CVE-2026-8452
A memory overflow vulnerability in NetScaler ADC and Gateway appliances configured as SSL VPN, ICA, or AAA servers may lead to service disruption or Denial of Service (DoS).
Critical vulnerabilities, curated daily for security professionals
Google Chrome, D-Link ShareCenter NAS, and a set of embedded network appliances account for the highest-impact disclosures, with remote code execution and authentication bypass the dominant patterns. The day brought 44 critical CVEs (CVSS 9.0 and above), up 69% from the prior day's 26, alongside 80 high-priority issues, a 19% increase from 67. Named critical entries include CVE-2026-82971 (CVSS 10, QVidium Opera11), CVE-2026-83524 (CVSS 9.9, RedPort Optimizer wXa series), and CVE-2026-82692 (CVSS 9.9, D-Link DNS-340L and DNS-345 ShareCenter), with CVE-2026-78948 and CVE-2026-78904 (both CVSS 9.6) affecting Google Chrome. Edge and IoT devices, WordPress plugins (WPLP Cookie Consent, Tickera), and enterprise infrastructure such as NetScaler ADC, JFrog Artifactory, and PaperCut MF/NG make up the bulk of exposure, and 11 entries carry confirmed active exploitation. No vendor patch links were confirmed for the newly disclosed set at publication time (0% patch availability), so treat mitigation and network-level restriction as the near-term posture while monitoring vendor advisories.
Immediate action: Prioritize Google Chrome updates across the fleet, then internet-facing infrastructure running NetScaler ADC and Gateway, JFrog Artifactory, and PaperCut MF/NG, all of which appear on the actively exploited list. Embedded and edge devices (QVidium, RedPort Optimizer, D-Link ShareCenter, Ebyte, ZTE) have no confirmed patches yet, so restrict management interfaces to trusted networks and monitor vendor advisories for fixes.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A memory overflow vulnerability in NetScaler ADC and Gateway appliances configured as SSL VPN, ICA, or AAA servers may lead to service disruption or Denial of Service (DoS).
A remote code execution vulnerability exists in Microsoft SQL Server due to improper handling of internal functions, allowing authenticated attackers to execute arbitrary code.
An authentication bypass in ownCloud core allows unauthenticated attackers to access, modify, or delete files if the victim username is known and no signing key is configured.
An improper memory calculation vulnerability exists in the Linux kernel's IPv6 paged-allocation path, potentially leading to memory corruption.
Ajax.NET Professional is vulnerable to deserialization of untrusted data, which can be exploited by unauthenticated attackers to achieve remote code execution.
A race condition in the Red Hat Libuser userhelper program allows local users to cause a denial of service by corrupting the system password file.
The ABRT tool contains a local privilege escalation vulnerability via symlink attacks on predictable file names in /var/tmp or /var/spool, allowing authenticated local users to gain root privileges.
A critical out-of-bounds memory write vulnerability exists in the Linux kernel watch_queue event notification subsystem, allowing local users to gain elevated privileges or cause a system crash.
An authenticated user can perform path traversal to write data outside the intended Docker cache directory in JFrog Artifactory due to improper input validation.
PaperCut MF and NG are vulnerable to unsafe dynamic class loading in database utilities, allowing attackers to execute arbitrary Java bytecode via manipulated system configuration parameters.
An improper access control flaw in PaperCut MF/NG allows unauthenticated remote attackers to modify system configurations by bypassing validation checks for administrative functions.
A buffer overflow vulnerability in the WebGL component of Google Chrome allows remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page.
QVidium Opera11 contains a command injection vulnerability in the net_tr.cgi script via the ipaddr parameter, allowing unauthenticated remote code execution.
A command injection vulnerability in the RedPort Optimizer system clock component allows remote attackers to execute arbitrary commands via the datetime.php file.
A type confusion vulnerability in the ANGLE component of Google Chrome allows remote attackers to execute arbitrary code via a specially crafted HTML page.
The WPLP Cookie Consent plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads via the saas_upload_logo function, potentially leading to remote code execution.
A critical PHP object injection vulnerability in the Tickera WordPress plugin allows unauthenticated attackers to execute arbitrary code via deserialization of untrusted data.
The Ebyte NA111-M firmware utilizes a deprecated hashing algorithm for authentication, which may allow an unauthenticated attacker to bypass security controls and gain unauthorized access.
A command injection vulnerability in the ZTE ZXDU68 S202 V5.0 allows unauthenticated attackers to gain root privileges, delete critical system files, and compromise power system configurations.
