CVE-2026-21962
An unauthenticated remote code execution vulnerability exists in Oracle WebLogic Server Proxy Plug-ins for Apache HTTP Server and IIS, potentially leading to a full system compromise.
Critical vulnerabilities, curated daily for security professionals
Yesterday's disclosures center on two clusters: unauthenticated remote code execution in enterprise platforms (ServiceNow AI Platform, Redis, Bytedance UI-TARS-desktop) and a large batch of WordPress plugin vulnerabilities affecting Tutor LMS, Hash Form, Geo Controller, ACPT and the WPMU DEV Dashboard. Volume dropped sharply from the prior day: 27 critical CVEs (down 76% from 114) and 77 high-priority CVEs (down 46% from 143), for 104 total. CVE-2026-74820 (CVSS 10, ServiceNow AI Platform) and CVE-2026-81735 (CVSS 10, Bytedance UI-TARS-desktop) sit at the top of the list, alongside CVE-2026-81934 (CVSS 9.8) in Redis and CVE-2026-74232 (CVSS 9.8) spanning more than a dozen Zbtlink router models. The pattern is heavily weighted toward pre-authentication code execution and access-control failures in internet-facing components, which puts hosting providers, SaaS operators and small-business web estates in the primary blast radius. Patch data is unavailable for the current set (0% confirmed), so treat vendor advisories as the authoritative source and prioritize exposure reduction where fixes are not yet published; 11 CVEs carry confirmed active exploitation, including Oracle WebLogic Server Proxy Plug-in, Gitea, NetScaler ADC and Gateway, and JFrog Artifactory.
Immediate action: Prioritize internet-facing enterprise systems first: NetScaler ADC and Gateway, Oracle WebLogic, Gitea, JFrog Artifactory and ServiceNow AI Platform, followed by Redis instances reachable from untrusted networks and WordPress estates running Tutor LMS, Hash Form, Geo Controller, ACPT or the WPMU DEV Dashboard. No patch availability is confirmed for this set, so verify fix status against each vendor advisory rather than assuming updates exist. Where no fix is published, restrict network exposure, tighten authentication and monitor for exploitation of the actively targeted CVEs.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An unauthenticated remote code execution vulnerability exists in Oracle WebLogic Server Proxy Plug-ins for Apache HTTP Server and IIS, potentially leading to a full system compromise.
A critical remote code execution vulnerability exists in Gitea's diffpatch feature that allows an attacker to execute arbitrary shell commands.
A memory overflow vulnerability in NetScaler ADC and Gateway appliances configured as SSL VPN, ICA, or AAA servers may lead to service disruption or Denial of Service (DoS).
A remote code execution vulnerability exists in Microsoft SQL Server due to improper handling of internal functions, allowing authenticated attackers to execute arbitrary code.
An authentication bypass in ownCloud core allows unauthenticated attackers to access, modify, or delete files if the victim username is known and no signing key is configured.
An improper memory calculation vulnerability exists in the Linux kernel's IPv6 paged-allocation path, potentially leading to memory corruption.
Ajax.NET Professional is vulnerable to deserialization of untrusted data, which can be exploited by unauthenticated attackers to achieve remote code execution.
A race condition in the Red Hat Libuser userhelper program allows local users to cause a denial of service by corrupting the system password file.
The ABRT tool contains a local privilege escalation vulnerability via symlink attacks on predictable file names in /var/tmp or /var/spool, allowing authenticated local users to gain root privileges.
A critical out-of-bounds memory write vulnerability exists in the Linux kernel watch_queue event notification subsystem, allowing local users to gain elevated privileges or cause a system crash.
An authenticated user can perform path traversal to write data outside the intended Docker cache directory in JFrog Artifactory due to improper input validation.
The Tutor LMS WordPress plugin before 4.0.6 is vulnerable to an injection flaw allowing unauthenticated users to execute arbitrary zero-argument PHP functions and capture the resulting output.
The jahlives openssl_encrypt library fails to sanitize email fields, allowing attackers to inject ANSI escape sequences to forge identity fingerprints and bypass verification.
Redis contains a use-after-free vulnerability in the tlsProcessPendingData function that allows remote, unauthenticated attackers to execute arbitrary commands.
A SQL injection vulnerability in the ServiceNow AI platform allows unauthenticated remote attackers to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification.
An unauthenticated PHP object injection vulnerability in the Geo Controller plugin allows remote attackers to execute arbitrary code via deserialization of untrusted data.
The Hash Form WordPress plugin is vulnerable to unauthenticated PHP object injection, allowing remote attackers to execute arbitrary code.
The WPMU DEV Dashboard plugin for WordPress contains an authentication bypass vulnerability due to improper HMAC signature verification in its SSO AJAX actions.
