CVE-2026-60004
A critical remote code execution vulnerability exists in Gitea's diffpatch feature that allows an attacker to execute arbitrary shell commands.
Critical vulnerabilities, curated daily for security professionals
Google Chrome accounts for the largest cluster of critical disclosures, with five separate CVSS 9.6 issues alongside a CVSS 9.4 flaw in Google Cloud Build that reaches build pipeline infrastructure. Yesterday's disclosures produced 26 critical CVEs (up 8% from 24) and 67 high-priority CVEs (down 17% from 81), for 93 total. Notable entries include CVE-2026-82542 (CVSS 10) in the Tenda HG10 router, CVE-2026-58574 (CVSS 9.8) in Dell PowerStore T Series storage, and CVE-2026-82870 and CVE-2026-82872 (CVSS 9.6 and 9.1) in the ToolJet low-code platform. The pattern spans browser memory corruption, edge networking equipment, enterprise storage, and CI/CD and low-code developer tooling, and 10 CVEs carry confirmed active exploitation including issues in Gitea, NetScaler ADC and Gateway, and JFrog Artifactory. Patch data is unavailable for this set (0% recorded), so treat vendor advisories as the authoritative source and prioritize by exposure rather than by reported patch status.
Immediate action: Prioritize Chrome updates across managed endpoints and review exposure of internet-facing NetScaler ADC and Gateway, Gitea, and JFrog Artifactory instances, which have confirmed exploitation. Dell PowerStore T Series, Tenda HG10, ToolJet, and Google Cloud Build carry the highest-scoring critical flaws and should be checked against vendor advisories next. Patch availability is not recorded for this set, so verify fixed versions directly with each vendor and apply documented mitigations where no update is published.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A critical remote code execution vulnerability exists in Gitea's diffpatch feature that allows an attacker to execute arbitrary shell commands.
A memory overflow vulnerability in NetScaler ADC and Gateway appliances configured as SSL VPN, ICA, or AAA servers may lead to service disruption or Denial of Service (DoS).
A remote code execution vulnerability exists in Microsoft SQL Server due to improper handling of internal functions, allowing authenticated attackers to execute arbitrary code.
An authentication bypass in ownCloud core allows unauthenticated attackers to access, modify, or delete files if the victim username is known and no signing key is configured.
An improper memory calculation vulnerability exists in the Linux kernel's IPv6 paged-allocation path, potentially leading to memory corruption.
Ajax.NET Professional is vulnerable to deserialization of untrusted data, which can be exploited by unauthenticated attackers to achieve remote code execution.
A race condition in the Red Hat Libuser userhelper program allows local users to cause a denial of service by corrupting the system password file.
The ABRT tool contains a local privilege escalation vulnerability via symlink attacks on predictable file names in /var/tmp or /var/spool, allowing authenticated local users to gain root privileges.
A critical out-of-bounds memory write vulnerability exists in the Linux kernel watch_queue event notification subsystem, allowing local users to gain elevated privileges or cause a system crash.
An authenticated user can perform path traversal to write data outside the intended Docker cache directory in JFrog Artifactory due to improper input validation.
A use after free vulnerability in Google Chrome for Android allows remote attackers to execute arbitrary code outside the sandbox through social engineering and UI interaction.
An incorrect authorization vulnerability in Google Cloud Build allows remote attackers to execute unreviewed code in the build environment via webhook suppression.
ToolJet before v3.16.208 allows authenticated workspace administrators to bypass authorization checks and manipulate database tables in other workspaces by modifying the organizationId parameter.
A critical flaw in Google Chrome Media components allows unauthenticated remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page.
An incorrect reference resolution vulnerability in the Google Chrome FileSystem component allows remote attackers to achieve arbitrary code execution outside the sandbox via social engineering.
An out of bounds read vulnerability in the ANGLE graphics engine of Google Chrome for Windows allows remote attackers to execute arbitrary code via a crafted HTML page.
An out of bounds write vulnerability in the ANGLE component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
ToolJet before v3.16.208 suffers from an authorization bypass, allowing authenticated builder-role users to manipulate database schemas and data across tenant boundaries.
Dell PowerStore appliances contain a missing authentication vulnerability that allows unauthenticated attackers to read sensitive internal system files and potentially gain full administrative access.
