CVE-2025-62593
Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.
Critical vulnerabilities, curated daily for security professionals
Container and cloud infrastructure carried the weight of yesterday's disclosures, with LXC Incus, Microsoft Azure SQL Database, and AWS Athena Federated Query all receiving critical ratings. The set totals 22 critical CVEs, down 15% from the prior day's 26, alongside 86 high-priority items, a 54% increase over the prior day's 56. CVE-2026-61539 in xorbitsai inference and CVE-2026-69502 in Microsoft Azure SQL Database both score CVSS 10, while CVE-2026-62283 in nezhahq nezha and CVE-2026-63125 in LXC Incus sit at 9.9. Remote code execution and authentication bypass patterns dominate, spanning open-source AI and monitoring tooling, WordPress plugins such as Mailgun for WordPress, network hardware including the Comfast CF-N1-S, and managed cloud data services. Patch data is unavailable for the full set at publication (0% confirmed), so treat vendor advisories as the authoritative source and prioritize by exposure rather than by patch status; 9 entries carry confirmed active exploitation, including Microsoft SharePoint, VMware Cloud Foundation, Apple macOS, and Zimbra Collaboration.
Immediate action: Prioritize the actively exploited set first: Microsoft Windows and SharePoint, VMware Cloud Foundation and vCenter, Apple macOS, Zimbra Collaboration, and TrueConf Server, followed by internet-facing LXC Incus hosts, SPIP installations, and WordPress sites running the Mailgun plugin. Confirmed patch data is not yet available for this batch, so check vendor advisories directly for fixed versions and apply interim mitigations (network restriction, disabling exposed services) where no fix has shipped. For Azure SQL Database and AWS Athena Federated Query, verify whether the provider has already remediated server-side and what customer-side connector updates remain.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.
A double-free vulnerability in the Windows IKE Extension allows unauthenticated attackers to execute arbitrary code over a network.
VMware vCenter contains a directory traversal vulnerability in the Syslog server, which may allow an unauthenticated attacker with network access to execute arbitrary code on the system.
A weak authentication vulnerability in Microsoft SharePoint allows unauthenticated remote attackers to bypass security controls and access sensitive information.
An improper authentication flaw in Apple macOS Screen Sharing allows unauthenticated network attackers to bypass credentials and gain remote access.
TrueConf Server contains a vulnerability involving missing authentication for critical functions, which allows unauthorized remote attackers to perform sensitive actions.
Zimbra Collaboration (ZCS) is susceptible to remote code execution due to improper neutralization of OS commands.
MLflow contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to reach internal services due to improper validation of redirected URLs.
TrueConf Server is affected by a code injection vulnerability that allows attackers to execute arbitrary code and escape isolated environments.
An improper neutralization of directives vulnerability in Xinference allows unauthenticated remote attackers to execute arbitrary commands via crafted tool-call prompts.
A SQL injection vulnerability in the GeoTools library allows attackers to execute arbitrary SQL commands via the jsonArrayContains function in OGC filters.
A server-side request forgery vulnerability in Microsoft Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
A Server-Side Request Forgery (SSRF) vulnerability in the Mailgun for WordPress plugin allows unauthenticated attackers to perform unauthorized API actions, potentially leading to account takeover.
An authorization bypass vulnerability in Nezha Monitoring allows authenticated users to access terminal or file-manager sessions of other users by manipulating stream identifiers.
An authenticated Incus user can achieve arbitrary code execution as root on the host by supplying a crafted image containing a symlink to a host file.
An authenticated Incus user can read or overwrite arbitrary files on the host as root by using a crafted image with a symlink in the `metadata.yaml` file.
The Comfast CF-N1-S device is vulnerable to remote command injection via the timestr argument in the ntp_timezone configuration function.
SPIP versions before 4.4.21 are vulnerable to unauthenticated remote code execution via a maliciously crafted X-Spip-Filtre HTTP request header, which is improperly handled during processing.
An improper neutralization of directives in dynamically evaluated code allows authenticated users to access properties in the Lambda compute function used by the Athena Federated Query Neptune Connector.
Incus versions prior to 7.2.0 contain an argument injection vulnerability due to improper validation of backup compression algorithm inputs, enabling arbitrary file writes on the host.
