CVE-2026-49869
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
Critical vulnerabilities, curated daily for security professionals
Yesterday's disclosures were led by three Google Chrome vulnerabilities rated CVSS 9.6, a cluster of CVSS 9.8 flaws in the themoos core-moos framework, and critical issues in WordPress plugins from Divi Engine and WPFunnels. Critical CVEs reached 52, up 160% from the prior day's 20, while high-priority CVEs rose 30% to 78. Notable entries include CVE-2026-85042 in Google Chrome, CVE-2026-11613 in the Divi Ajax Filter plugin, CVE-2026-85181 in Dianping CAT, and CVE-2026-85216 in the MISP threat intelligence platform. Browser memory safety bugs, WordPress plugin input handling flaws, and open-source framework weaknesses dominate the set, with additional exposure for security tooling and monitoring platforms. Nine CVEs carry confirmed active exploitation, including SonicWall SMA1000, PaperCut MF/NG, JFrog Artifactory, Kestra, LiteLLM, and Starlette, and no patch availability was recorded for the day's set, so defenders should verify vendor advisories directly and apply compensating controls where fixes are not yet published.
Immediate action: Prioritize Google Chrome updates, exposed SonicWall SMA1000 and PaperCut MF/NG appliances, JFrog Artifactory, and internet-facing WordPress sites running Divi Ajax Filter or Mail Mint, along with Python services built on Starlette or LiteLLM. Patch availability was not recorded for these disclosures, so check vendor advisories for current fix status and restrict network exposure of affected systems until updates are confirmed.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
JFrog Artifactory contains an authentication weakness that may allow an unauthenticated attacker to obtain administrative privileges via remote network access.
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition that allows remote attackers to execute arbitrary database commands via the /pa endpoint.
A pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the SonicWall SMA1000 Work Place interface allows remote unauthenticated attackers to perform unauthorized operations.
A post-authentication OS command injection vulnerability exists in the SonicWall SMA1000 Appliance Management Console, allowing an authenticated administrator to execute arbitrary OS commands.
PaperCut MF and NG are vulnerable to unsafe dynamic class loading in database utilities, allowing attackers to execute arbitrary Java bytecode via manipulated system configuration parameters.
An improper access control flaw in PaperCut MF/NG allows unauthenticated remote attackers to modify system configurations by bypassing validation checks for administrative functions.
LiteLLM proxy server contains a critical authentication vulnerability that allows unauthenticated access to sensitive functions.
A critical HTTP request smuggling vulnerability exists in the Starlette framework due to improper validation of the Host header, allowing for security restriction bypasses.
The Divi Ajax Filter plugin for WordPress is susceptible to unauthenticated Local File Inclusion via the custom_loop_template parameter, enabling arbitrary code execution on the server.
Dianping CAT uses a weak, unkeyed Java hashCode for session cookie integrity, enabling offline forgery. Attackers can bypass IP validation via header manipulation to gain full administrative access.
A use after free vulnerability in Google Chrome DevTools allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
MISP contains an authentication bypass vulnerability in its LDAP and LinOTP components, allowing remote unauthenticated attackers to impersonate users via empty or invalid credential submissions.
MOOS core-moos versions up to 10.4.0 contain a pre-authentication heap overflow vulnerability in packet handling that allows remote attackers to write arbitrary data via a negative packet length.
Google Chrome on iOS contains an improper input validation vulnerability in the Transactions Platform, allowing remote attackers to execute arbitrary code outside the browser sandbox.
A remote attacker can execute arbitrary code outside the browser sandbox by tricking a user into visiting a crafted HTML page that triggers an out of bounds write in WebGL.
The MOOS core-moos HTTP server allows unauthenticated remote attackers to modify critical system variables by sending specially crafted HTTP requests to the MOOSDB service.
The MOOS core-moos wire protocol lacks authentication, allowing unauthenticated remote attackers to connect and execute privileged operations, including clearing the database.
A critical PHP object injection vulnerability in the Mail Mint plugin allows unauthenticated attackers to execute arbitrary code.
The JobSearch WordPress plugin contains an unauthenticated PHP object injection vulnerability in versions 3.2.0 and earlier.
