CVE-2026-72529
TrueConf Server contains a vulnerability involving missing authentication for critical functions, which allows unauthorized remote attackers to perform sensitive actions.
Critical vulnerabilities, curated daily for security professionals
Widely deployed open-source and web infrastructure carried the day's most impactful flaws, with remote code execution reported in GitPython, Adminer, rConfig, CakePHP, and the Zephyr RTOS, alongside two 9.6 issues in Google Chrome. Yesterday's disclosures totaled 150 CVEs: 54 rated critical (up 135% from 23) and 96 rated high priority (up 167% from 36). CVE-2026-78676 in gitpython-developers GitPython and CVE-2026-56705 in vrana Adminer both score 9.8 and sit inside developer and database administration toolchains, while CVE-2026-76840 in RustDesk (9.6) affects remote access deployments. Five vulnerabilities have confirmed active exploitation, including TrueConf Server (CVE-2026-72529, CVE-2026-72530), Zimbra Collaboration (CVE-2026-73570), and Oracle WebLogic Server Proxy Plug-in (CVE-2026-21962), pointing at collaboration and middleware tiers as current attacker targets. Patch data was unavailable for this set (0% recorded), so teams should verify fix status directly with each vendor and prioritize internet-facing and developer-adjacent systems.
Immediate action: Prioritize internet-facing collaboration and middleware systems first: TrueConf Server, Zimbra Collaboration, and Oracle WebLogic Server Proxy Plug-in all have confirmed exploitation, followed by Chrome updates across managed endpoints and the mlflow instances in ML environments. Developer toolchain components (GitPython, Adminer, rConfig, CakePHP) should be inventoried and upgraded next given their 9.2+ scores and typical placement near credentials and source code. Patch availability is recorded at 0% for this data set, so validate current fixed versions against each vendor advisory rather than assuming no update exists.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
TrueConf Server contains a vulnerability involving missing authentication for critical functions, which allows unauthorized remote attackers to perform sensitive actions.
Zimbra Collaboration (ZCS) is susceptible to remote code execution due to improper neutralization of OS commands.
An unauthenticated remote code execution vulnerability exists in Oracle WebLogic Server Proxy Plug-ins for Apache HTTP Server and IIS, potentially leading to a full system compromise.
MLflow contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to reach internal services due to improper validation of redirected URLs.
TrueConf Server is affected by a code injection vulnerability that allows attackers to execute arbitrary code and escape isolated environments.
A PHP Object Injection vulnerability in the ACPT (Pro) plugin for WordPress allows unauthenticated attackers to execute arbitrary code or perform unauthorized actions via deserialization.
A stack-based buffer overflow in the OCPP 1.6 client of the Zephyr RTOS allows remote attackers to cause a denial of service or potentially execute arbitrary code via a crafted message.
Adminer before 5.4.3 is vulnerable to DSN injection, allowing unauthenticated attackers to write arbitrary PHP code to the web root and achieve remote code execution.
GitPython before 3.1.59 is vulnerable to argument injection where crafted multi-line git-config values allow attackers to inject malicious directives, leading to arbitrary code execution.
rConfig 8.0.0 before 8.2.10 contains an authentication bypass that allows unauthenticated users to register new accounts with default Administrator privileges.
CakePHP is vulnerable to SQL injection in the FunctionsBuilder::jsonValue method when using the PostgresDriver, potentially allowing unauthorized database manipulation.
RustDesk's clipboard redirection feature in Windows is vulnerable to a heap buffer overflow, which could allow a malicious remote peer to execute arbitrary code on the client.
RansomLook contains an authorization flaw in its legacy database export functionality, allowing unauthenticated users to access private entity data.
Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Multiple vulnerabilities in OpenThread's handling of MLE packets in Google Nest allow unauthenticated attackers to cause a denial of service via buffer overflows or assertion failures.
An unauthenticated privilege escalation vulnerability exists in the Affiliate Pro plugin for WordPress, allowing unauthorized users to elevate their account permissions.
The Total Donations plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive database information.
The CakePHP Authentication plugin is vulnerable to authentication bypass and resource exhaustion due to the use of forgeable legacy tokens in the CookieAuthenticator.
Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Medium)
Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
The WP Project Manager plugin for WordPress contains an unauthenticated PHP object injection vulnerability that can lead to remote code execution.