A critical privilege escalation vulnerability in the ACPT (Pro) WordPress plugin allows unauthenticated attackers to gain unauthorized administrative access.
Multiple Zbtlink and MoreQuick devices contain a hardcoded backdoor command-and-control implant (yunmgrd) that allows unauthenticated remote attackers to execute arbitrary commands as root.
The mcp-http-server component in UI-TARS-desktop defaults to listening on all interfaces without authentication, enabling unauthenticated remote command execution via the commands server.
The openssl_encrypt library fails to properly validate GPG signatures, allowing revoked or expired keys to be treated as valid, which can lead to the execution of malicious plugins.
A signature verification bypass in jahlives openssl_encrypt allows unauthenticated attackers to execute arbitrary code by loading malicious plugins.
The jahlives openssl_encrypt library fails to validate identity fingerprints upon loading, allowing unauthenticated attackers to perform silent public key substitution.
ToolUniverse versions 1.2.6 and earlier contain a critical sandbox escape vulnerability allowing unauthenticated remote code execution via the Python code executor and insecure API server configurations.
Green-Computing NUMail contains an OS command injection vulnerability that allows unauthenticated remote attackers to execute arbitrary system commands on the server.
The web management interface of Ebyte NE2-D11 firmware fails to enforce authentication, allowing unauthenticated remote attackers to modify device settings or disrupt availability.
A vulnerability in Ebyte NE2-D11 firmware allows unauthenticated attackers to steal and reuse session tokens to gain unauthorized administrative access to the device management interface.
The Xiiaozet LK100W device contains an authentication bypass vulnerability, allowing unauthenticated remote attackers to enable restricted administrative services.
Multiple Zbtlink router models contain an unauthenticated command injection vulnerability in the infosrvd service via UDP port 9992, allowing remote code execution as root.
An improper access control vulnerability in the ServiceNow AI platform allows unauthenticated users to create or modify instance data, potentially leading to full privilege escalation.
A code injection vulnerability in the ServiceNow AI Platform allows unauthenticated attackers to execute arbitrary code and modify instance data.
The Ebyte NE2-D11 firmware transmits MQTT credentials and control traffic in cleartext, which allows unauthenticated network attackers to intercept sensitive data and impersonate devices.
Ebyte NE2-D11 firmware contains an authentication bypass vulnerability due to the use of insecure client-side logic, allowing unauthenticated attackers to gain administrative access.
The Xiiaozet LK100W administrative service contains an authentication weakness that allows unauthenticated attackers to bypass access controls and achieve remote command execution.
An unauthenticated SSRF and RCE vulnerability exists in Spring MVC applications using XsltView with specific wildcard view rendering configurations.
Spring MVC and WebFlux applications are susceptible to stream corruption via CRLF injection when utilizing Server-Sent Events with view fragments.
The Spring WebFlux component fails to enforce memory limits when using the Aalto XML processor, allowing for potential resource exhaustion.
The MongoDB PHP client library and extension fail to sanitize namespace identifiers, allowing attackers with low privileges to redirect database operations to unintended storage locations.
Dolibarr before 24.0.0 contains a SQL injection vulnerability in its CSV and XLSX import wizard due to improper sanitization of update keys.
An unauthenticated HTTP/2 peer can trigger an out-of-memory denial of service in the http4s Ember backend due to improper handling of compressed HPACK header data.
A SQL injection vulnerability in the iSquad /ws/apitribuna/ultimosVideos endpoint allows unauthenticated attackers to manipulate database queries via the limit_videos parameter.
The iSquad /ws/apiprensa/getVideo endpoint is vulnerable to unauthenticated SQL injection via the id_ambito parameter, allowing potential database information disclosure.
A memory boundary validation error in WibuKey64.sys allows local attackers with low privileges to potentially achieve remote code execution, privilege escalation, or denial of service.
The wallabag Android application through 2.6.0 is vulnerable to Cross-site Scripting (XSS) due to insecure handling of /api/entries data within a WebView component.
A cryptographic flaw in the Ceph RADOS Gateway allows authenticated users to tamper with STS session tokens via CBC bit-flipping, resulting in a full administrative privilege escalation.
A Server-Side Request Forgery vulnerability in the GitLab AI Gateway allows authenticated users with Duo Agent Platform access to redirect model requests and disclose cloud service credentials.
A Server-Side Request Forgery vulnerability in the GitLab AI Gateway allows authenticated users to redirect model requests and disclose sensitive Google Cloud Vertex credentials and signing keys.
A kernel driver vulnerability in WibuKey for Windows allows local users to achieve privilege escalation via an untrusted pointer dereference leading to a write-what-where primitive.
The Workeera WordPress plugin contains an unrestricted file upload vulnerability that allows authenticated subscribers to achieve remote code execution on the underlying server.