An OS command injection vulnerability in eObčanka-Identifikace on macOS allows attackers to execute arbitrary commands via unsanitized URL parameters passed to an AppleScript wrapper.
D-Link DNS-340L and DNS-345 devices are vulnerable to OS command injection via the iscsi_mgr.cgi script, allowing authenticated remote attackers to execute arbitrary commands.
An OS command injection vulnerability exists in the ISO Image Handler component of multiple D-Link NAS devices, allowing authenticated remote attackers to execute arbitrary commands via the upIsoRootPath.
D-Link ShareCenter NAS devices are vulnerable to OS command injection via the f_ups_ip parameter in the usb_device.cgi script, allowing authenticated remote attackers to execute arbitrary shell commands.
An OS command injection vulnerability in the D-Link ShareCenter NAS allows authenticated remote attackers to execute arbitrary commands via the f_dev parameter in /cgi-bin/ve_mgr.cgi.
D-Link DNS-340L and DNS-345 NAS devices are vulnerable to OS command injection via the virtual_vol.cgi handler, allowing authenticated attackers to execute arbitrary commands with system privileges.
MCPHub allows authenticated non-admin users to execute arbitrary system commands via unvalidated API endpoints, leading to full remote code execution with elevated privileges.
A missing authentication vulnerability in the Tenda AC1206 Web UI allows unauthenticated remote attackers to trigger manufacturing functions via the /goform/ate endpoint.
A critical missing authentication vulnerability in the Tenda AC18 router allows remote, unauthenticated attackers to enable and access the Telnet management shell via the /goform/telnet endpoint.
A vulnerability in Tenda AC1206 firmware 15.03.06.23 allows unauthenticated remote attackers to enable the Telnet service via the /goform/telnet endpoint, potentially leading to unauthorized access.
A command injection vulnerability in the Cobham SATCOM VSAT7090 router allows remote attackers to execute arbitrary commands via the mail-report.sh script.
Dokploy versions up to 0.29.7 contain a path traversal vulnerability in the writeTraefikConfigInPath function, allowing authenticated attackers to manipulate file paths remotely.
Goploy suffers from an authorization bypass vulnerability allowing authenticated users to perform unauthorized file operations and achieve remote code execution across namespaces.
A Time-of-Check Time-of-Use race condition in Sauter automation controllers allows unauthenticated remote attackers to bypass security controls and execute unauthorized code.
An unauthenticated SQL injection vulnerability in the WP Data Access plugin allows remote attackers to execute arbitrary SQL commands.
A critical SQL injection vulnerability in the Smart Marketing SMS and Newsletters Forms plugin allows unauthenticated attackers to query the database.
The Throws SPAM Away WordPress plugin contains an unauthenticated SQL injection vulnerability in versions 3.8.2 and earlier, allowing remote attackers to extract sensitive database information.
A critical input validation vulnerability in the Silk Themes Newspapers X WordPress theme allows for the installation of malicious software.
A critical vulnerability in the Hash Form WordPress plugin allows unauthenticated attackers to perform arbitrary file uploads, potentially leading to full system compromise.
The Ebyte NA111-M firmware contains an authentication bypass vulnerability in its configuration utility, allowing unauthenticated attackers to modify critical settings or credentials.
Spring Framework is susceptible to a header predicate bypass in pre-flight requests when using WebFlux functional endpoints with DispatcherServlet, potentially allowing unauthorized access.
Spring MVC applications using the functional web framework are vulnerable to stream corruption via CRLF injection when utilizing Server-Sent Events (SSE).
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to delete firewall filter rules via a crafted POST request.
An access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to enable WAN-side administration via a crafted POST request to the cgi-bin interface.
The disconf configuration management platform contains an incorrect access control vulnerability allowing unauthenticated access to sensitive configuration-fetching APIs.
A NULL pointer dereference vulnerability in the Linux kernel KVM s390 PCI subsystem allows for potential system crashes or code execution due to improper error handling during AIBV allocation.
A buffer overflow vulnerability in the Linux kernel idpf driver allows an attacker to trigger a slab out of bounds write via a malicious VIRTCHNL2_OP_ALLOC_VECTORS reply.
A safety guard bypass vulnerability in Spring Framework allows unauthenticated attackers to manipulate SpEL expressions when the compiler is active, potentially leading to unauthorized data integrity loss.