A buffer overflow vulnerability in the Tenda HG10 Boa web server allows unauthenticated remote attackers to trigger a denial of service via the formIPv6Routing interface.
A stack-based buffer overflow in the setUploadSetting function of the TOTOLINK NR1800X allows remote attackers to execute arbitrary code via the FileName argument.
D-Link DIR-825M routers contain a stack-based buffer overflow and command injection vulnerability in the firmware upgrade function, allowing remote code execution with root privileges.
A stack-based buffer overflow and command injection vulnerability in the D-Link DIR-825M disk formatting endpoint allows authenticated remote attackers to execute arbitrary code.
Nodemailer is vulnerable to SMTP command injection via the envelope.size parameter, allowing unauthenticated attackers to inject arbitrary SMTP commands like RCPT TO.
An unauthenticated code injection vulnerability in ash_ai allows remote attackers to execute arbitrary Elixir code by injecting malicious EEx templates into prompt actions.
A stack-based buffer overflow in the TOTOLINK A720R cstecgi.cgi binary allows an authenticated administrator to achieve remote code execution via a crafted MAC filtering request.
A privilege escalation vulnerability in the hulumi IAM policy allows unauthenticated attackers to create persistent higher-privilege roles in the sandbox account.
ToolJet versions prior to 3.16.208 contain an authorization bypass vulnerability allowing authenticated users to perform unauthorized database operations across tenant boundaries.
The hulumi policies package contains an evidence validation bypass that allows attackers to suppress security violations by submitting compliant evidence from unrelated resources.
A security bypass in @hulumi/policies versions before 1.3.2 allows unauthenticated attackers to evade IAM condition guardrails via malicious OIDC trust policies.
The @hulumi/drift package fails to validate the provenance of externally supplied execute plans, allowing unauthenticated attackers to perform unauthorized and unsafe reconciliation operations.
A deployment SCP template vulnerability in hulumi versions before v1.3.2 allows attackers to bypass IAM boundary protections during tag-on-create operations.
The hulumi policies package fails to properly inspect IAM policy evidence, allowing unauthenticated attackers to bypass administrator-policy guardrails via crafted policy paths.
Punk::Plugin::TOTP allows an authentication bypass by accepting an attacker's recovery code for a target user account due to improper numeric comparison of user identifiers during validation.
Stomper 5e2741e is susceptible to a heap use-after-free vulnerability when handling malformed sequences of CONNECT and SEND frames, which can lead to a process crash or potential remote code execution.
An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of Cohere North AI v1.1.5 allows unauthenticated attackers to execute arbitrary code.
Admidio before 5.0.12 is vulnerable to unauthenticated blind SQL injection in lists_show.php, allowing attackers to extract sensitive database contents including user credentials.
AVideo is vulnerable to an unauthenticated credential disclosure flaw due to improper cryptographic validation, allowing attackers to forge tokens and access sensitive stream keys for external platforms.
An unauthenticated unrestricted file upload vulnerability exists in the Profile Builder Plugin for WordPress, allowing remote attackers to upload arbitrary files via the avatar upload handler.
A flaw in ash_ai allows unauthenticated attackers to bypass DNS-rebinding protections via malicious web pages, leading to unauthorized cross-site requests to a user's local MCP server.
A cookie validation flaw in ash_admin allows an attacker controlling a sibling subdomain to hijack an administrator session by injecting shadowing cookies.
A SQL injection vulnerability in the Online Medicine Delivery System v1.0 password recovery interface allows unauthenticated remote attackers to execute arbitrary database queries via the phonenumber parameter.
A SQL injection vulnerability in the Online Medicine Delivery System 1.0 allows unauthenticated remote attackers to execute arbitrary database queries via the category parameter.
The Online Medicine Delivery System contains a SQL injection vulnerability in the product search interface, allowing unauthenticated remote attackers to execute arbitrary database queries.
The itsourcecode Online Medicine Delivery System 1.0 contains an unauthenticated SQL injection vulnerability in the product detail page, allowing remote attackers to extract sensitive database information.
A SQL injection vulnerability exists in the itsourcecode Online Medicine Delivery System 1.0, specifically in the Customer::cusAuthentication function within login.php.
