerability in the Dragonfly in-memory data store allows unauthenticated remote attackers to trigger memory corruption and cause service disruption.
Oh My Zsh is susceptible to code injection, allowing an unauthenticated attacker to execute arbitrary commands if a user is coerced into interacting with a malicious environment.
A memory safety vulnerability in the Linux kernel ksmbd module allows local attackers to trigger an out-of-bounds read during Access Control Entry (ACE) processing.
A flaw in the Linux kernel ksmbd module's set_ntacl_dacl function leads to an out-of-bounds read when size accounting overflows occur during Access Control Entry (ACE) processing.
An out-of-bounds heap read vulnerability exists in the Linux kernel ksmbd implementation, allowing authenticated attackers to disclose sensitive memory via crafted security descriptors.