CVE-2026-21962
An unauthenticated remote code execution vulnerability exists in Oracle WebLogic Server Proxy Plug-ins for Apache HTTP Server and IIS, potentially leading to a full system compromise.
Critical vulnerabilities, curated daily for security professionals
Google Chrome accounted for the largest single cluster of critical vulnerabilities disclosed yesterday, alongside a remote code execution flaw in Apache Tomcat and several WooCommerce extension issues. The day produced 24 critical CVEs (down 43% from the prior day's 42) and 81 high-priority CVEs (up 23% from 66). CVE-2026-65905 (CVSS 9.8) affects Apache Tomcat, CVE-2026-79090 (CVSS 9.8) and CVE-2026-79026 (CVSS 9.6) affect Google Chrome, and CVE-2026-15369 (CVSS 9.8) affects the Addify Custom User Registration Fields plugin for WooCommerce. Attack patterns skew toward remote code execution and unauthenticated access in internet-facing web infrastructure and e-commerce plugin code, with 11 CVEs carrying confirmed active exploitation including Oracle WebLogic Server Proxy Plug-in, NetScaler ADC and Gateway, and Gitea. Patch availability is recorded at 0% in the collected data, so verify fixed versions directly with each vendor and apply available updates to browsers and application servers first.
Immediate action: Prioritize Google Chrome browser updates across managed endpoints and patch internet-facing Apache Tomcat and NetScaler ADC and Gateway deployments, followed by WordPress sites running the affected WooCommerce registration and payment plugins. Patch availability is reported at 0% in this dataset, so check vendor advisories directly for fixed builds and apply documented mitigations or access restrictions where no update exists yet.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An unauthenticated remote code execution vulnerability exists in Oracle WebLogic Server Proxy Plug-ins for Apache HTTP Server and IIS, potentially leading to a full system compromise.
A critical remote code execution vulnerability exists in Gitea's diffpatch feature that allows an attacker to execute arbitrary shell commands.
A memory overflow vulnerability in NetScaler ADC and Gateway appliances configured as SSL VPN, ICA, or AAA servers may lead to service disruption or Denial of Service (DoS).
A remote code execution vulnerability exists in Microsoft SQL Server due to improper handling of internal functions, allowing authenticated attackers to execute arbitrary code.
An authentication bypass in ownCloud core allows unauthenticated attackers to access, modify, or delete files if the victim username is known and no signing key is configured.
An improper memory calculation vulnerability exists in the Linux kernel's IPv6 paged-allocation path, potentially leading to memory corruption.
Ajax.NET Professional is vulnerable to deserialization of untrusted data, which can be exploited by unauthenticated attackers to achieve remote code execution.
A race condition in the Red Hat Libuser userhelper program allows local users to cause a denial of service by corrupting the system password file.
The ABRT tool contains a local privilege escalation vulnerability via symlink attacks on predictable file names in /var/tmp or /var/spool, allowing authenticated local users to gain root privileges.
A critical out-of-bounds memory write vulnerability exists in the Linux kernel watch_queue event notification subsystem, allowing local users to gain elevated privileges or cause a system crash.
An authenticated user can perform path traversal to write data outside the intended Docker cache directory in JFrog Artifactory due to improper input validation.
A capture-replay vulnerability in the Apache Tomcat DIGEST authenticator allows unauthenticated attackers to replay specific requests, potentially bypassing authentication mechanisms.
The Omnivore API contains an authentication bypass flaw in Apple sign-in token verification that allows unauthenticated attackers to impersonate any Apple-linked account.
An unauthenticated privilege escalation vulnerability in the Addify Custom User Registration Fields for WooCommerce plugin allows attackers to gain administrative access during the checkout process.
A use after free vulnerability in Google Chrome Extensions allows a remote attacker to achieve arbitrary code execution outside the sandbox via a crafted extension and social engineering.
A use after free vulnerability in the Google Chrome Network component on Mac allows remote attackers to achieve arbitrary code execution outside the sandbox via a malicious extension.
The Total processing card payments for WooCommerce plugin is vulnerable to SSRF, allowing unauthenticated attackers to steal payment credentials and forge order payment statuses.
Google Chrome contains an improper privilege management vulnerability in Actor, potentially allowing a remote attacker to bypass system access restrictions via a crafted HTML page.
A use of an uninitialized variable in Google Chrome on iOS allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Google Chrome contains a high-severity input validation flaw in the Dawn component that allows remote code execution outside the sandbox via a crafted HTML page.
A remote code execution vulnerability exists in the ANGLE graphics engine of Google Chrome, allowing attackers to bypass sandbox protections via a crafted HTML page.
