CVE-2026-72529
TrueConf Server contains a vulnerability involving missing authentication for critical functions, which allows unauthorized remote attackers to perform sensitive actions.
Critical vulnerabilities, curated daily for security professionals
Enterprise application platforms dominated yesterday's disclosures, with Adobe Campaign Classic, Apache Hive, and Oracle WebLogic all carrying remotely exploitable flaws that reach core business systems. The day recorded 35 critical CVEs (CVSS 9.0+) and 65 high-priority CVEs, down 35% and 32% respectively from the prior day. Adobe Campaign Classic drew two CVSS 10.0 issues (CVE-2026-76193 and CVE-2026-76195), while CVE-2026-77998 (CVSS 10.0) affects miniOrange SAML SSO for Joomla and CVE-2026-49845 (CVSS 9.8) affects Apache Hive. Remote code execution and authentication bypass dominate the pattern, with additional exposure across web publishing stacks (Avada Fusion Builder, ClipBucket) and developer tooling (Chainlit, nokogiri); six CVEs, including flaws in Zimbra Collaboration, Oracle WebLogic Server Proxy Plug-in, Gitea, and MLflow, have confirmed active exploitation. Patch availability data was not confirmed for any of the 100 CVEs at publication, so teams should verify vendor advisories directly rather than assume fixes are staged.
Immediate action: Prioritize internet-facing Adobe Campaign Classic, Oracle WebLogic (including the Proxy Plug-in), Apache Hive, and Zimbra Collaboration deployments, followed by Joomla sites running miniOrange SAML SSO and WordPress installs using Avada Fusion Builder. Google Chrome should be updated to the current stable channel to address CVE-2026-78909 and CVE-2026-18015. No patch status was confirmed for these CVEs at publication, so check each vendor advisory for fixed versions and apply interim mitigations or access restrictions where updates are not yet available.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
TrueConf Server contains a vulnerability involving missing authentication for critical functions, which allows unauthorized remote attackers to perform sensitive actions.
Zimbra Collaboration (ZCS) is susceptible to remote code execution due to improper neutralization of OS commands.
An unauthenticated remote code execution vulnerability exists in Oracle WebLogic Server Proxy Plug-ins for Apache HTTP Server and IIS, potentially leading to a full system compromise.
A critical remote code execution vulnerability exists in Gitea's diffpatch feature that allows an attacker to execute arbitrary shell commands.
MLflow contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to reach internal services due to improper validation of redirected URLs.
TrueConf Server is affected by a code injection vulnerability that allows attackers to execute arbitrary code and escape isolated environments.
A SQL injection vulnerability in the Apache Hive Metastore allows authenticated users to manipulate partition metadata and interfere with cache operations via crafted partition names.
An authentication bypass vulnerability in multiple miniOrange Joomla extensions allows unauthenticated attackers to log in as arbitrary users, including administrators, via malformed SAML responses.
An arbitrary file write vulnerability in the Avada theme and Fusion Builder plugin for WordPress allows unauthenticated attackers to achieve remote code execution and full site compromise.
Chainlit versions 2.4.0rc0 through 2.11.x are vulnerable to unauthenticated OS command injection via the MCP endpoint when features.mcp.enabled is true.
Nokogiri is affected by a use-after-free vulnerability in the xmlTextReader module when processing crafted XML documents with DTD validation and XInclude expansion enabled.
A use-after-free vulnerability in Google Chrome allows remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page.
ClipBucket V5 contains an unauthenticated OS command injection vulnerability in the web installer due to improper validation of the php_cli_filepath parameter.
Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Adobe Campaign Classic is vulnerable to a Server-Side Request Forgery (SSRF) flaw, which allows unauthenticated remote attackers to achieve arbitrary code execution.
Adobe Campaign Classic is affected by an OS Command Injection vulnerability that permits unauthenticated remote attackers to execute arbitrary code on the underlying host.
Adobe Campaign Classic is vulnerable to an OS Command Injection, allowing unauthenticated attackers to execute arbitrary code on the host system.
NLTK before 3.10.3 contains an argument injection vulnerability in the java() function, allowing unauthenticated attackers to execute arbitrary code via malicious JVM flag injection.
The Total Donations plugin for WordPress is vulnerable to unauthenticated privilege escalation, allowing remote attackers to gain administrative access.
A remote code execution vulnerability in Halo 2.25.4 exists due to insecure handling of plugin artifacts and insufficient validation of external plugin sources.
The TranslatePress plugin for WordPress is vulnerable to sensitive information exposure via an AJAX action, allowing unauthenticated attackers to steal administrator password-reset URLs.
DB-GPT contains a path traversal vulnerability in the skill upload function, allowing unauthenticated remote attackers to write arbitrary files and achieve remote code execution.
PbootCMS v.3.2.15 contains an arbitrary code execution vulnerability in multiple controller files, allowing unauthenticated attackers to compromise the server.
The TOTOLINK N600R router contains a stack-based buffer overflow in the setSystemConfig function, allowing remote attackers to execute arbitrary code via a crafted Hostname parameter.
