CVE-2026-21962
An unauthenticated remote code execution vulnerability exists in Oracle WebLogic Server Proxy Plug-ins for Apache HTTP Server and IIS, potentially leading to a full system compromise.
Critical vulnerabilities, curated daily for security professionals
Enterprise content and print management platforms drove the day's most severe disclosures, with CVE-2026-55634 in Pimcore (CVSS 9.9) and CVE-2026-82078 in PaperCut MF/NG (CVSS 9.4) exposing widely deployed business systems to remote compromise. Yesterday's disclosures produced 42 critical CVEs, up 56% from the prior day's 27, alongside 66 high-priority issues, down 14% from 77. Mission-critical and telecom infrastructure also featured prominently: CVE-2026-55565 and CVE-2026-55559 affect the Yamcs mission control platform (CVSS 9.9 and 9.8), CVE-2026-55068 affects the free5gc 5G core (CVSS 9.3), and CVE-2026-66906 affects Apache Camel (CVSS 9.1). Linux kernel flaws CVE-2026-80630 and CVE-2026-80612 (both CVSS 9.8) extend the exposure to Linux fleets broadly, while 11 CVEs including Oracle WebLogic Server Proxy Plug-in, Gitea, and NetScaler ADC and Gateway carry confirmed active exploitation. Vendor patch data was unavailable for these entries at publication, so teams should verify fixed versions directly with vendor advisories and prioritize internet-facing systems first.
Immediate action: Prioritize internet-facing Oracle WebLogic, NetScaler ADC and Gateway, Gitea, and JFrog Artifactory instances given confirmed exploitation, then address Pimcore, PaperCut MF/NG, Apache Camel, and Linux kernel systems carrying CVSS 9.0+ issues. Patch availability is recorded at 0% in the collected data, so confirm fixed versions and interim mitigations directly against vendor advisories rather than assuming no fix exists. Where no patch is confirmed, restrict network exposure of the affected services and increase monitoring on the actively exploited products.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An unauthenticated remote code execution vulnerability exists in Oracle WebLogic Server Proxy Plug-ins for Apache HTTP Server and IIS, potentially leading to a full system compromise.
A critical remote code execution vulnerability exists in Gitea's diffpatch feature that allows an attacker to execute arbitrary shell commands.
A memory overflow vulnerability in NetScaler ADC and Gateway appliances configured as SSL VPN, ICA, or AAA servers may lead to service disruption or Denial of Service (DoS).
A remote code execution vulnerability exists in Microsoft SQL Server due to improper handling of internal functions, allowing authenticated attackers to execute arbitrary code.
An authentication bypass in ownCloud core allows unauthenticated attackers to access, modify, or delete files if the victim username is known and no signing key is configured.
An improper memory calculation vulnerability exists in the Linux kernel's IPv6 paged-allocation path, potentially leading to memory corruption.
Ajax.NET Professional is vulnerable to deserialization of untrusted data, which can be exploited by unauthenticated attackers to achieve remote code execution.
A race condition in the Red Hat Libuser userhelper program allows local users to cause a denial of service by corrupting the system password file.
The ABRT tool contains a local privilege escalation vulnerability via symlink attacks on predictable file names in /var/tmp or /var/spool, allowing authenticated local users to gain root privileges.
A critical out-of-bounds memory write vulnerability exists in the Linux kernel watch_queue event notification subsystem, allowing local users to gain elevated privileges or cause a system crash.
An authenticated user can perform path traversal to write data outside the intended Docker cache directory in JFrog Artifactory due to improper input validation.
An authenticated code and SQL injection vulnerability exists in the Pimcore class definition import endpoint, allowing attackers to execute arbitrary PHP code and manipulate database schemas.
A race condition in the Linux kernel sch_fq_codel component leads to improper backlog tracking, potentially causing a general protection fault and wild memory access.
An improper input validation vulnerability in the NRF RegisterNFInstance handler allows unauthenticated attackers to register malicious NF profiles, enabling control-plane signaling redirection.