An out of bounds write vulnerability in the ANGLE graphics engine of Google Chrome allows a remote attacker to execute arbitrary code via a crafted HTML page.
The SigmaForms Pro WordPress plugin is vulnerable to unauthenticated remote code execution due to improper file upload validation in the handle_form_submission function.
An off-by-one error in the Google Chrome DevTools allows a remote attacker to potentially read sensitive sandbox memory through the use of a crafted Chrome extension.
Shinobi contains a hardcoded connection key in the child node service, allowing unauthenticated attackers to execute arbitrary database queries and modify user records or camera configurations.
Apache Tomcat contains an improper input validation vulnerability resulting from an incomplete fix for a previous security issue.
An incorrect authorization vulnerability in Google Chrome for Android's CustomTabs allows a local attacker to bypass web origin policy through a co-installed malicious application.
The MyHome Core WordPress plugin contains an authentication bypass flaw in its AJAX handlers, allowing unauthenticated attackers to hijack user accounts, including those with administrative privileges.
An authorization flaw in Apache Tomcat's FORM authentication process allows unauthenticated attackers to bypass security constraints that restrict access to specific HTTP methods.
An improper access control vulnerability in Apache Tomcat allows unauthenticated attackers to bypass security constraints by misconfiguring path-based authorization rules.
The Uix UserCenter WordPress plugin contains a hardcoded authentication token vulnerability, allowing unauthenticated attackers to hijack any user account, including administrator accounts.
The argocd-mcp component binds its HTTP transport to all network interfaces and permits unauthenticated sessions, allowing unauthorized access to Argo CD resources when an API token is present.
The 爱采集 WordPress plugin allows unauthenticated attackers to perform arbitrary file reads, server-side request forgery, and arbitrary file writes due to missing authentication and input validation.
The rust-iot-platform contains an authentication bypass vulnerability where REST API routes lack necessary security guards, allowing unauthenticated attackers to manipulate user accounts.
Cloud Commander versions prior to 19.20.2 are vulnerable to directory traversal via REST file-operation and markdown endpoints, allowing unauthenticated attackers to read or modify files system-wide.
An out of bounds write vulnerability in the Google Chrome Crashpad component allows remote attackers to achieve arbitrary code execution outside the sandbox via a crafted HTML page.
A vulnerability in the MongoDB BI Connector schema-sampling routine allows an authenticated database user to cause a denial of service by creating a view that triggers a failure during evaluation.
An unauthenticated attacker can cause a denial of service in the MongoDB BI Connector by initiating an incomplete SASL login exchange, which exhausts connection capacity by holding sessions open.
BookStack contains a remote code execution vulnerability in the portable ZIP import feature, allowing authenticated users to upload and execute malicious PHP files via crafted book covers.
A relative path traversal vulnerability in the Apache Camel Google Storage component allows unauthenticated attackers to write files outside the intended directory during object downloads.
MariaDB Connector/Node.js improperly validates SSL certificates, allowing unauthenticated attackers to perform man-in-the-middle attacks and capture database credentials during the handshake process.
A use after free vulnerability in the Chromoting component of Google Chrome on Windows allows an attacker to achieve remote code execution outside the sandbox via crafted network traffic.
An unauthenticated remote denial of service vulnerability exists in the alos-http framework due to improper handling of malformed request paths, leading to an out-of-bounds panic.
Budibase server versions before 3.41.3 are susceptible to a missing authorization vulnerability in the resource duplication API, allowing authenticated builders to inject resources into unauthorized workspaces.
Documenso versions prior to 2.13.0 contain an unauthenticated file upload vulnerability in the /api/files/upload-pdf endpoint that allows for arbitrary file uploads and potential resource exhaustion.
A certificate validation flaw in the MongoDB BI Connector allows remote attackers to bypass client certificate authentication and gain unauthorized access to exposed data.
An authentication bypass vulnerability in phpSysInfo allows unauthenticated attackers to spoof IP addresses and access sensitive system information.
A race condition in the GPU component of Google Chrome allows a remote attacker with renderer process compromise to potentially execute arbitrary code outside the sandbox via a crafted HTML page.
A race condition in the FileSystem component of Google Chrome allows a remote attacker with renderer process control to escape the sandbox and execute arbitrary code via a malicious HTML page.
A type confusion vulnerability in the Accessibility component of Google Chrome on Windows allows remote attackers to achieve sandbox escape and arbitrary code execution via crafted HTML content.
A vulnerability in Google Chrome for Android allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page after compromising the renderer process.
An integer overflow vulnerability exists in the Chromecast component of Google Chrome, allowing a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
A logic error in the CheckProfileTypeAuthorizer component of pac4j-core allows authenticated users to bypass authorization checks and access restricted resources by spoofing profile types.