The Events Calendar plugin for WordPress is vulnerable to unauthenticated PHP object injection, allowing remote attackers to execute arbitrary code.
The FreightCo theme for WordPress contains an unauthenticated PHP object injection vulnerability that may allow for remote code execution.
SteelSeries GG for macOS contains a buffer overflow vulnerability in its device management components, allowing remote code execution.
The Jawn theme for WordPress is susceptible to an unauthenticated privilege escalation vulnerability, allowing attackers to gain administrative control.
OAuth2 Proxy fails to properly validate the X-Forwarded-Uri header when configured with default proxy settings, allowing unauthenticated attackers to bypass authentication for protected routes.
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to writ
RansomLook contains an authorization weakness in its administrative interface, allowing authenticated users to modify sensitive application configurations without proper privilege validation.
The NLTK library contains an unsafe pickle deserialization vulnerability in the TransitionParser, allowing arbitrary code execution when processing malicious model files.
The WPvivid Backup, Migration & Staging plugin contains an arbitrary file creation vulnerability due to improper sanitization of log file paths provided by unauthenticated requests.
Netis NC63 firmware is vulnerable to a stack-based buffer overflow via the login handler, allowing unauthenticated remote attackers to achieve remote code execution as root.
Netis NC63 firmware contains a stack-based buffer overflow in the ipFilterList action, allowing unauthenticated remote attackers to achieve remote code execution as root.
UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.
The Grav Login plugin before 1.0.16 fails to validate privilege levels in the API, allowing attackers to remove brute-force protection from high-privilege accounts.
Multiple DrayTek VigorAP models are vulnerable to pre-authentication remote OS command injection via the dray_apm component.
Multiple DrayTek VigorSwitch models are susceptible to pre-authentication OS command injection via the setget.cgi interface.
An authorization bypass in the Roskus Prospero Flow CRM supplier API allows authenticated users to modify or reassign sensitive supplier records via IDOR.
RansomLook fails to enforce authorization checks, allowing unauthenticated attackers to retrieve private group information, ransom notes, and metadata via web and API endpoints.
The TranslatePress WordPress plugin contains an unauthenticated privilege escalation vulnerability, allowing remote attackers to gain unauthorized administrative access.
The Digits WordPress plugin is affected by an unauthenticated privilege escalation vulnerability, enabling remote attackers to gain unauthorized elevated access.
A critical privilege escalation vulnerability exists in MVPThemes Jawn up to version 1.4.2, allowing unauthenticated attackers to gain unauthorized administrative access.
An unauthenticated SQL injection vulnerability in the WooBeWoo Product Filter Pro plugin up to version 3.1.8 allows attackers to execute arbitrary database queries.
An unauthenticated SQL injection vulnerability in the PixelYourSite Boost plugin up to version 2.0.4 allows attackers to execute arbitrary database commands.
A critical SQL injection vulnerability in the DiviNext Woo Essential plugin allows unauthenticated attackers to execute arbitrary database queries.
An arbitrary account takeover vulnerability in the miniOrange OAuth Client extension for Joomla allows remote attackers to log in as arbitrary users via cookie manipulation.
An arbitrary file upload vulnerability in the tophive UltimateAI plugin allows authenticated subscribers to upload malicious files, leading to potential remote code execution.
A path traversal vulnerability in Canonical LXD allows authenticated users to escape container confinement and achieve host root code execution by overwriting arbitrary host files.
An unauthenticated local file inclusion vulnerability in the WPCafe WP Cafe Pro plugin allows remote attackers to access sensitive files on the server.
Combodo iTop versions prior to 3.2.3 contain a vulnerability allowing authenticated users to delete a critical .readonly configuration file, leading to remote code execution.
The FURUNO ELECTRIC CO. FA-50 marine device contains hard-coded credentials that allow unauthorized users to modify identification numbers via the settings screen.
RansomLook versions 2.0.0 and earlier expose full API keys in the HTML source code of the administrative interface, allowing unauthorized credential recovery.
Dancer2::Plugin::Auth::Extensible is vulnerable to host header injection, allowing unauthenticated attackers to poison password reset links and perform account takeovers.
A critical file upload vulnerability in RainyGao-GitHub DocSys v.2.02.80 allows remote, unauthenticated attackers to execute arbitrary code on the host system.
