CVE-2026-49869
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
Critical vulnerabilities, curated daily for security professionals
Cisco network infrastructure leads the disclosures from yesterday, with CVE-2026-20274 and CVE-2026-20279 in IOS XR Software and CVE-2026-20212 in NX-OS Software all rated CVSS 9.8. Twenty critical CVEs were disclosed, a 29% decrease from the prior day, along with 60 high-priority CVEs, down 43%. Other critical issues include CVE-2026-4357 (CVSS 10) in the WordPress Embed HTML5 Game plugin, CVE-2026-85031 (CVSS 9.9) in the TOTOLINK CP450 router, and CVE-2026-66786 (CVSS 9.1) in Red Hat Advanced Cluster Management for Kubernetes. Network devices, WordPress plugins, and container orchestration platforms account for most of the critical activity, with 10 CVEs under active exploitation spanning SonicWall SMA1000, JFrog Artifactory, PaperCut MF/NG, Kestra, and LiteLLM. No patch availability data is confirmed for the day's disclosures, so teams should check vendor advisories directly and apply compensating controls where fixes are not yet published.
Immediate action: Prioritize Cisco IOS XR and NX-OS devices, SonicWall SMA1000 appliances, JFrog Artifactory, and PaperCut MF/NG servers, since these combine high severity with confirmed exploitation or broad network exposure. Patch availability is unconfirmed for the critical disclosures, so consult vendor advisories now, restrict management interface exposure, and monitor for exploitation indicators until fixes are applied.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
JFrog Artifactory contains an authentication weakness that may allow an unauthenticated attacker to obtain administrative privileges via remote network access.
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition that allows remote attackers to execute arbitrary database commands via the /pa endpoint.
A post-authentication OS command injection vulnerability exists in the SonicWall SMA1000 Appliance Management Console, allowing an authenticated administrator to execute arbitrary OS commands.
A pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the SonicWall SMA1000 Work Place interface allows remote unauthenticated attackers to perform unauthorized operations.
An authenticated user can perform path traversal to write data outside the intended Docker cache directory in JFrog Artifactory due to improper input validation.
PaperCut MF and NG are vulnerable to unsafe dynamic class loading in database utilities, allowing attackers to execute arbitrary Java bytecode via manipulated system configuration parameters.
An improper access control flaw in PaperCut MF/NG allows unauthenticated remote attackers to modify system configurations by bypassing validation checks for administrative functions.
LiteLLM proxy server contains a critical authentication vulnerability that allows unauthenticated access to sensitive functions.
A critical HTTP request smuggling vulnerability exists in the Starlette framework due to improper validation of the Host header, allowing for security restriction bypasses.
The Embed HTML5 Game WordPress plugin allows unauthenticated attackers to upload arbitrary files, leading to potential remote code execution via PHP backdoors.
The WatchMan-Site7 WordPress plugin contains a code injection vulnerability in its debugging console that allows authenticated users to execute arbitrary PHP code on the server.
Cisco IOS XR Software contains a vulnerability involving improper resource control, which may allow an unauthenticated attacker to impact system availability and integrity.
Cisco IOS XR Software contains multiple improper access control vulnerabilities identified during an internal security review, potentially allowing unauthorized system access.
Joro versions prior to 1.1.1 contain an authentication bypass and CSRF vulnerability allowing unauthenticated remote code execution via malicious cross-origin requests.
A code injection vulnerability in Submariner allows authenticated attackers to achieve remote code execution as root by injecting malicious directives into the CableName configuration.
A critical vulnerability in the Silicon One integration for Cisco Nexus 9000 switches allows unauthenticated remote attackers to execute arbitrary code with root privileges via TCP ports 43210 and 43211.
The Developer Tools WordPress plugin contains an unauthenticated arbitrary file upload vulnerability within its bundled SWFUpload component.
The Workeera WordPress plugin contains a flaw allowing authenticated subscribers to delete arbitrary files on the server due to insufficient path validation.
A buffer overflow vulnerability in the TOTOLINK CP450 /cgi-bin/cstecgi.cgi file allows authenticated remote attackers to execute arbitrary code via the topicurl argument.
A critical OS command injection vulnerability exists in the Looking Glass network-diagnostic platform due to improper input validation, allowing unauthenticated remote code execution.
The Authorizer plugin for WordPress contains an unauthenticated privilege escalation vulnerability due to incorrect privilege assignment, allowing unauthorized users to gain elevated access.
WCFM Marketplace for WordPress contains an unauthenticated SQL injection vulnerability in versions 3.8.1 and earlier, allowing attackers to extract sensitive database information.
A critical authentication bypass vulnerability allows unauthenticated attackers to register malicious FIDO2 credentials and gain unauthorized access to target accounts in Delinea Secret Server.
Craft CMS versions prior to 5.10.11 contain an improper privilege management flaw that allows unauthenticated attackers to inherit administrator privileges during user registration.