KubeEdge CloudCore through 1.23.1 fails to authenticate node task status reports, allowing unauthenticated attackers to manipulate upgrade job statuses and disrupt control plane operations.
HeyForm versions before 3.0.0-rc.8 insecurely configure CORS, allowing unauthorized cross-origin requests to execute authenticated GraphQL queries and access sensitive user data.
Budibase Server versions before 3.41.3 are vulnerable to server-side request forgery in the datasource verify endpoint, allowing authenticated builder-level users to leak internal credentials.
An unauthenticated input validation flaw in Graylog2 allows remote attackers to manipulate or suppress security logs via crafted syslog messages, potentially facilitating malicious activity obfuscation.
An unauthenticated path traversal vulnerability exists in the Yamcs mission control framework, allowing attackers to read arbitrary files from the host operating system.
The Rest Routes WordPress plugin fails to sanitize input in public REST routes, enabling unauthenticated SQL injection attacks.
Apache Tomcat contains an improper authorization vulnerability where security-role-ref definitions are incorrectly used as role aliases, potentially leading to unauthorized integrity and availability impacts.
Apache Tomcat contains an improper authentication vulnerability where non-existent users may be authenticated when using specific configurations like CLIENT-CERT or SPNEGO.
A Time-of-check Time-of-use (TOCTOU) race condition in Apache Tomcat during unix domain socket creation allows local unauthorized users to gain unauthorized access to the socket.
The HEL Online Classroom WordPress plugin fails to perform authorization checks on REST API routes, allowing unauthenticated users to access sensitive configuration settings and API secrets.
A race condition in the free5GC AUSF component allows unauthenticated attackers to trigger a denial of service for specific subscribers by flooding the SBI/N12 interface.
A SQL injection vulnerability in MongoDB BI Connector allows an authenticated user with write permissions to execute arbitrary SQL commands by manipulating database object names.
The SAML Single Sign On plugin for WordPress fails to validate SAML signatures before updating certificates, allowing unauthenticated attackers to forge authentication assertions for any user account.
The User Profile Builder plugin for WordPress fails to restrict file upload features, allowing unauthenticated users to access media libraries and modify unpublished content.
The SmartAIPress WordPress plugin is vulnerable to Server-Side Request Forgery due to missing capability checks and lack of input validation on an AJAX action, allowing unauthorized data retrieval.
The erlef oidcc library improperly verifies cryptographic signatures, allowing unauthenticated attackers to impersonate arbitrary users via crafted encrypted ID tokens or JARM responses.
An improper access control flaw in the Appointment Booking Calendar WordPress plugin allows unauthenticated users to manipulate payment verification, resulting in unauthorized appointment approval.
Rodauth before 2.46.0 contains an authentication bypass vulnerability in the WebAuthn login route, allowing authenticated users to impersonate other accounts.
An authorization bypass exists in the Go SSH package where source-address restrictions are ignored for several authentication callbacks, allowing unauthorized access from restricted network locations.
An unauthenticated attacker can cause a denial of service in the MongoDB BI Connector by exhausting storage through excessive connection log activity, leading to an unhandled exception and process crash.
An improper authentication vulnerability in the Apache Camel Platform HTTP Main component allows unauthenticated attackers to bypass JWT issuer and audience validation.
SvelteKit contains a deserialization expansion vulnerability in the experimental remote functions feature, allowing unauthenticated attackers to cause a denial of service via memory exhaustion.
SvelteKit versions 2.49.0 through 2.52.1 are susceptible to a memory exhaustion vulnerability via malformed remote form data, leading to a denial of service.
SvelteKit contains a CPU exhaustion vulnerability in form deserialization that allows unauthenticated attackers to cause a denial of service.
wolfProvider fails to increment AES-GCM nonces in TLS 1.2 and DTLS 1.2 connections, leading to keystream disclosure and authentication tag forgery.
Budibase server versions before 3.41.3 contain a missing authorization vulnerability in the query endpoint that allows authenticated users to bypass table-level access controls.
Budibase server versions before 3.41.3 contain a missing authorization vulnerability that allows authenticated users to escalate privileges and access unrelated applications.
Budibase server versions before 3.41.3 lack proper authorization checks on license management endpoints, permitting authenticated users to modify or delete license keys and offline tokens.
A traffic interception vulnerability in the BOSH Director vCenter CPI allows unauthenticated attackers to capture administrator credentials via improper certificate validation.
The rust-iot-platform stores user passwords in plaintext within its database, allowing unauthorized retrieval of credentials via API endpoints.
IBM Administration Runtime Expert for i version 1R1M0 contains an improper authentication enforcement vulnerability that may allow a remote attacker to access sensitive information.