A relative path traversal vulnerability in the Apache Camel Azure Storage Blob component allows unauthenticated attackers to write files to arbitrary locations on the local filesystem.
Yamcs is vulnerable to code injection via unescaped LIKE patterns in SQL queries, allowing authenticated users to execute arbitrary Java code on the server.
Yamcs is vulnerable to code injection via improper YAML context escaping in template arguments, allowing unauthenticated or privileged attackers to execute arbitrary system commands.
A flaw in the Linux kernel network subsystem allows for memory corruption when handling lightweight tunnel (LWT) encapsulation, potentially leading to unauthorized system access or crashes.
PaperCut MF and NG are vulnerable to unsafe dynamic class loading in database utilities, allowing attackers to execute arbitrary Java bytecode via manipulated system configuration parameters.
A logic error in the Klever-Go marketplace settlement process allows asset owners to manipulate royalty percentages, resulting in the creation of unbacked currency and supply corruption.
A critical integer overflow vulnerability in Klever-Go allows authenticated users to create unbacked assets via crafted split-royalty values.
Redpanda versions up to 26.2.2 incorrectly default the Admin API to allow unauthenticated requests with superuser privileges, potentially exposing cluster management functions to unauthorized parties.
The SmilePass Selfie Login WordPress plugin fails to perform server-side identity verification, allowing unauthenticated attackers to hijack any user account, including those with administrative privileges.
An unauthenticated server-side request forgery vulnerability in Kubeflow Pipelines allows attackers to access internal cluster services and cloud metadata via the /_proxy/ route.
An improper input validation flaw in the Apache Camel Atmosphere Websocket component allows unauthenticated remote attackers to manipulate message routing via injected HTTP headers.
The Argo Rollouts dashboard exposes critical, unauthenticated mutating API operations, allowing unauthorized users to manipulate rollout processes across accessible Kubernetes namespaces.
A memory management flaw in the Linux kernel IPVS module allows stale hash nodes to point to freed memory, potentially leading to system instability or arbitrary code execution.
A memory corruption vulnerability in the Linux kernel TLS receive path allows a remote attacker to trigger unintended memory writes, potentially leading to information disclosure or system compromise.
A session fixation vulnerability in IBM Administration Runtime Expert for i allows unauthenticated remote attackers to hijack authenticated user sessions and gain elevated system privileges.
IBM Langflow OSS versions 1.0.0 through 1.11.1 are vulnerable to remote code execution due to improper security restrictions on the A2A public endpoint.
A race condition in the Linux kernel netfilter subsystem allows for potential memory corruption due to improper management of expectation timers and garbage collection.
IBM Langflow OSS versions 1.0.0 through 1.11.1 are vulnerable to OS command injection via crafted flow types, allowing authenticated users to bypass policy controls and execute arbitrary system commands.
A heap buffer overflow vulnerability in the Linux kernel airoha network driver allows unauthenticated attackers to cause a kernel crash or potentially execute arbitrary code.
JFrog Artifactory contains an authentication weakness that may allow an unauthenticated attacker to obtain administrative privileges via remote network access.
A use-after-free vulnerability in the Linux kernel batman-adv module allows for potential memory corruption due to improper handling of skb buffer reallocation during ARP hardware source acquisition.
A memory safety vulnerability in the Linux kernel qede driver allows for out of bounds access due to improper index validation during cqe len_list processing.
A vulnerability in the Linux kernel netfilter flowtable allows for an out-of-bounds stack read due to an integer underflow when handling bridge VLAN untagging.
A slab out-of-bounds read vulnerability exists in the Linux kernel NTFS filesystem driver due to improper validation of attribute-list entries during lookup operations.
The Linux kernel NTFS filesystem implementation fails to properly validate resident attribute lists, allowing for potential out-of-bounds memory access.
A use-after-free vulnerability in the Linux kernel vxlan implementation allows local or remote attackers to potentially execute code or crash the system by triggering a re-allocation of skb memory.