An incorrect authorization vulnerability in the Drupal Commerce PayPal module allows unauthenticated attackers to perform forceful browsing, potentially leading to unauthorized data access or modification.
The Linux kernel perf scheduler contains multiple memory corruption flaws when processing untrusted perf.data files, potentially allowing arbitrary code execution or system crashes.
A heap-based out-of-bounds read vulnerability exists in the Linux kernel perf tools due to insufficient validation of CPU indices derived from untrusted perf.data files.
The Prevail eBPF verifier fails to update offset variables correctly, leading to out of bounds memory access and potential runtime memory corruption.
The PREVAIL eBPF verifier incorrectly models memory writes to context registers, allowing unauthenticated attackers to bypass safety checks and perform arbitrary memory dereferences.
The User Frontend WordPress plugin contains a PHP Object Injection vulnerability due to insecure deserialization of user-supplied data during frontend post editing, potentially leading to RCE.
The Jenkins Customizable Header Plugin is vulnerable to stored cross-site scripting (XSS) via insecure Stapler data binding, allowing attackers to inject malicious JavaScript through SVG icons.
Cisco IOS XR Software contains an incorrect calculation vulnerability, categorized under CWE-682, which may impact system integrity and availability.
Cisco IOS XR Software contains improper neutralization vulnerabilities identified during an internal security review, potentially allowing an authenticated attacker to compromise system integrity.
Cisco IOS XR Software contains vulnerabilities related to the improper handling of exceptional conditions, which may lead to unauthorized system impact.
A cross-site request forgery (CSRF) vulnerability in Jenkins allows attackers to obtain a user's security crumb and perform unauthorized actions on their behalf.
The Jenkins Microsoft Entra ID plugin improperly validates Entra group permissions by display name, allowing attackers to escalate privileges via group name collisions.
A path traversal vulnerability in the Jenkins File Parameter Plugin allows authenticated attackers to write arbitrary files to the Jenkins controller file system, potentially leading to RCE.
A use after free vulnerability in the WebRTC component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A use after free vulnerability in the TabStrip component of Google Chrome allows remote attackers to execute arbitrary code via social engineering and user interaction.
A cross-origin request vulnerability in WinML CLI allows unauthenticated attackers to achieve arbitrary code execution via a malicious website.
An uninitialized resource in the V8 engine of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
Jenkins is susceptible to remote code execution due to improper handling of nested configuration objects in user-submitted config.xml documents processed via Stapler.
A form data binding vulnerability in the Stapler library within Jenkins allows authenticated users with Overall/Read permission to instantiate unauthorized configuration objects.
The Jenkins SAML Plugin contains a vulnerability allowing authenticated users to overwrite the SAML identity provider metadata file, leading to arbitrary user authentication.
A PHP Object Injection vulnerability in the Ninja Forms - Layout & Styles plugin allows unauthenticated attackers to execute arbitrary code or perform unauthorized actions.
A PHP object injection vulnerability in the WP User Frontend plugin allows authenticated subscribers to execute arbitrary code or perform unauthorized actions through deserialization.
OpenAI Codex CLI and Desktop misclassify PowerShell stop-parsing tokens, allowing unauthenticated attackers to bypass approval prompts and execute code via malicious repository configurations.
A stored cross-site scripting (XSS) vulnerability in the FAQ Builder AYS WordPress plugin allows unauthenticated attackers to execute malicious scripts in the context of an administrator.
A use-after-free vulnerability exists in the Linux kernel UFS trace events due to improper pointer dereferencing during tracepoint output, which can lead to kernel crashes.
A race condition in the Linux kernel driver core allows for potential memory corruption or privilege escalation due to improper handling of the dev->driver pointer during concurrent unbind operations.
The Linux kernel iomap implementation contains a flaw where splitting bio structures can lead to a deadlock when the bio_set is exhausted.
Spring Framework WebFlux applications using Jetty 12 Core fail to set the SameSite attribute on response cookies, increasing vulnerability to cross-site request forgery attacks.
Jenkins contains a deserialization flaw where transient fields cannot be excluded during configuration updates, potentially allowing authenticated attackers to manipulate internal system states.
The Simple Ajax Chat WordPress plugin fails to sanitize chat messages, allowing unauthenticated attackers to execute stored Cross-Site Scripting (XSS) attacks against site administrators and users.
An authenticated user can create administrative accounts via the BIG-IP Traffic Management User Interface (TMUI), leading to full system privilege escalation.
Jenkins contains a stored cross-site scripting (XSS) vulnerability in the system log viewer that allows attackers in control of agent processes to execute malicious scripts.
A path traversal vulnerability in Jenkins Allure Plugin allows authenticated attackers with Item/Read permissions to read arbitrary files on the Jenkins controller file system.