IBM Langflow OSS versions 1.0.0 through 1.11.1 are vulnerable to path traversal, allowing an unauthenticated remote attacker to read arbitrary files on the host system.
A resource exhaustion vulnerability in the multer Node.js middleware allows unauthenticated remote attackers to cause a denial of service via file descriptor and disk block leakage.
A flaw in the multer middleware allows unauthenticated attackers to trigger an uncaught exception, resulting in a denial of service by terminating the Node.js process.
The multer Node.js middleware is vulnerable to a remote denial of service via a crafted multipart request that triggers uncontrolled resource consumption, causing the event loop to block.
A resource exhaustion vulnerability in dd-trace-rs allows remote unauthenticated attackers to trigger a denial of service via malformed W3C tracestate headers.
PLANET GS-4210-16P2S firmware contains a pre-authentication buffer overflow in the web management interface, allowing unauthenticated remote attackers to trigger a denial of service.
Portkey AI Gateway versions 1.14.0 through 1.15.2 are vulnerable to server-side request forgery in the /v1/proxy/* route due to a missing requestValidator middleware.
Stable Diffusion WebUI contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint, allowing unauthenticated attackers to retrieve cleartext authentication credentials.
An integer underflow vulnerability in the NASA cFS Software Bus allows remote attackers to trigger memory errors via manipulated message size arguments.
Skyvern before 1.0.45 is vulnerable to a sandbox escape in TextPromptBlock, allowing attackers to inject malicious Jinja template syntax and execute arbitrary code with server process privileges.
The cohttp package for OCaml is vulnerable to directory traversal due to improper validation of input before canonicalization, potentially allowing unauthorized access to sensitive files.
The pac4j-oidc library fails to validate access token signatures and claims, allowing authenticated users to forge tokens and escalate privileges via Keycloak role injection.
iFlytek astron-agent contains an authorization bypass in the copyFlow endpoint, allowing authenticated attackers to enumerate, overwrite, or steal workflows from other tenants.
Snyk sweater-comb before 3.8.8 is vulnerable to OS command injection via a malicious branch name field in the .vervet.yaml configuration file.
Atlantis fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to intercept sensitive GitHub App credentials including RSA private keys and webhook secrets.
Sudo fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode, allowing local users to bypass security restrictions and command logging.
The su-exec utility fails to validate numeric user and group identifiers, allowing attackers to trigger integer truncation that results in unintended root privilege execution.
IGEL OS 11 and 12 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux kernel parameters via an unsigned configuration area.
Qwen-Agent contains a server-side request forgery vulnerability in the document parsing module that allows unauthenticated attackers to make the server issue requests to arbitrary internal addresses.
Qwen-Agent through 0.0.34 contains a path traversal vulnerability in the document parser, allowing unauthenticated attackers to read arbitrary files via the Gradio interface.
The Smush Image Compression and Optimization plugin for WordPress is vulnerable to an unauthenticated denial of service attack due to improper resource allocation limits.
A broken access control vulnerability in the Simple Payment plugin allows unauthenticated attackers to perform unauthorized actions due to missing authorization checks.
A resource exhaustion vulnerability in OX Dovecot allows unauthenticated remote attackers to trigger a denial of service by sending specially crafted email messages that consume excessive memory.
An unauthenticated attacker can trigger a denial of service in the ManageSieve login process by sending a malformed command, potentially disrupting Sieve script management.
An unauthenticated attacker can cause a denial of service in OX Dovecot by sending an IMAP ID command with an excessive number of parameters, triggering uncontrolled resource consumption.
A URL parsing flaw in gitoxide's gix-url crate allows attackers to leak HTTP Basic Authorization credentials to unintended hosts during malicious redirects.
A path traversal vulnerability in gitoxide allows unauthenticated attackers to redirect submodule directory operations to arbitrary locations by crafting malicious submodule names in .gitmodules files.
Gitoxide improperly follows symlinks when reading .gitmodules files, allowing unauthenticated attackers to inject and parse arbitrary files from outside the repository tree.
The gitoxide crate contains a path traversal vulnerability in submodule validation that, when combined with a trust inheritance flaw, allows unauthenticated remote attackers to read arbitrary files.
Gitoxide versions before 0.69.0 are vulnerable to denial of service attacks via crafted pack data during git clone or fetch operations.
Kotaemon versions through 0.12.0 contain an authorization bypass vulnerability in control.py, allowing unauthorized users to access, rename, or delete arbitrary chat conversations.
Gitingest versions through 0.3.1 contain a Server-Side Request Forgery vulnerability due to improper hostname validation, allowing attackers to trigger outbound connections and disclose sensitive tokens.