The nokogiri gem contains outdated libxml2 and libxslt libraries, exposing applications to denial of service, memory disclosure, or remote code execution when parsing untrusted XML or XSL documents.
NLTK versions before 3.10.3 are vulnerable to remote code execution due to unsafe pickle deserialization of untrusted data in allowlisted loaders.
QWED-MCP versions prior to 0.2.1 contain a code injection vulnerability in the math engine that allows arbitrary command execution via unsanitized input to the verify_math_expression function.
NVIDIA OpenShell for Linux contains a sandbox provisioning vulnerability where an incomplete list of disallowed inputs allows for potential code execution and privilege escalation.
Thinking Software Technology EFence is vulnerable to arbitrary file upload, allowing unauthenticated attackers to execute web shells and gain remote code execution.
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4, allowing unauthenticated attackers to impersonate any user and perform unauthorized read, write, or delete operations.
An unrestricted file upload vulnerability in TRtek Software Repository Management allows remote attackers to upload web shells and execute arbitrary code.
Nokogiri contains stack buffer overflow and use-after-free vulnerabilities in libxml2, which can be triggered by malicious XML content to cause denial of service or code execution.
Apache SkyWalking MCP contains a critical vulnerability combining Server-Side Request Forgery and GraphQL expression injection.
A sandbox escape vulnerability in NVIDIA OpenShell for Linux allows attackers with low privileges to execute arbitrary code, escalate privileges, and disclose sensitive information.
An OS command injection vulnerability in the web management interface of Weidmueller IE-SR-2TX-WL devices allows unauthenticated attackers to execute arbitrary commands with root privileges.
A heap-based out-of-bounds write in S2OPC 1.7.3 during EventFilter handling allows remote, unauthenticated attackers to execute arbitrary code.
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT sessi
A security flaw in Net::OAuth::Client allows service providers to silently downgrade OAuth 1.0a to the less secure OAuth 1.0 protocol.
A Server-Side Template Injection (SSTI) vulnerability in the xdocreport Velocity template engine configuration allows unauthenticated remote attackers to execute arbitrary code.
An information disclosure vulnerability in the Mahara Text block functionality allows unauthorized users to recall sensitive backed-up content from other sections.
A privilege escalation vulnerability in Trueview T18061 WiFi 3MP security cameras allows physically proximate attackers to compromise the device via an exposed RSA private key.
Use after free in Audio in Google Chrome on Mac prior to 151.
A use-after-free vulnerability in the V8 JavaScript engine of Google Chrome allows a remote attacker to trigger memory corruption and potentially execute arbitrary code via a crafted webpage.
A use after free vulnerability exists in the DevTools component of Google Chrome, potentially allowing for arbitrary code execution.
A use after free vulnerability exists in the Compositing component of Google Chrome, which may lead to memory corruption or arbitrary code execution.
A use after free vulnerability in the V8 JavaScript engine of Google Chrome may allow an unauthenticated attacker to execute arbitrary code.
A use after free vulnerability exists in the PDF rendering component of Google Chrome, potentially allowing for arbitrary code execution or system compromise.
A use after free vulnerability in the WebRTC implementation of Google Chrome could allow a remote attacker to execute arbitrary code.
A use after free vulnerability in the Scripting engine of Google Chrome allows for potential remote code execution by an unauthenticated attacker.
A use after free vulnerability exists in the V8 engine of Google Chrome, which could allow a remote attacker to execute arbitrary code.
A use after free vulnerability exists in the Platform component of Google Chrome, which could allow a remote attacker to execute arbitrary code.
A use after free vulnerability exists in the Chromecast component of Google Chrome, which could allow a remote attacker to execute arbitrary code.
A use after free vulnerability exists in the Animation component of Google Chrome, which could allow a remote attacker to trigger memory corruption.
A use after free vulnerability in the DevTools component of Google Chrome could allow an attacker to trigger memory corruption through a malicious web page.
An insecure PIN derivation mechanism in Admin By Request allows a low-privileged user to escalate privileges to administrator by masquerading as an Apple-signed process via XPC.
Airbyte Platform is vulnerable to an authorization bypass where the system resolves workspace authorization based on a user-controlled field in the request.
A missing authorization vulnerability in the PraisonAI multi-agent system allows unauthenticated remote attackers to perform unauthorized actions, leading to potential integrity and availability loss.
A missing authentication vulnerability in PraisonAI allows unauthenticated remote attackers to access critical functions, potentially leading to unauthorized data disclosure and service disruption.
PraisonAI is affected by a missing authentication vulnerability allowing unauthorized access to critical functions, potentially leading to unauthorized system actions.
Out of bounds read in WebXR in Google Chrome prior to 151.
PraisonAI is vulnerable to Server-Side Request Forgery (SSRF) and reliance on insecure reverse DNS resolution, which may allow authenticated attackers to perform unauthorized network actions.
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection in the archive restore functionality, allowing authenticated users to execute arbitrary SQL commands.
Race in Updater in Google Chrome on Mac prior to 151.
The Mang Board WP plugin for WordPress contains an improper privilege management vulnerability, allowing authenticated users to forge authentication cookies and potentially escalate privileges.
Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.