An improper template neutralization flaw in Trilium allows unauthenticated attackers to achieve remote code execution via malicious import archives.
The CephX authentication protocol uses vulnerable encryption methods and lacks message authentication, enabling attackers to forge credentials and escalate privileges within the storage cluster.
An authenticated OS command injection vulnerability in ZoneMinder allows users with View Events permission to execute arbitrary system commands via the exportFile parameter.
SpeechBrain versions prior to 1.1.1 are vulnerable to arbitrary code execution via unsafe YAML deserialization in the Checkpointer component.
The Booking and Rental Manager plugin for WordPress is vulnerable to PHP object injection, allowing authenticated contributors to execute arbitrary code.
Dolibarr versions 9.0.0 through 23.0.4 are vulnerable to path traversal via the EmailCollector module, allowing unauthenticated attackers to write files to arbitrary locations on the server.
APITable fails to enforce authentication on internal user management endpoints, allowing unauthenticated attackers to enumerate and permanently close accounts in a cooling-off period.
A vulnerability in Apache APISIX allows unauthenticated attackers to cause a denial of service by sending specific requests that pin a gateway worker to 100% CPU usage via graphql-limit-count routes.
A SQL injection vulnerability in the ACPT (Pro) plugin for WordPress allows authenticated subscribers to execute arbitrary database queries via improper input neutralization.
The 12 Step Meeting List plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to improper sanitization of user-submitted data stored in activity logs.
A vulnerability in the MongoDB C++ Driver allows attackers to manipulate namespace identifiers, potentially leading to unauthorized data access across logical tenants.
A vulnerability in the Silicon Labs BT Mesh SDK allows remote code execution via malformed extended advertisements, requiring an already joined device to trigger.
The Unitree G1 EDU firmware contains an unauthenticated remote code execution vulnerability via a chain of three flaws in the WebRTC-to-DDS bridge, AES key management, and chat_go API.
A stack-based buffer overflow in Greenbone OS allows an authenticated remote attacker to execute arbitrary code with full system privileges via a malicious NASL vulnerability test.
A stack-based buffer overflow in the WatchGuard Fireware OS iked process allows remote unauthenticated attackers to cause a Denial of Service condition in VPN processing.
Flowintel contains a code injection vulnerability where improperly sanitized configuration keys allow attackers to execute arbitrary Python code via the alerts settings update endpoint.
A buffer overflow vulnerability exists in the Linux kernel s390 qeth driver's SNMP and ARP query ioctls, allowing local attackers to trigger memory corruption via crafted user-supplied buffer lengths.
The PayRange API lacks proper authorization on management endpoints, allowing unauthorized access to sensitive device details, configuration modifications, and potential denial of service.
The Ebyte NE2-D11 web management interface is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to trigger unauthorized configuration changes or service disruptions.
A remote unauthenticated integer underflow vulnerability in the WatchGuard Fireware OS iked process allows attackers to trigger a Denial of Service condition in VPN processing.
A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to trigger a Denial of Service condition in VPN processing.
An out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process allows remote unauthenticated attackers to trigger a denial of service in VPN processing via crafted network traffic.
A remote, unauthenticated out-of-bounds read vulnerability in the WatchGuard Fireware OS iked process enables attackers to trigger a Denial of Service condition in VPN processing.
An integer underflow in WatchGuard Fireware OS allows remote unauthenticated attackers to trigger a Denial of Service condition in VPN processing via crafted network traffic.
The mcp-use inspector proxy middleware fails to validate destination hostnames, allowing unauthenticated attackers to perform Server-Side Request Forgery (SSRF) against internal network resources.
Flowintel contains an authorization flaw in the administrative user-edit API that allows an organization administrator to modify or reset the password of a full administrator account.
CodeMeter Runtime fails to enforce network origin restrictions for configuration commands, allowing unauthenticated remote attackers to read sensitive data and overwrite the Server.ini configuration.
The bestzip library fails to properly delimit command arguments, allowing attackers to inject arbitrary commands via crafted file paths passed to the underlying zip utility.
CodeMeter Runtime is vulnerable to a format string injection flaw, allowing unauthenticated remote attackers to crash the service or disclose sensitive process memory and stack canaries.
The ip-customblock active response script in Wazuh is vulnerable to path traversal, allowing authenticated attackers to create or delete arbitrary files on the filesystem with root privileges.
The Ceph Object Gateway fails to properly validate SigV4 header signatures, allowing attackers to inject unauthorized x-amz-* headers into presigned URLs to escalate privileges.
An authentication bypass vulnerability in the Ebyte NE2-D11 configuration utility allows unauthenticated attackers to perform disruptive administrative actions.
A buffer overflow in the WatchGuard Fireware OS Management Web UI allows an authenticated administrator to trigger a denial of service or arbitrary code execution via crafted network traffic.