A SQL injection vulnerability in the itsourcecode Online Medicine Delivery System 1.0 allows unauthenticated remote attackers to bypass authentication via the emp_email parameter in login.php.
SeaCMS versions 13.0 through 13.6 contain an SQL injection vulnerability in the zyapi.php file, allowing unauthenticated remote attackers to manipulate database queries via the ids parameter.
A use-after-free vulnerability in the Chromoting component of Google Chrome allows a remote attacker to achieve arbitrary code execution via crafted network traffic.
A use after free vulnerability in Google Chrome for iOS allows a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic.
A use after free vulnerability in the Chromoting component of Google Chrome on Windows allows remote attackers to execute arbitrary code via crafted network traffic.
A stored cross-site scripting (XSS) vulnerability in ash_admin allows lower-privileged users to execute malicious scripts in an administrator's browser session via crafted record labels.
A Server-Side Request Forgery (SSRF) vulnerability exists in the PowerJob transport endpoint, allowing unauthenticated attackers to initiate unauthorized outbound TCP connections.
An unauthenticated authorization bypass in the AdminDao servlet of Soarkey StudentManagement allows remote attackers to execute administrative functions without valid credentials.
SeaCMS versions up to 13.6 are vulnerable to remote code execution due to improper handling of user input within the Template Engine, allowing attackers to inject arbitrary PHP code via search parameters.
Google Chrome contains an incorrect authorization vulnerability in its USB implementation that could allow a remote attacker to execute arbitrary code outside the sandbox.
ToolJet Database contains a privilege escalation vulnerability in the join_tables endpoint, allowing authenticated users to access data from unauthorized workspaces.
A race condition in the V8 engine of Google Chrome allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
A race condition in the ANGLE graphics component of Google Chrome allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page.
Google Chrome contains a flaw in Media workflow enforcement that enables a remote attacker, who has compromised the renderer process, to execute code outside the security sandbox via a crafted HTML page.
Google Chrome on Windows contains an input validation flaw in the Media component that allows remote code execution outside the sandbox following a renderer process compromise.
Pake before 3.13.1 is vulnerable to path traversal via the download_file command, allowing unauthenticated attackers to write arbitrary files and achieve code execution on the user account.
An unauthenticated resource exhaustion vulnerability in ash_graphql allows attackers to bypass query complexity limits, causing unbounded database reads through specifically crafted GraphQL queries.
The SiYuan Windows installer uses an uncontrolled search path, allowing local attackers to execute arbitrary code with elevated privileges by placing a malicious binary in the installer directory.
Hulumi versions before 1.3.2 are susceptible to arbitrary code execution due to an untrusted search path flaw that allows malicious workspace files to shadow legitimate helper scripts.
Qubes OS is vulnerable to OS command injection in the qvm-copy-to-vm utility, allowing arbitrary command execution from an attacker-controlled qube.
ToolJet fails to validate organization membership in database read routes, allowing authenticated users to access sensitive data from other organizations via manipulated URL parameters.
WWBN AVideo contains a brute-force rate limiting bypass in the enforceRateLimit function, allowing unauthenticated attackers to perform unrestricted password-guessing attacks.
Admidio versions before 5.0.12 contain an authentication bypass vulnerability in RSS feed endpoints, allowing unauthenticated attackers to access private forum and announcement content.
Jina AI reader contains a server-side request forgery vulnerability that allows unauthenticated attackers to bypass private-address protections when deployed outside of Google Cloud environments.
A race condition in Google Chrome for Android prior to version 152.0.7977.65 allows a local attacker to execute arbitrary code outside the sandbox via a co-installed application.
A resource consumption vulnerability in Apache Tomcat allows remote attackers to trigger an allocation leak in HTTP/2 backlog tracking when a stream is reset, causing a denial of service.
An off-by-one error in the Apache Tomcat RewriteValve causes rewrite processing to restart at the second rule instead of the first, potentially allowing for access control bypass.
A race condition in the Enterprise component of Google Chrome on Windows allows an adjacent attacker to execute arbitrary code outside the sandbox through crafted network traffic.
Kaltura HTML5 Video Player contains a local file disclosure vulnerability in mwEmbedLoader.php, allowing unauthenticated attackers to read arbitrary files via the ServiceUrl parameter.