Type Confusion in V8 in Google Chrome prior to 151.
Mesop is vulnerable to uncontrolled resource consumption and excessive iteration, which can be triggered by unauthenticated users to cause a denial of service.
An incorrect authorization vulnerability in Apache DolphinScheduler allows authenticated users to generate administrative access tokens via the /access-tokens endpoint.
Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.
NVIDIA OpenShell contains an OS command injection vulnerability triggered by a malicious gateway, which could allow arbitrary code execution.
Cloud Foundry UAA contains an authorization bypass vulnerability due to improper handling of case sensitivity in identity zone endpoints.
The Codefresh platform contains a privilege escalation vulnerability where an authenticated user can leverage an API endpoint to gain administrative permissions.
A Server-Side Request Forgery (SSRF) vulnerability in JFrog Artifactory allows authenticated users to manipulate VCS repository configurations and data URLs.
An arbitrary file upload vulnerability exists in Thinking Software Technology Efence, allowing authenticated users to upload malicious files to the server.
A missing authorization vulnerability in Kimai before 2.62.0 allows authenticated users to bypass access controls via the quick entry feature.
Kimai is vulnerable to an authorization bypass flaw, allowing unauthenticated attackers to perform unauthorized actions due to incorrect authorization checks.
The genieacs-mcp server for GenieACS is vulnerable to an origin validation error, which can be exploited by remote attackers to perform unauthorized actions.
QWED-AI qwed-verification is susceptible to code injection, allowing authenticated users with low privileges to execute arbitrary code within the verification infrastructure.
NVIDIA UFM Enterprise contains an improper authentication vulnerability in the web interface authorization component that can be triggered via specially crafted HTTP requests.
The Vocos library is vulnerable to unsafe reflection, allowing arbitrary class instantiation via configuration files without proper validation.
Crater Invoice through version 6.0.6 contains a path traversal vulnerability in the update unzip endpoint, which can be leveraged to achieve remote code execution.
The lin-snow Ech0 application suffers from a missing authorization vulnerability that allows authenticated users to access or modify data beyond their intended privileges.
The TYPO3 Club Directory extension fails to perform ownership checks when processing frontend requests, allowing unauthorized users to modify club records.
The TYPO3 Industry Directory extension relies solely on client-side visibility flags, failing to enforce server-side ownership checks during company record updates.
The TYPO3 Forum extension fails to perform server-side authorization checks during frontend topic editing, allowing unauthenticated visitors to modify topics they do not own.
A vulnerability in the Faktory background job server, caused by an uncaught exception, can lead to a denial of service condition.
The Typebot chatbot builder is vulnerable to unauthorized information exposure and path manipulation, potentially allowing attackers to access sensitive data.
A denial-of-service vulnerability exists in the internal JPEG2000 (JPX) decoding implementation of the Innodata Labs Poppler fork due to uncontrolled resource consumption.
The TYPO3 Telephone Directory extension fails to validate HMAC tokens during the data persistence phase, allowing unauthorized modifications to employee records.
The Virtualization Discovery module in LibreNMS is susceptible to OS command injection, allowing authenticated users with high privileges to execute arbitrary commands on the host system.
Compliance-trestle suffers from an incomplete list of disallowed inputs and server-side request forgery (SSRF) vulnerabilities, potentially allowing unauthorized data access or internal resource interaction.
The browse-mcp server contains a path traversal vulnerability that could allow an unauthenticated attacker to access unauthorized files on the host system.
The mcp-shell server is susceptible to OS command injection, which could allow an attacker to execute arbitrary commands on the underlying host.
Nokogiri versions before 1.13.5 contain a memory corruption vulnerability due to an integer overflow in the underlying libxml2 library.
Weidmueller IE-SR-2TX-WL-4G devices contain an authentication bypass vulnerability in the SMS control function, which can be triggered despite the Enable Password Authorization setting.
NVIDIA OpenShell Sandbox for Linux contains a path traversal vulnerability that allows an authenticated attacker to bypass L7 REST network policies.
CorvusSKK is vulnerable to code injection, which may allow an attacker to execute arbitrary code on the host system.
The mcp-shell server is susceptible to OS command injection and insecure resource initialization, potentially allowing unauthorized command execution.
The mcp-shell server contains an OS command injection vulnerability, which may allow an attacker to execute arbitrary commands on the underlying system.
A protection mechanism failure in Winter CMS allows for a Twig sandbox escape via the security policy settings.
A command injection vulnerability exists in the TOTOLINK N600R router, allowing unauthenticated attackers to execute arbitrary commands via the device interface.
An authorization bypass in the TYPO3 femanager extension allows unauthorized users to self-approve accounts by exploiting a predictable confirmation hash.
A flaw in the TYPO3 femanager extension invitation controller allows unauthenticated attackers to hijack and re-enable arbitrary frontend user accounts by manipulating input hashes.
Full details and mitigation steps are currently restricted and will be published at a later date.
Full details and mitigation steps are currently restricted and will be published at a later date.
A sandbox bypass vulnerability in O2OA v.10.0.2 allows local attackers to execute arbitrary code via the Invoke script mechanism.