A SQL injection vulnerability exists in the /superdiamond/preview/ endpoint of super-diamond-server 1.3.3 and earlier due to improper sanitization of the module parameter.
A critical unrestricted file upload vulnerability in the WP Cookie Notice plugin allows unauthenticated attackers to upload and execute arbitrary malicious files.
An incorrect access control vulnerability in the TOTOLINK T6 NTPSyncWithHost function allows unauthenticated attackers to modify the system clock via a crafted POST request.
TOTOLINK T6 routers contain an incorrect access control vulnerability in the delWiFiAclRules function, allowing unauthenticated attackers to remove Wi-Fi ACL rules via crafted POST requests.
An incorrect access control vulnerability in the TOTOLINK T6 setPasswordCfg function allows unauthenticated attackers to modify administrator account settings via a crafted POST request.
An incorrect access control flaw in the TOTOLINK T6 router allows unauthenticated attackers to modify device LED settings via a crafted POST request to the administrative CGI interface.
Denx U-Boot contains an integer overflow vulnerability in its ZFS filesystem support, which can be triggered by malformed metadata to cause memory corruption and potential code execution.
JetLinks Community version 2.11 contains a server-side request forgery (SSRF) vulnerability in the device metadata import interface, allowing unauthenticated attackers to perform unauthorized requests.
A file upload vulnerability in elFinder allows unauthenticated attackers to bypass MIME type restrictions and achieve remote code execution via malicious file extraction.
A Server-Side Request Forgery (SSRF) vulnerability in elFinder allows unauthenticated attackers to bypass protections and read internal network resources via DNS rebinding during URL uploads.
The ProfilePress WordPress plugin before 4.17.2 is vulnerable to unauthenticated remote code execution via a brute-forceable 32-bit token in the ppress_connect_process AJAX handler.
The Frontend Admin by DynamiApps plugin for WordPress contains a path traversal vulnerability in the move_folders function, allowing unauthenticated attackers to delete arbitrary files on the server.
Wallos versions prior to 4.9.4 contain an authentication bypass vulnerability in endpoints/db/import.php allowing unauthenticated attackers to overwrite the application database.
Wallos versions prior to 4.9.4 are vulnerable to an OIDC state validation flaw, allowing attackers to perform account linking attacks via a crafted URL.
Wallos versions prior to 4.9.4 contain an authentication bypass vulnerability in the migration endpoint, allowing unauthenticated attackers to execute database schema migrations.
Eclipse Theia's AI Agent Mode lacks workspace-containment checks for file operations, allowing unauthenticated attackers to perform arbitrary file writes or deletions via indirect prompt injection.
ShopEx ECShop is vulnerable to remote SQL injection via the flow_update_cart function in /flow.php, allowing unauthenticated attackers to manipulate the rec_id argument.
A SQL injection vulnerability in Hospital-Management-System 1.0 allows remote, unauthenticated attackers to execute malicious database queries via the Contact argument in search.php.
The Online Shopping System version 1.0 contains a time-based blind SQL injection vulnerability in the search functionality, allowing unauthenticated remote attackers to extract backend database data.
Wallos contains an unauthenticated Server-Side Request Forgery vulnerability in the logo-image search endpoint due to improper cURL proxy configuration.
Kirby CMS is vulnerable to path traversal via the media handler and file versioning components, allowing unauthenticated remote attackers to read arbitrary files and delete job files.
ShopEx ECShop versions 2.5.0 and 2.5.1 contain an unrestricted file upload vulnerability in the check_img_type function of admin/pack.php, allowing remote unauthenticated attackers to upload malicious files.
The ActiveInbox Extension for Chrome contains hard-coded Google OAuth client secrets in its service worker, allowing remote attackers to potentially misuse these credentials.
A race condition vulnerability in the ReadAloud feature of Google Chrome allows a remote attacker to execute arbitrary code within the sandbox via a crafted HTML page.
Google Chrome contains a privilege management flaw in Navigation, allowing remote attackers to potentially execute arbitrary code outside the sandbox via a crafted HTML page.
A GPU input validation flaw in Google Chrome on Android allows a remote attacker who has compromised the renderer process to escape the sandbox and execute arbitrary code via a crafted HTML page.
A critical improper input validation flaw in the Google Chrome Chromecast component allows remote attackers to achieve sandbox escape and execute arbitrary code via a malicious HTML page.
A remote attacker who has compromised the renderer process in Google Chrome for Android can exploit improper input validation to execute arbitrary code outside the sandbox via a crafted HTML page.