WatchGuard Dimension contains an authenticated SQL injection vulnerability in the scheduled report feature that allows users with report administration permissions to achieve arbitrary command execution.
WatchGuard Dimension is vulnerable to an authenticated SQL injection in the log viewer, allowing an attacker with administrative permissions to execute arbitrary commands as the WebUI process user.
WatchGuard Dimension is vulnerable to an authenticated SQL injection in the audit report feature, allowing an attacker with report administration permissions to achieve arbitrary command execution.
The Kadence Shop Kit WordPress plugin contains an SQL injection vulnerability allowing authenticated subscribers to execute arbitrary database queries.
A SQL injection vulnerability exists in the Like Button Rating plugin for WordPress, allowing authenticated subscribers to execute arbitrary SQL commands.
A SQL injection vulnerability in the VillaTheme Suggestion Engine for WooCommerce plugin allows authenticated contributors to execute arbitrary SQL commands.
The execute_ruby tool in rails-mcp-server fails to properly sanitize process-spawning methods, allowing attackers to escape the sandbox and execute arbitrary OS commands.
The openssl_encrypt pip package improperly stores mTLS client private keys in a world-readable file, allowing local attackers to access sensitive credentials.
A use-after-free vulnerability in the cpp-httplib TLS-enabled WebSocket client allows attackers to trigger memory corruption during secure connection teardown.
The Xiiaozet LK100W web-based management interface is susceptible to OS command injection, allowing authenticated attackers to execute arbitrary commands on the underlying operating system.
A code injection vulnerability in the Silverstripe UserForms module allows authenticated CMS users with specific permissions to execute arbitrary server-side code via the email recipient subject field.
An unauthenticated Cross-Site Request Forgery (CSRF) vulnerability exists in the GeoDirectory WordPress plugin, allowing attackers to perform unauthorized actions on behalf of users.
WatchGuard Dimension is vulnerable to a denial-of-service attack, where an unauthenticated attacker can flood the log listening service with TCP SYN packets to disrupt availability.
A sandbox escape vulnerability in the ServiceNow Now Platform allows attackers to execute arbitrary code. The flaw impacts multiple versions and requires immediate remediation.
A Twig sandbox configuration flaw in Craft CMS allows authenticated attackers to perform arbitrary code execution via the Yii framework.
A critical broken access control vulnerability exists in the Mobile App for WooCommerce plugin, allowing unauthenticated attackers to bypass authorization checks.
WatchGuard Dimension contains a cross-site request forgery vulnerability in the Web UI, allowing an attacker to change an administrator passphrase via a crafted link.
LimeSurvey 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page, allowing authenticated users to inject malicious scripts into HTML attributes.
A heap-based buffer overflow in the Linux kernel XFS filesystem driver allows local attackers to cause memory corruption via a crafted filesystem image during log recovery.
A memory safety vulnerability exists in the Linux kernel Focaltech input driver where an integer underflow leads to an out of bounds write in the focaltech_process_rel_packet function.
A missing authorization vulnerability in go-wind-cms before 1.0.0 allows any authenticated user to perform administrative actions such as deleting users or resetting passwords.
openNDS prior to 11.0.0 is vulnerable to unauthenticated OS command injection via the fas query parameter on the /opennds_preauth/ endpoint.
Spring Authorization Server fails to encode user-controlled input on its default consent page, enabling a stored cross-site scripting (XSS) attack via crafted OAuth2 authorization requests.
A race condition in Spring Integration's .fluxTransform() allows concurrent requests to leak reply headers, resulting in misrouted responses and cross-message header exposure.
A cross-site scripting vulnerability exists in the Spring Security Authorization Server due to improper encoding of user-controlled input on the default consent page.
A locking inconsistency in the Linux kernel s390 vfio_ccw driver allows for potential resource management errors during asynchronous device failure.
An improper access control vulnerability in the Ubiquiti UniFi Connect Application allows a network-adjacent attacker to perform unauthorized privilege escalation.
The OpenRGB network protocol is vulnerable to memory exhaustion and out-of-bounds memory access due to improper validation of inconsistent input data.
The get-html-skeleton tool in Apify actors-mcp-server is vulnerable to Server-Side Request Forgery (SSRF) by failing to validate the host of user-supplied URLs.
FluentBooking Pro is vulnerable to unauthenticated Cross Site Request Forgery (CSRF), allowing an attacker to perform unauthorized actions on behalf of a user.
A path authorization flaw in the SeaweedFS SFTP server allows authenticated users to bypass directory restrictions and access sibling directories via improper string-prefix comparison.
Trilium versions prior to 0.104.0 contain a vulnerability in the automatic image-download feature that allows authenticated users to read arbitrary local files or cause a server denial of service.