A memory management flaw in the Linux kernel mtk_eth_soc driver allows a crash when CONFIG_NET_POLL_CONTROLLER is enabled due to an incorrect pointer type being passed during interrupt handling.
A memory corruption vulnerability exists in the Linux kernel XDP subsystem where improper clone validation leads to skb_shared_info overwrites, potentially allowing for remote code execution.
A race condition in the Linux kernel DIBS driver allows unauthenticated attackers to trigger a null pointer dereference or memory corruption via GID event interrupts, potentially leading to system compromise.
A use-after-free vulnerability in the Linux kernel net/x25 subsystem allows for potential memory corruption due to improper handling of socket timers during destruction.
A use-after-free vulnerability in the Linux kernel NFS implementation allows unauthenticated attackers to potentially trigger system crashes or arbitrary code execution via a delayed FREE_STATEID call.
A use-after-free vulnerability in the Linux kernel SCTP implementation allows unauthenticated attackers to potentially trigger memory corruption or system crashes via crafted ASCONF packets.
A memory corruption vulnerability in the Linux kernel ip6_tunnel module allows unauthenticated remote attackers to potentially achieve remote code execution via malformed IPv6 ICMP error packets.
A stack out-of-bounds write vulnerability exists in the Linux kernel IPVS module due to improper handling of IPv4 options during ICMP error rebasing.
A use-after-free vulnerability in the Linux kernel SCTP implementation allows attackers to trigger memory corruption and potential code execution by manipulating queued control chunks.
A slab-out-of-bounds vulnerability in the Linux kernel Btrfs file system lzo decompression module allows unauthenticated attackers to trigger system crashes or potentially execute code via crafted images.
A deserialization of untrusted data vulnerability in the GiveWP WordPress plugin allows unauthenticated attackers to perform remote code execution via object injection.
A critical OS command injection vulnerability in the ai-maestro killSessionSync function allows unauthenticated attackers to execute arbitrary system commands via crafted input.
The Punk web framework for Perl allows unauthenticated session cookie forgery because it defaults to an empty HMAC key when a session secret is not explicitly configured.
MapFish Print is vulnerable to XML External Entity (XXE) injection via the /api/print3/print endpoint, allowing unauthenticated attackers to read local files or perform server-side request forgery.
A logic error in the Linux kernel spi-qpic-snand driver causes incorrect SPI-NAND feature programming, potentially leading to persistent OTP mode activation and device unbootability.
An out of bounds read vulnerability in the V8 engine of Google Chrome allows a remote attacker to execute arbitrary code within the sandbox via a crafted HTML page.
A race condition in the Linux kernel hisi_sas driver allows for a potential system crash or memory corruption during simultaneous link resets and driver removal.
HyperDX versions up to 1.10.1 contain a missing authorization vulnerability that allows any authenticated team member to perform administrative actions on team management endpoints.
A SQL injection vulnerability in the sample MySQLBrowserProvider of WsgiDAV allows unauthenticated attackers to extract arbitrary data via crafted GET requests if the provider is enabled.
A type confusion vulnerability in Microsoft Edge (Chromium-based) allows an unauthenticated remote attacker to execute arbitrary code.
A missing size validation in the Linux kernel HID core allows an out of bounds read or kernel panic when processing specially crafted numbered HID reports.
A vulnerability in the Linux kernel network stack allows unprivileged users to trigger a kernel panic via malformed GSO state in fragmented packets.
A flaw in the Linux kernel ims-pcu driver improperly exposes sysfs attributes on non-control interfaces, potentially leading to system instability or crashes when accessed.
Bifrost contains a Server-Side Request Forgery vulnerability due to improper classification of IP addresses as public, allowing unauthenticated attackers to access internal cloud metadata services.
KubeVela contains a vulnerability in the Terraform remote configuration loader that allows authenticated users to trigger uncontrolled resource consumption, leading to a denial of service.
BiSheng before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code.
Klever-Go is vulnerable to an integer overflow in the semi-fungible token add-quantity path, allowing a mint-role holder to bypass supply limits and corrupt on-chain counters.