A Server-Side Request Forgery (SSRF) vulnerability in Wallos allows an authenticated administrator to perform unauthorized internal network requests via unvalidated OIDC configuration URLs.
A path traversal vulnerability in Wallos allows an authenticated administrator to upload a malicious ZIP file, leading to arbitrary file write and potential remote code execution.
A Server-Side Request Forgery vulnerability in the testemailnotifications.php endpoint of Wallos allows authenticated users to probe internal network resources and cloud metadata services.
The Support Genix plugin for WordPress is vulnerable to authentication bypass via weak encryption, allowing authenticated attackers to perform administrative account takeover.
A remote code execution vulnerability in klaussilveira GitList 2.0.0 allows unauthenticated attackers to execute arbitrary OS commands via a manipulated Git configuration.
A flaw in RESTEasy's SourceProvider allows unauthenticated remote file reading via XML External Entity (XXE) injection.
The Keep Backup Daily WordPress plugin before 2.1.4 allows unauthenticated attackers to trigger and download full MySQL database backups via the kbd_cron_process parameter.
The Project Manager WordPress plugin before 4.0.7 contains a missing authorization vulnerability that allows unauthenticated users to create accounts with known passwords.
The OpenSearch SQL plugin contains an unsafe deserialization flaw in the cursor pagination component, enabling remote code execution by authenticated users via a crafted cursor parameter.
An improper authentication vulnerability in Apache Hive allows unauthenticated attackers to forge SAML bearer tokens and gain unauthorized access to HiveServer2 sessions.
Tornado is vulnerable to uncontrolled resource consumption, where unauthenticated requests can stall the event loop via large, malformed form-encoded request bodies.
Devtron versions through 2.2.0 contain a missing authorization flaw in the webhook API token endpoint, allowing authenticated users to retrieve plaintext super-admin JWT tokens.
A memory corruption vulnerability in the D-Link DSM-G600 multipart handler allows authenticated remote attackers to trigger a denial of service via specifically crafted configuration files.
A critical eval injection vulnerability in cPanel allows authenticated remote users to execute arbitrary code with root privileges.
A stored Cross-Site Scripting (XSS) vulnerability in the Helix Ultimate extension for Joomla allows high-privileged users to inject malicious scripts into MegaMenu layout configurations.
EasyAdminBundle contains an authorization bypass vulnerability where improper validation of the routeName query parameter allows authenticated users to access restricted controllers.
An SQL injection vulnerability in the Ankara Hosting Site Management Panel allows authenticated users to execute arbitrary SQL commands.
The Charitable WordPress plugin contains an SQL injection vulnerability allowing authenticated subscribers to execute unauthorized database queries.
A Server-Side Request Forgery vulnerability exists in the Hyperledger Firefly Webhook Subscription component, allowing remote attackers to manipulate URL parameters via the ValidateOptions function.
A missing authentication vulnerability in the create_app function of cu silicon allows unauthenticated remote attackers to manipulate the edit endpoint.
MegaEase EaseProbe versions 2.3.0 and earlier contain an IP spoofing vulnerability in the web server middleware, allowing remote attackers to bypass IP-based access controls and rate limiting.
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in NASA earthdata-search allows remote attackers to perform internal network mapping and host discovery via the scale endpoint.
An authentication bypass vulnerability in Pangolin allows unauthenticated attackers to access protected resources by manipulating URL parameters in the share-link endpoint.
A privilege escalation vulnerability in the Fluent Forms Pro Add On Pack plugin for WordPress allows authenticated subscribers to gain unauthorized administrative privileges.
A privileged file upload bypass exists in the Helix Ultimate extension for Joomla, where insufficient MIME type validation allows attackers to upload malicious files disguised as images.
A memory corruption vulnerability in WebKitGTK allows for potential code execution when processing malicious web content.
MSI Dragon Center contains an integer overflow vulnerability in the NTIOLib_X64.sys driver, which can be triggered by a local attacker to achieve system-wide compromise.
A local privilege escalation vulnerability in the Ultra RAMDisk Pro URDSCSI.sys kernel driver allows standard users to perform unauthorized writes to protected registry keys.
The Ebyte NA111-M firmware fails to properly separate user and administrative management functions, allowing low-privileged authenticated users to access and modify sensitive configuration settings.
A missing authentication check in multiple free miniOrange Joomla extensions allows unauthenticated attackers to remotely deinstall arbitrary extensions from the affected site.