Mahara is vulnerable to unauthorized internal account access via Learning Tools Interoperability (LTI) 1.1 and 1.3 due to improper request validation.
HP Easy Start for macOS contains a vulnerability related to the use of unmaintained third-party components, which could be leveraged by a local user to escalate privileges or compromise the system.
A vulnerability in HP Easy Start for macOS allows for the creation of temporary files in directories with insecure permissions, potentially leading to unauthorized system access.
HP Easy Start for macOS contains a vulnerability related to the cleartext transmission of sensitive information, which may be intercepted by unauthorized parties.
A use after free vulnerability in the Fuchsia zircon kernel pager proxy allows an authenticated attacker to achieve privilege escalation from userspace to kernel.
A buffer overflow vulnerability in Zscaler Client Connector for Windows allows an authenticated attacker to trigger a local and kernel denial of service.
CakePHP is vulnerable to CRLF injection, which may allow an unauthenticated attacker to manipulate HTTP headers and perform malicious actions against the application.
A buffer overflow vulnerability in Zscaler Client Connector for Android and ChromeOS allows a local attacker to trigger a denial of service condition.
A local file inclusion vulnerability in LiquidThemes MagicAI for WordPress allows an authenticated subscriber to include arbitrary files on the server.
Filament contains an improper authentication vulnerability that allows authenticated users to perform unauthorized actions.
The Tonda Core WordPress plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read or execute arbitrary files on the server.
The Verdure Core WordPress plugin contains a local file inclusion vulnerability that allows unauthenticated attackers to read or execute arbitrary files.
A resource consumption vulnerability exists in the js-libp2p networking stack, potentially allowing unauthenticated remote attackers to cause a denial-of-service state.
The InfusedWoo Pro plugin for WordPress is susceptible to privilege escalation through an account takeover vulnerability, allowing authenticated users to compromise accounts.
The CM Map Locations plugin for WordPress is vulnerable to limited arbitrary file upload, which can be exploited by authenticated users to upload malicious files.
The Extra Product Options Builder for WooCommerce plugin lacks authorization checks, allowing unauthenticated users to access and download customer-uploaded files if the filename is known.
The Verdure Core plugin for WordPress is vulnerable to Local File Inclusion, which could allow an unauthenticated attacker to access sensitive files on the server.
The Edge-Themes Shuffle WordPress theme is vulnerable to Local File Inclusion, allowing unauthenticated attackers to potentially access or execute arbitrary files on the server.
The Elated-Themes Mane WordPress theme contains a Local File Inclusion vulnerability, enabling unauthenticated attackers to potentially read or execute arbitrary files on the underlying web server.
The CatFolders Document Gallery & PDF Library WordPress plugin fails to implement authorization checks, allowing unauthenticated users to enumerate and retrieve sensitive media attachment metadata.
An improper access control vulnerability in Dell ThinOS 10 allows a local authenticated user to potentially gain elevated privileges or perform unauthorized actions.
The WP Directory Kit WordPress plugin is vulnerable to SQL injection, allowing an authenticated administrator to potentially access unauthorized data across a multisite network.
A remote code execution vulnerability in the Le-yan Medical Practice Management System allows unauthenticated attackers to execute arbitrary code via a malicious communication channel.
Xinference improperly enables remote code execution when loading models via Hugging Face, potentially allowing attackers to execute arbitrary code.
GitPython is vulnerable to local file content disclosure via specially crafted gitmodules, which allows attackers to read arbitrary files on the local system.
GitPython is susceptible to path traversal attacks via separate git directories, potentially allowing unauthorized access to files outside the intended repository scope.
Mistune is susceptible to uncontrolled recursion, allowing unauthenticated attackers to cause a denial of service through specially crafted Markdown input.
RansomLook contains authentication weaknesses allowing unauthenticated attackers to enumerate usernames, perform password guessing, and exhaust system resources.
RansomLook exposes sensitive operator-side scraping configurations through unauthenticated API responses, leading to potential information disclosure.
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an administrative user to execute arbitrary system commands via a VPN connection.
Firmware in KAON PG5298A and PG5298B routers allows authenticated users to execute unauthorized operations via crafted JSON-RPC requests.
The OAuth token endpoint in hexpm contains an authorization flaw allowing API keys with repository permissions to access private packages belonging to other organizations.