Incus client versions before 7.2.0 are vulnerable to an arbitrary file write flaw when processing a malicious Incus-Image-Hash header from an image server, potentially leading to root-level code execution.
Incus versions prior to 7.3.0 are vulnerable to argument injection in storage volume configuration, allowing project-scoped users to execute arbitrary commands as root on the host.
Incus versions prior to 7.3.0 fail to enforce project restrictions during instance migration, allowing restricted users to escalate privileges and escape to the host.
Incus versions prior to 7.3.0 contain an authorization flaw where instance configuration is merged before project restriction checks, allowing security bypasses during instance copying.
Incus instance snapshots improperly ignore security restrictions, allowing authenticated users to execute arbitrary commands on the host via lowlevel hooks.
A file system vulnerability in LXC Incus allows authenticated users to read or write arbitrary files on the host system using crafted instance backups or images.
The S3 protocol endpoint in LXC Incus is vulnerable to path traversal, allowing authenticated users to create arbitrary files on the host system.
Incus versions prior to 7.2.0 are vulnerable to arbitrary file read, write, or creation via crafted images, potentially leading to arbitrary command execution on the host system.
A symlink-based vulnerability in the Incus `/instances/$name/exec` endpoint allows authenticated users to write arbitrary content to host files, potentially leading to arbitrary command execution.
A broken access control vulnerability in the foreUP customer REST API allows low-privilege users to access records belonging to other users.
The Linux kernel SCTP implementation contains an out-of-bounds read vulnerability due to insufficient validation of embedded address parameters, allowing remote denial of service or information leaks.
CloudNativePG improperly stores sensitive credentials in plaintext, creating a risk of unauthorized database access within Kubernetes environments.
A cross-site scripting (XSS) vulnerability in the OpenSearch Dashboards observability plugin allows authenticated users to execute arbitrary JavaScript in other users' browser sessions.
A use after free vulnerability exists in the Chromoting component of Google Chrome, potentially allowing for arbitrary code execution.
A use after free vulnerability in the Document Object Model (DOM) of Google Chrome could allow a remote attacker to execute arbitrary code.
A buffer overflow vulnerability in the network stack of Google Chrome could allow an attacker to execute arbitrary code.
The WordPress Persistent Login plugin is vulnerable to SQL injection, allowing authenticated subscribers to execute arbitrary database commands.
The WP w3all phpBB plugin for WordPress contains an SQL injection vulnerability that allows authenticated attackers with subscriber-level access to manipulate database queries.
The eShipper Commerce WordPress plugin is vulnerable to an authenticated SQL injection flaw, allowing low-privileged users to execute arbitrary SQL commands via the plugin interface.
The Basekick-Labs arc time-series database is susceptible to unauthenticated information exposure and resource exhaustion due to missing authentication on critical functions.
The Microsoft UFO framework is vulnerable to information exposure and origin validation errors, allowing attackers to compromise sensitive data and system integrity.
Google Chrome contains a privilege elevation vulnerability within its Import functionality, which can be exploited by an attacker to gain elevated system permissions.
Google Chrome is susceptible to improper resource control within the Linux Toolkit Theming component, which may allow for unauthorized system behavior.
A server-side request forgery vulnerability in Microsoft Azure Data Factory allows unauthorized attackers to disclose sensitive information over a network.
An observable response discrepancy in Azure Stack HCI allows an unauthenticated attacker to perform unauthorized information disclosure over a network.
An authorization bypass flaw in Microsoft Partner Center allows an unauthenticated attacker to disclose sensitive information by manipulating user-controlled keys.
An integer overflow vulnerability in Microsoft Azure Data Manager for Energy allows an authenticated attacker to execute arbitrary code over a network.
The Basekick-Labs arc database contains multiple vulnerabilities, including path traversal and insufficient data authenticity checks, requiring low-privileged authentication.
The Basekick-Labs arc time-series database contains vulnerabilities involving missing authentication and insufficient data integrity verification for critical functions.
The YOURLS URL shortener is susceptible to a stored Cross-site Scripting (XSS) vulnerability, allowing unauthenticated attackers to execute malicious scripts in a user's browser.