An unauthenticated resource exhaustion vulnerability in ash_typescript allows attackers to crash the BEAM virtual machine by flooding the atom table with arbitrary field names.
MCPHub contains an authorization bypass vulnerability in the PUT /api/system-config endpoint, allowing authenticated users to perform unauthorized configuration updates.
A heap-based buffer overflow in the ppp(8) utility's mp_SetEnddisc() function allows a local user to crash the service or achieve arbitrary code execution with root privileges.
An unauthenticated resource exhaustion vulnerability in ash_typescript allows attackers to crash the BEAM virtual machine by flooding the atom table with arbitrary input.
An incorrect authorization flaw in ash_typescript allows unauthorized RPC callers to access sensitive attribute values that should have been restricted by Ash field policies.
The Phison PS3111-S11 controller firmware incorrectly verifies RSA signatures by using a modulus embedded in the firmware image, allowing attackers to load arbitrary, malicious firmware.
Wallos versions 4.0.0 through 4.9.5 contain an authentication bypass vulnerability in the OIDC login flow, allowing unauthenticated attackers to hijack accounts by spoofing email claims.
A critical authentication bypass vulnerability in the SiteGround Security WordPress plugin allows unauthenticated attackers to circumvent security controls.
A vulnerability in oasdiff-action allows unauthenticated attackers to trigger SSRF and disclose sensitive files on the runner via malicious OpenAPI specs containing external references.
A command injection vulnerability in Pardus Boot Repair allows local attackers to execute arbitrary OS commands via improper neutralization of input.
MCPHub contains an incorrect authorization vulnerability where bearer keys can incorrectly grant access to unauthorized servers within a group.
Nokia WaveSuite contains a broken access control vulnerability in the CPB Log Files feature, allowing low-privileged users to access restricted administrative pages.
A path traversal vulnerability in pnpm allows malicious tarball dependencies to overwrite arbitrary files outside the node_modules directory, potentially leading to remote code execution.
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to an unauthenticated broken access control flaw, allowing unauthorized integrity impacts.
A missing authorization flaw in TBC Technology KitLogistic allows unauthenticated attackers to access restricted application functionality due to improper access control list constraints.
YaCy Search Server fails to disable external entity resolution in its SVG, FreeMind, and OpenSearch parsers, enabling XML external entity injection attacks.
RegistrationMagic contains an unauthenticated broken authentication vulnerability that allows attackers to bypass security controls via an alternate path or channel.
A type mismatch in the zbus_polkit crate leads to a time-of-check/time-of-use (TOCTOU) race condition, allowing local attackers to bypass polkit authorization checks via PID reuse.
A Cross-Site Request Forgery vulnerability in Unraid OS allows unauthenticated remote attackers to perform unauthorized actions and escalate privileges due to lax cookie policies.
A path traversal vulnerability in the Goploy backend API endpoint /deploy/fileDiff allows authenticated attackers to read arbitrary files from the server filesystem.
A cross-tenant authorization bypass in MCPHub allows authenticated non-admin users to execute tools on MCP servers owned by other users, leading to unauthorized file access and SSRF.
MCPHub contains a Server-Side Request Forgery (SSRF) vulnerability due to an incomplete blocklist in its IPv6 address validation logic, allowing attackers to reach internal infrastructure.
A kernel credential handling flaw in FreeBSD allows authenticated users to elevate privileges to the wheel group through improper group ID transitions in the mac_do function.
A use-after-free vulnerability in the FreeBSD sound subsystem allows local, unprivileged users to achieve privilege escalation via a race condition in sync group ioctl handling.
A use-after-free vulnerability in the FreeBSD SOCK_STREAM receive path allows an unprivileged local user to escalate privileges via improper control message handling.
Applications evaluating user-supplied SpEL expressions are vulnerable to a Denial of Service (DoS) attack via the power operator with large exponents.
A memory corruption vulnerability in the GDB STABS debug parser allows attackers to achieve arbitrary code execution by crafting a malicious ELF binary file.
HTML::FormFu allows unauthenticated remote attackers to trigger resource exhaustion by providing an unbounded repeat count via query string parameters in Repeatable elements.
A flaw in the openRISC OR1200 processor architecture allows for a denial of service due to inaccurate program counter updates during special purpose register changes.
A path traversal vulnerability in the UnPoller 2.33.0 password field allows unauthenticated attackers to perform arbitrary file reads and network exfiltration.