The Booking Hub WordPress plugin contains a privilege escalation vulnerability allowing authenticated subscribers to gain unauthorized elevated permissions.
Multiple local privilege escalation vulnerabilities in Zscaler Client Connector allow unprivileged users to execute code with elevated system privileges.
A SQL injection vulnerability exists in Delta DIAEnergie that allows an authenticated attacker to execute arbitrary SQL commands via improper input neutralization.
A SQL injection vulnerability exists in Delta DIAEnergie that allows an authenticated attacker to execute arbitrary SQL commands via improper input neutralization.
A SQL injection vulnerability exists in Delta DIAEnergie that allows an authenticated attacker to execute arbitrary SQL commands via improper input neutralization.
Delta DIAEnergie versions up to 1.11.00.002 contain an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands.
AshAuthentication in team-alembic contains an authentication flaw where purpose-limited JWTs can be replayed as full bearer API credentials in stateless verification scenarios.
The ThemeBing ProLancer Element plugin for WordPress contains a SQL injection vulnerability that allows authenticated subscribers to execute arbitrary SQL commands.
A SQL injection vulnerability in the WP Project Manager Pro plugin allows authenticated subscribers to execute unauthorized database queries.
An SQL injection vulnerability in the FluentCRM Pro plugin allows authenticated authors to execute arbitrary database queries.
A cross-site scripting (XSS) vulnerability in Combodo iTop allows authenticated users to execute arbitrary JavaScript in the context of the victim's session.
Adminer is vulnerable to an unrestricted file upload flaw, allowing authenticated attackers to upload malicious files to the server.
The Grav Email plugin is susceptible to a template injection vulnerability, allowing authenticated attackers to execute arbitrary code.
Label Studio fails to properly scope annotation detail endpoints, permitting unauthorized access to sensitive data across different organizations.
AzuraCast contains an authorization bypass vulnerability allowing authenticated users to modify Liquidsoap custom configuration fields without the required permissions.
The Zephyr virtio driver fails to validate the descriptor chain head ID, which may lead to memory corruption when communicating with a virtio device.
RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view, allowing execution of arbitrary scripts in the context of a user session.
A use after free vulnerability in WebKitGTK allows remote attackers to trigger memory corruption and potentially execute arbitrary code via a crafted web page.
The nektos act tool exposes an unauthorized HTTP Artifacts V4 backend when using specific artifact upload or download actions, leading to potential data integrity or access issues.
RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint, allowing unauthenticated attackers to perform unauthorized administrative actions.
Combodo iTop is vulnerable to deserialization of untrusted data and code injection, potentially allowing authenticated users with low privileges to execute arbitrary code.
An unauthenticated OS command injection vulnerability in the parental control functionality of multiple TP-Link Archer routers allows remote attackers to execute arbitrary system commands.
Craft CMS contains a vulnerability involving improperly controlled modification of dynamically determined object attributes, which can be exploited by authenticated users to gain elevated privileges.
RansomLook fails to enforce privacy status for ransomware groups and markets when distributing victim posts, resulting in unauthorized data exposure.
The MasterStudy LMS plugin for WordPress contains an unauthenticated arbitrary file deletion vulnerability due to improper path traversal validation.
The WooCommerce File Approval plugin for WordPress is vulnerable to unauthenticated arbitrary file deletion caused by improper path traversal.
ShopBuilder Pro for Elementor contains an unauthenticated arbitrary file deletion vulnerability due to inadequate validation of user-supplied file paths.
A missing authorization vulnerability in SKYSEA Client View and SKYMEC IT Manager allows authenticated local users to perform unauthorized actions.
Incorrect default permissions in SKYSEA Client View and SKYMEC IT Manager allow authenticated local users to access or modify sensitive resources.
A stored OS command injection vulnerability in the parental control module of the TP-Link Archer BE3600 v1 allows an authenticated administrator to execute arbitrary commands on the underlying system.
A Server-Side Request Forgery (SSRF) vulnerability in Hi.Events allows authenticated users to trigger unauthorized requests to internal resources.
Grav CMS contains an improper link resolution vulnerability, allowing local attackers to perform file operations via symbolic link following.
RansomLook contains a Server-Side Request Forgery vulnerability in its PDF generation functionality, allowing authenticated administrators to trigger unauthorized requests.
RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts, potentially allowing unauthorized file access.