The deepmerge-ts TypeScript library is vulnerable to an uncontrolled recursion flaw, which can lead to denial-of-service conditions when processing deeply nested objects.
The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin is vulnerable to code injection, which may allow unauthenticated attackers to execute arbitrary code on the server.
The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the wpematico_import_settings function.
Apache CloudStack contains a command injection vulnerability in the diagnostics functionality for system VMs and virtual routers, allowing authenticated users to execute arbitrary commands.
A buffer overflow was addressed with improved bounds checking.
SQL injection vulnerability in Dede CMS v.
A logic issue was addressed with improved restrictions.
A memory corruption issue was addressed with improved memory handling.
The issue was addressed with improved memory handling.
The issue was addressed with improved memory handling.
The issue was addressed with improved memory handling.
An integer overflow was addressed with improved input validation.
Apache InLong is vulnerable to argument injection due to improper neutralization of argument delimiters, which may allow authenticated users to manipulate command executions.
Apache CloudStack is vulnerable to Server-Side Request Forgery (SSRF) and OS Command Injection, allowing authenticated tenants to trigger requests to internal targets via malicious metalink files.
A vulnerability in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes allows for Man-in-the-Middle attacks due to insufficient data authenticity verification.
A vulnerability in the HP OMEN Gaming Hub allows for improper verification of cryptographic signatures, potentially leading to unauthorized system access.
The WP Helper Premium plugin fails to verify order keys during AJAX actions, enabling unauthenticated users to view private customer order details and modify arbitrary order states.
The KiviCare WordPress plugin contains an unauthenticated privilege management vulnerability allowing attackers to register as privileged clinic staff, gaining unauthorized access to sensitive data.
The lxml library and lxml_html_clean package contain an incomplete list of disallowed inputs, leading to potential Cross-site Scripting (XSS) vulnerabilities.
The kin-openapi Go project is susceptible to uncontrolled resource consumption caused by improper memory allocation when processing OpenAPI files.
An authorization bypass vulnerability in the transaction API of Roskus Prospero Flow CRM allows unauthenticated users to access restricted data via user-controlled keys.
A Server-Side Request Forgery vulnerability in the Headroom LLM proxy allows remote attackers to force the server to send requests to arbitrary destinations via a crafted HTTP header.
A Server-Side Request Forgery vulnerability in the 9router /api/provider-nodes/validate endpoint allows authenticated users to bypass SSRF protection and send requests to arbitrary destinations.
Frappe framework contains a Cross-Site Request Forgery (CSRF) vulnerability that allows unauthenticated attackers to perform unauthorized actions on behalf of users.
A stack-based buffer overflow in the firmware update function of TP-Link TL-MR6400 v7.0 allows for potential code execution via malicious firmware images.
Combodo iTop is susceptible to a Cross-site Scripting (XSS) vulnerability that permits attackers to execute malicious scripts in the context of a user session.
LeafWiki is affected by an improper privilege management vulnerability, allowing authenticated users to perform unauthorized actions beyond their intended permission levels.
LeafWiki is affected by a relative path traversal vulnerability that allows authenticated users to access unauthorized files on the underlying system.
Combodo iTop contains a missing authorization vulnerability that allows authenticated users to perform actions outside their designated permission levels.
LibVNCClient is vulnerable to a heap-based buffer overflow and out-of-bounds write, which can be triggered by a malicious VNC server.
A code injection vulnerability in the Omnigent AI agent framework allows authenticated users to execute arbitrary code via improper generation control.
A path traversal vulnerability in Omnigent before version 0.3.0 allows authenticated users to read or write files outside of the intended directory.
Improper authorization in the FreeRTOS-Kernel between versions 7.0.0 and 11.3.0 allows for potential privilege escalation or unauthorized system access.
A path traversal vulnerability in the misp-stix library allows attackers to manipulate file paths during STIX 2 import and export operations.
A vulnerability in the RaTeX math rendering engine allows unauthenticated users to trigger uncontrolled resource consumption or crashes via malformed inputs.
A server-side request forgery (SSRF) vulnerability in the SpecifyJS framework allows unauthenticated attackers to force the server to make unauthorized network requests.