A missing authorization vulnerability in Google Chrome for Android's CustomTabs component allows a local attacker to execute arbitrary code outside the sandbox via a malicious co-installed application.
A path traversal vulnerability in ash_admin allows authenticated attackers to write arbitrary files to the server, potentially leading to remote code execution.
A flaw in the Undertow web server handles WebSocket connections without proper resource limits, allowing remote attackers to cause a denial of service via memory or resource exhaustion.
An improper HTML sanitization vulnerability in the Readest e-book reader allows unauthenticated attackers to achieve remote code execution via malicious EPUB files.
AJCloud AJY IPC firmware contains a path traversal vulnerability allowing unauthenticated remote attackers to read arbitrary files with root privileges via the jdbhttpd web service.
A flaw in the ash_phoenix SubdomainHook allows bypass of tenant-scoped authorization checks because the tenant identifier is incorrectly evaluated as nil during the initial mount process.
An unchecked return value in ash_postgres allows authenticated users to perform tenant name collisions, potentially leading to unauthorized cross-tenant data access.
The Keploy agent control-plane HTTP server binds to all interfaces without authentication, allowing unauthenticated attackers to steal TLS session keys or manipulate recording sessions.
A stack-based buffer overflow in the NASA Trick JSONVariableServer component allows remote attackers to potentially achieve arbitrary code execution via crafted JSON payloads.
RubyGems is vulnerable to a path traversal flaw during gem extraction, caused by improper validation of filesystem symlinks, which could allow files to be written outside the intended directory.
A vulnerability in Linux Foundation Magma 1.9.0 allows remote attackers to bypass integrity protection mechanisms by sending specially crafted NAS packets to the SecurityModeComplete handler.
NextChat versions 2.15.8 through 2.16.1 contain an improper URL validation flaw in the proxy endpoint, allowing unauthenticated attackers to exfiltrate the server's OpenAI API key.
Kamailio contains an out-of-bounds read vulnerability in the AVP Handler component due to improper length validation when processing Diameter answer AVPs.
A command injection vulnerability exists in the setUssd function of the TOTOLINK NR1800X router, allowing remote attackers to execute arbitrary commands via the ussd parameter.
D-Link DIR-825M firmware version 1.1.8 contains a command injection vulnerability in the /boafrm/formSysCmd endpoint, allowing remote attackers to execute arbitrary commands with root privileges.
A race condition vulnerability in the FileCodeBox update_file_usage function allows unauthenticated remote attackers to bypass file download limits and access restricted content.
The ash_ai library improperly handles embedding provider errors, leading to the exposure of sensitive credentials and request state in user-facing validation messages.
SiYuan versions before 3.8.1 are vulnerable to stored cross-site scripting in confirmDialog() due to improper neutralization of package and notebook names.
SiYuan versions before 3.8.1 are vulnerable to stored cross-site scripting due to improper sanitization of block name, alias, and memo fields in various rendering functions.
Colorful iGameCenter version 2.0.0.81 contains an improper privilege management vulnerability in WinRing0x64.sys, allowing local attackers to escalate privileges via crafted IOCTL requests.
A resource exhaustion vulnerability in ash_admin allows authenticated users to crash the BEAM virtual machine by flooding LiveView event handlers with unvalidated input.
The @hulumi/policies package is vulnerable to a parent spoof bypass, allowing unauthenticated attackers to submit falsified SecureBucket evidence to evade security policy enforcement.
Nodemailer versions before 9.0.1 fail to enforce file and URL access restrictions in raw message options, enabling authenticated attackers to perform arbitrary file reads or server-side request forgery.
A vulnerability in ash_ai allows authenticated users to bypass authorization checks, enabling the unauthorized modification or destruction of database records via manipulated tool arguments.
An incorrect authorization flaw in ash_graphql allows authenticated users to access data belonging to other tenants via GraphQL subscriptions due to improper in-memory policy evaluation.
An improper check in the FreeBSD hwpmc module allows local users to continue monitoring processes after they execute setuid or setgid binaries, bypassing intended security policies.
A race condition in the FreeBSD TIOCSCTTY ioctl handler allows local unprivileged users to escalate privileges by linking a terminal that is being destroyed to a process session.
A local file path manipulation vulnerability exists in the SonicWall NetExtender Linux client due to insecure handling of temporary files during the auto-upgrade process.