The Jenkins Performance Plugin contains a deserialization vulnerability allowing authenticated users with Item/Configure permission to execute arbitrary code on the Jenkins controller.
The Groundhogg WordPress plugin is vulnerable to stored Cross-Site Scripting (XSS) due to insufficient input sanitization, allowing unauthenticated attackers to target administrative users.
YzmCMS 7.5 contains a SQL injection vulnerability in the get_arrchildid function, allowing authenticated administrators to execute arbitrary SQL queries.
The Workeera WordPress plugin before 1.0.6 allows authenticated subscribers to perform arbitrary file reads on the server due to insufficient input validation and directory restriction.
The WP OAuth Server plugin fails to secure debug logs, enabling unauthenticated remote attackers to access sensitive OAuth tokens, authorization codes, and user password hashes.
An incomplete fix in the Nuclio dashboard allows unauthenticated attackers to perform OS command injection via HTTP headers, leading to arbitrary command execution within the container.
SEPPmail Secure Email Gateway versions prior to 15.0.7 are vulnerable to command injection, allowing authenticated administrators to execute arbitrary commands with elevated privileges.
SEPPmail Secure Email Gateway before 15.0.6 is vulnerable to insecure deserialization and OS command injection in a privileged REST API workflow.
Talassoft Industrial Management Software is susceptible to SQL injection due to improper neutralization of special elements in SQL commands, allowing unauthorized database interactions.
A memory access flaw in the Linux kernel netfilter synproxy component allows unaligned memory access, potentially leading to system crashes or performance degradation.
A Cross Site Request Forgery (CSRF) vulnerability in the Simply Schedule Appointments plugin allows unauthenticated attackers to perform unauthorized actions on behalf of a user.
An unauthenticated Cross-Site Request Forgery (CSRF) vulnerability exists in the Mang Board WP plugin for WordPress, versions 2.3.8 and earlier, allowing unauthorized actions.
Craft CMS contains a site scope bypass vulnerability in GraphQL mutation resolvers that fails to validate site identifiers, allowing unauthorized modification of entries across different sites.
Craft CMS versions prior to 5.10.11 contain an authorization flaw allowing authenticated users with specific permissions to reset administrator passwords and achieve full control-panel takeover.
Craft CMS contains an improper authorization vulnerability in the elements/save action allowing authenticated users to modify account passwords without proper validation or elevated session checks.
Craft CMS GraphQL entry mutation resolvers fail to enforce site-scope filtering, allowing authenticated attackers to modify or delete content across unauthorized sites.
Rockwell Automation DataEdgePlatform DataMosaix Private Cloud contains hardcoded links to JSON files that are accessible without authentication, leading to unauthorized customer data exposure.
LiquidThemes Booking Hub is vulnerable to an incorrect privilege assignment flaw, allowing authenticated users to escalate their privileges within the application.
A use-after-free vulnerability in the AppArmor security module of the Linux kernel could allow for denial of service or arbitrary code execution.
A use-after-free vulnerability in the Linux kernel tlclk driver allows local attackers to cause memory corruption or privilege escalation due to improper module cleanup and lifecycle management.
An out-of-bounds access vulnerability exists in the Linux kernel firmware arm_scmi driver due to a failure to validate domain numbers provided by external callers.
A memory safety issue in the Linux kernel HFS+ file system driver allows local attackers to trigger uninitialized value bugs via malformed file system images during the mounting process.
A use after free vulnerability in the Linux kernel amd-mp2 driver allows local attackers to potentially achieve code execution or system instability by triggering an I2C adapter registration failure.
An incorrect unit alignment in the RISC-V memory management subsystem of the Linux kernel causes a kernel warning and potential system instability during initialization.
A NULL pointer dereference in the Linux kernel network component can lead to a system crash during the emac probe process.
A null pointer dereference vulnerability exists in the Linux kernel IPv6 stack within the __in6_dev_stats_get function, which can be triggered when a physical device is unregistered.
Spring WebFlux applications with WebSocket support may inadvertently leak sensitive request headers within exception messages, potentially exposing user data to unauthenticated attackers.
A NULL pointer dereference vulnerability exists in the Linux kernel netfilter component, specifically within the xt_nat SNAT and DNAT target handlers, potentially allowing local privilege escalation.
A memory over-read vulnerability exists in the Linux kernel CXL subsystem, where an incorrect buffer size definition allows unauthorized access to kernel stack memory via trace events.
A local symlink attack in the Linux kernel intel-speed-select daemon allows unprivileged users to overwrite arbitrary files when the daemon runs with root privileges.
A memory management flaw in the Linux kernel KVM arm64 implementation allows a local attacker to trigger a system crash via an unhandled translation failure.
The prevail eBPF verifier incorrectly handles ALU32 pointer arithmetic, allowing unprivileged users to bypass safety checks and cause runtime faults or system instability.