The J2Store extension for Joomla contains an authorization bypass vulnerability, allowing unauthenticated remote attackers to access sensitive data through user-controlled keys.
A denial-of-service vulnerability in misp-stix allows unauthenticated attackers to cause uncontrolled resource consumption by submitting malicious STIX 1 or STIX 2 documents.
A missing authentication vulnerability in Combodo iTop allows unauthenticated attackers to interact with critical functions, potentially leading to unauthorized data access or system manipulation.
The J2Store extension for Joomla is susceptible to a Cross-site Scripting (XSS) vulnerability, which may allow attackers to execute arbitrary scripts in the context of a victim's browser session.
Jet Admin contains an authorization flaw that allows attackers to link malicious applications to custom user domains and reroute traffic by modifying authentication configurations.
The Zoo extension for Joomla is vulnerable to Cross-site Scripting (XSS) due to improper neutralization of input during web page generation.
OpenViking is susceptible to a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated attackers to perform unauthorized requests.
BigBlueButton contains an SQL Injection vulnerability that could allow an authenticated user to perform unauthorized database operations.
CVAT is affected by a Cross-Site Scripting (XSS) vulnerability that could allow an authenticated user to execute malicious scripts in the context of another user session.
IBM AIX and PowerVM VIOS contain an out-of-bounds write vulnerability that could lead to system compromise.
IBM AIX and PowerVM VIOS are susceptible to an OS Command Injection vulnerability that requires high-level privileges.
A heap-based buffer overflow and integer overflow vulnerability exists in the libvips image processing library, potentially allowing for memory corruption and arbitrary code execution.
A reachable assertion and out-of-bounds write vulnerability in the libevent notification library could lead to application crashes or arbitrary code execution.
A path traversal vulnerability in the DigiDoc4 client allows attackers to bypass directory restrictions, potentially leading to unauthorized file access and system compromise.
A heap out-of-bounds write vulnerability in the Photo CD (PCD) decoder of GraphicsMagick can lead to memory corruption during image processing.
A stored Cross-site Scripting (XSS) vulnerability exists in the n8n form completion page, allowing authenticated users to inject malicious scripts.
An expression injection vulnerability in the n8n resource locator allows authenticated users to execute arbitrary code or inject malicious expressions.
An out-of-bounds write vulnerability exists in IBM AIX and PowerVM VIOS, potentially allowing an adjacent attacker to compromise system integrity.
Defuddle is vulnerable to Cross-site Scripting (XSS) due to improper neutralization of input during web page generation.
DiscordChatExporter is vulnerable to Cross-site Scripting (XSS) due to improper neutralization of input during web page generation.
An untrusted pointer dereference vulnerability in IBM AIX and PowerVM VIOS allows an authenticated attacker with high privileges to potentially gain unauthorized system control.
An untrusted pointer dereference vulnerability in IBM AIX and PowerVM VIOS may allow an authenticated attacker with high privileges to impact system stability and security.
An integer overflow vulnerability in IBM AIX and PowerVM VIOS allows unauthenticated attackers to potentially cause a denial of service.
An out-of-bounds write vulnerability in IBM AIX and PowerVM VIOS allows authenticated high-privilege users to potentially compromise system integrity and availability.
The udecode Plate rich-text editor is vulnerable to Server-Side Request Forgery (SSRF) due to improper handling of external requests.
Atlantis is vulnerable to path traversal and improper input validation, allowing authenticated attackers to manipulate file paths via webhook interactions.
A use-after-free vulnerability exists in the llama.cpp RPC graph recompute handler, which could lead to memory corruption or arbitrary code execution.
An out-of-bounds write vulnerability in IBM AIX and PowerVM VIOS allows attackers to potentially compromise system integrity or cause a crash.
A stack-based buffer overflow in IBM AIX and PowerVM VIOS allows for potential system compromise due to improper memory handling.
A local privilege escalation vulnerability in the Linux kernel BPF verifier allows local users to trigger a kernel panic by loading invalid sleepable BPF_LSM_CGROUP programs.
In the Linux kernel, the following vulnerability has been resolved: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() bearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(), but tipc_disc_rcv() still dereferences b->disc in RX softirq under rcu_read_lock() (tipc_udp_rec.