A logic error in the Klever-Go royalty transfer process allows for unauthorized minting of KDA tokens, leading to unbounded inflation of the currency.
The MongoDB BI Connector ODBC driver is vulnerable to a stack-based buffer overflow, which may allow an authenticated user to execute arbitrary code or cause an application crash.
The Slider Hero WordPress plugin is vulnerable to Stored Cross-Site Scripting due to missing authorization and input sanitization, allowing unauthenticated attackers to execute arbitrary JavaScript.
The TP-Link TL-MR100 v3.20 is vulnerable to a pre-authentication stack-based buffer overflow in the http_gdpr_decrypt function, potentially allowing arbitrary code execution.
A privilege escalation vulnerability in Piccolo Admin allows authenticated non-superuser administrators to obtain session tokens, impersonate superusers, and modify account privileges.
SiYuan versions before 3.8.1 contain a server-side request forgery vulnerability allowing attackers to bypass SSRF defenses via DNS rebinding to access internal cloud metadata and services.
SpringBlade versions 2.7.3 through 3.5.0 contain a privilege escalation vulnerability allowing authenticated attackers to create administrator accounts via an unprotected Feign user-creation endpoint.
IBM Langflow OSS versions 1.0.0 through 1.11.1 are vulnerable to remote code execution due to improper control of code generation.
Yamcs mission control framework fails to perform authorization checks on multiple API endpoints, allowing authenticated low-privilege users to access metadata and manipulate critical system operations.
A path traversal vulnerability in the amazon-ssm-agent aws:downloadContent plugin allows authenticated users to write arbitrary files with root privileges, potentially leading to code execution.
An improper access control flaw in PaperCut MF/NG allows unauthenticated remote attackers to modify system configurations by bypassing validation checks for administrative functions.
The CP Plus CP-XR-DE21-S router contains hardcoded authentication credentials in its firmware, allowing unauthenticated attackers on the local network to gain administrative access.
A supply chain vulnerability in the Hermes Agent MCP catalog allows remote code execution due to the use of mutable branches instead of pinned commit SHAs for third-party repository references.
A kernel NULL pointer dereference vulnerability exists in the Linux kernel TLS implementation, allowing local unprivileged users to cause a system crash via a crafted loopback TCP socket.
IBM Langflow OSS contains an improper authentication vulnerability that allows unauthenticated remote attackers to execute arbitrary flows and access sensitive information.
IBM Langflow OSS versions 1.0.0 through 1.11.1 are vulnerable to unauthorized information disclosure and message injection due to a namespace collision involving user identifiers.
Bisheng versions up to 2.6.0-fix2 contain an unauthenticated server-side request forgery (SSRF) vulnerability in the workflow report callback endpoint, allowing unauthorized internal network access.
An authorization bypass vulnerability in Vikunja allows authenticated users to perform unauthorized cross-tenant deletion of Kanban assignments and ordering via the project view API.
Gophish API middleware fails to enforce account lockouts and password change requirements, allowing authenticated users with valid API keys to bypass these critical security controls.
VoltAgent versions through 2.1.20 lack authorization checks in memory API handlers, allowing authenticated users to access, modify, or delete arbitrary conversations belonging to other users.
The WPBulky WordPress plugin contains a SQL injection vulnerability in versions 1.2.2 and earlier, allowing authenticated contributors to execute arbitrary database queries.
A memory handling flaw in the Linux kernel's dst_metadata implementation causes a false-positive buffer overflow warning during tunnel information cloning, potentially leading to system instability.
Pega Platform versions 7.1.0 through 25.1.2 contain an input validation flaw in loop conditions that can result in a denial of service.
A use-after-free vulnerability exists in the Linux kernel batman-adv module due to improper handling of buffer reallocation during ethernet header acquisition.
A use-after-free vulnerability exists in the Linux kernel amdxdna accelerator driver, caused by an iommu domain lifetime race during device removal.
A locking omission in the Linux kernel iommufd subsystem allows a local user to trigger a kernel warning and potential instability by failing to acquire the required dma_resv lock.