The Mercado Pago Node.js SDK is vulnerable to path traversal due to unencoded identifiers in payment clients, allowing unauthenticated remote attackers to access sensitive files.
Adminer versions prior to 5.4.3 are susceptible to arbitrary file deletion via SQLite database operations, allowing authenticated users to disrupt service integrity.
Grav versions before 2.0.16 are vulnerable to path traversal during file deletion operations within MediaUploadTrait, allowing authenticated users to access or remove unauthorized files.
Dolibarr is vulnerable to missing authorization and mass assignment within its members API, allowing authenticated users to modify object attributes.
The Dolibarr payments REST API contains an incorrect authorization vulnerability, allowing authenticated users to delete payment records they should not have access to.
TIM Flow is susceptible to HTTP Request/Response Splitting via the rt parameter, potentially allowing for cross-site scripting or cache poisoning attacks.
The Select-Themes Tonda WordPress theme is vulnerable to an unauthenticated local file inclusion flaw, allowing attackers to access unauthorized files.
The Elated-Themes Måne WordPress theme contains an unauthenticated local file inclusion vulnerability that permits unauthorized file access.
A cross-site scripting vulnerability in the Network Optix Nx Witness VMS web administration interface allows for malicious script execution.
NLTK versions before 3.10.3 are vulnerable to an untrusted search path flaw, which can lead to arbitrary code execution when processing malicious input.
Autodesk 3ds Max is susceptible to an out-of-bounds write vulnerability when parsing maliciously crafted ABC files, potentially leading to arbitrary code execution.
Autodesk 3ds Max is vulnerable to memory corruption when parsing malformed SVG files, which may allow an attacker to execute arbitrary code.
Autodesk 3ds Max is vulnerable to an out of bounds write when parsing a maliciously crafted FLT file, potentially leading to arbitrary code execution.
The flairNLP flair library contains a deserialization of untrusted data vulnerability in its clustering model, which can lead to arbitrary code execution.
Tuleap Enterprise Edition is vulnerable to a use of default password flaw, which may allow unauthorized users to gain administrative access to the platform.
The Grav Flex Objects plugin is vulnerable to a missing authorization flaw that allows authenticated users to access unauthorized data.
A vulnerability involving the use of hard-coded cryptographic keys in the mesh functionality of several TP-Link Deco models allows attackers to potentially compromise secure communications.
A server-side request forgery (SSRF) vulnerability exists in multiple AWX notification backends within the Red Hat Ansible Automation Platform.
The FURUNO FA-50 maritime AIS transponder is vulnerable to a missing authentication flaw that allows unauthorized modification of critical configurations.
Grav is vulnerable to a host header injection flaw, allowing unauthenticated attackers to manipulate email invitation targets due to reliance on insecure reverse DNS resolution.
The Grav login plugin is susceptible to timing attacks due to a non-constant time token comparison, which may allow unauthenticated attackers to infer valid security tokens.
Grav contains an information disclosure vulnerability within the Twig sandbox, allowing unauthenticated attackers to access restricted data through improper credential or sensitive information protection.
NLTK is vulnerable to a denial of service attack via XML entity expansion, which allows an unauthenticated attacker to exhaust system resources.
NLTK versions before 3.10.3 are susceptible to a server-side request forgery (SSRF) vulnerability, enabling unauthenticated attackers to potentially access internal resources.
SAP S/4HANA (Private Cloud) utilizes a third-party component susceptible to a Regular Expression Denial of Service (ReDoS) vulnerability, potentially impacting service availability.
The SiteLeads WordPress plugin is vulnerable to unauthenticated sensitive data exposure, allowing unauthorized access to system information via the plugin's interface.
Multiple DrayTek VigorSwitch models are susceptible to a pre-authentication null pointer dereference vulnerability, potentially causing a denial of service.
HCL Hive version 1.0 is affected by incorrect default permissions, potentially enabling lateral movement, container breakout, and the interception of sensitive communications.
HCL Hive is vulnerable to the use of unmaintained third-party components, potentially allowing unauthenticated attackers to gain unauthorized access or compromise the system.
The Black Duck blackduck-c-cpp package manager is susceptible to OS command injection, potentially allowing local attackers to execute arbitrary commands on the host system.
A race condition in the Linux kernel cryptographic socket interface (algif_skcipher) allows local users to perform information disclosure by manipulating initialization vectors during processing.