A buffer handling flaw in the Linux kernel wcn36xx wireless driver allows an out of bounds read of heap memory due to insufficient validation of firmware response lengths.
A memory safety flaw in the Linux kernel ocfs2 filesystem driver allows an out-of-bounds write during refcounted file unlinking, potentially leading to system instability or code execution.
A integer truncation vulnerability in the Linux kernel NTFS driver allows local attackers to trigger an out of bounds read via a crafted NTFS image.
A use-after-free vulnerability exists in the Linux kernel Bluetooth subsystem due to improper reference counting in the SCO socket connection handling.
A use-after-free vulnerability exists in the Linux kernel Bluetooth subsystem due to improper reference counting during hci_sync task execution.
A use-after-free vulnerability in the Linux kernel Bluetooth ISO implementation allows unauthenticated attackers to trigger memory corruption via improper hcon reference handling.
A memory validation error in the Linux kernel mac80211 subsystem allows unauthenticated attackers to trigger out-of-bounds access via malformed S1G TWT setup frames.
A memory mapping vulnerability exists in the Linux kernel ptp vmclock driver where read-only mappings can be upgraded to writable, potentially allowing guest-to-host timekeeping data corruption.
The Sexy Polling Reloaded extension for Joomla is vulnerable to an unauthenticated blind SQL injection, allowing attackers to extract sensitive data from the database.
The gpt-crawler tool through 1.5.1 is vulnerable to arbitrary file write via the outputFileName parameter, allowing unauthenticated attackers to overwrite files on the host filesystem.
A vulnerability in the Linux kernel asus_atk0110 driver allows an out-of-bounds read due to improper validation of ACPI package elements.
A race condition in the Linux kernel i2c-imx driver allows for improper error handling during slave registration, potentially leading to a system crash or memory corruption via a null pointer dereference.
A flaw in the Linux kernel io_uring subsystem allows local users to bypass per-task security restrictions during an exec call, potentially leading to unauthorized system access.
A buffer overflow vulnerability in the Linux kernel device tree scanning function allows memory corruption during boot when excessive dynamic memory regions are defined.
Rybbit before 2.7.0 contains a CORS misconfiguration that allows attackers to bypass origin restrictions and perform credentialed cross-origin requests to read sensitive data or perform actions.
A use-after-free vulnerability in the Linux kernel VXLAN driver allows local attackers to trigger memory corruption via improper ageing timer management on inactive devices.
A vulnerability in the Linux kernel vhost-scsi subsystem allows an authenticated local attacker to trigger a kernel panic via improper handling of feature bit changes after endpoint initialization.
A race condition in the Linux kernel vsock/virtio component allows a use-after-free vulnerability when handling virtqueues during device suspend and resume operations.
The Linux kernel Integrity Measurement Architecture (IMA) fails to properly reset action cache flags during file truncation, potentially allowing stale security measurements.
A use-after-free race condition in the Linux kernel vsock/virtio component occurs during RX queue teardown, potentially leading to a kernel panic and denial of service.
The Linux kernel xsk subsystem fails to validate launch-time metadata size, potentially allowing local users to trigger memory inconsistencies via crafted metadata requests.
A vulnerability in the Linux kernel IPVS module allows a local attacker to trigger an out-of-bounds write via race conditions during packet processing, leading to memory corruption or system crashes.
A race condition in the Linux kernel gpio: pca953x driver allows local attackers to perform unauthorized register operations due to improper locking of the i2c_lock during IRQ bus synchronization.
A memory leak vulnerability in the Linux kernel netfilter bridge path allows unauthenticated attackers to cause a denial of service by exhausting slab memory through crafted non-IP packets.
A race condition in the Linux kernel bonding driver leads to a null pointer dereference or promiscuity counter underflow, potentially causing system crashes or unauthorized network traffic exposure.
Quivr versions through 0.0.322 contain an authorization bypass vulnerability allowing authenticated users to access, modify, or delete chat data belonging to other users.