The Canva Android application improperly validates the source of communication channels, allowing external origins to interact with the application via a privileged WebView.
The ACPT (Premium) WordPress plugin allows unauthenticated attackers to perform privilege escalation and account takeover by manipulating user IDs in form submissions.
A stack-based buffer overflow in the ipmi-oem utility of FreeIPMI allows for potential remote code execution via the idrac-info subcommand.
FreeIPMI is vulnerable to a stack-based buffer overflow in the ipmi-oem component, which may allow an unauthenticated attacker to achieve remote code execution or system crash.
FreeIPMI is vulnerable to a stack-based buffer overflow in the ipmi-oem component via the cmc-ipv6-info subcommand, potentially allowing remote code execution.
SciPhi-AI R2R contains a stacked SQL injection vulnerability in the vector index creation endpoint, allowing unauthenticated attackers to execute arbitrary SQL commands.
A critical flaw in ASUS Control Center Enterprise allows unauthenticated attackers to obtain encryption keys, enable SSH, and gain root access via hardcoded credentials.
A command injection vulnerability in the D-Link DNS-340L dropbox.cgi handler allows authenticated remote attackers to execute arbitrary OS commands via manipulated POST parameters.
Lightstar SmartIT Desktop Manager contains a hard-coded credentials vulnerability allowing unauthenticated remote attackers to retrieve SSH service account passwords from the application source code.
Eclipse Arrowhead versions 5.0.0 to 5.2.1 fail to validate X.509 certificate signatures and issuer chains in the MQTT API, allowing unauthenticated attackers to spoof system operator identities.
Peppermint versions 0.5.5 and earlier contain a hardcoded JWT signing secret in the docker-compose.yml file, allowing unauthenticated attackers to forge session tokens and impersonate any user.
A remote code execution vulnerability in the MOOS-IvP iSay component allows attackers to execute arbitrary system commands via unsanitized SAY_MOOS variable input.
MOOS-IvP contains multiple buffer overflow vulnerabilities in IvP function string decoders that fail to validate attacker-controlled length fields, potentially leading to remote code execution.
A buffer overflow in the Tenda HG10 Boa web server allows unauthenticated remote attackers to trigger a denial of service or potentially execute arbitrary code via the username parameter.
Lightstar SmartIT Desktop Manager contains a hard-coded credentials vulnerability allowing unauthenticated remote attackers to gain unauthorized access to user hosts.
FreeIPMI contains a stack-based buffer overflow in the _read_fru_data function within libfreeipmi/fru/ipmi-fru.c, triggered when a BMC returns an excessive number of bytes.
FreeIPMI is vulnerable to a stack-based buffer overflow in the Fujitsu SEL long-text response handling, potentially allowing unauthenticated remote code execution.
MOOS-IvP contains a buffer overflow in StringToIvPFunction() due to unvalidated payload counts, allowing attackers to trigger memory corruption via crafted BHV_IPF payloads.
The Bricksforge WordPress plugin contains a vulnerability that allows unauthenticated subscribers to escalate their privileges, potentially gaining administrative access to the site.
A logic error in the DOM.sanitize function of MapLibre GL JS allows for cross-site scripting (XSS) via improperly sanitized attributes, leading to potential unauthorized script execution.
The MOOS-IvP uMemWatch component fails to sanitize MOOS client names, allowing attackers to inject shell metacharacters and execute arbitrary system commands.
The pShare component in essential-moos fails to authorize PSHARE_CMD messages, allowing unauthenticated attackers to reconfigure network routes and listeners at runtime.
YITH Request a Quote for WooCommerce Premium versions prior to 4.46.0 contain an unauthenticated broken access control vulnerability, allowing unauthorized access to restricted plugin functions.
WWBN AVideo contains an authentication failure where the video_id_hash credential functions as a permanent, non-revocable bearer token, allowing unauthorized administrative account access.
A missing authorization flaw in the J2Store extension for Joomla allows unauthenticated attackers to execute arbitrary SQL files and perform unauthorized database operations via path traversal.
MetaGPT 0.8.1 contains an OS command injection vulnerability in the RepoParser.rebuild_class_views function, allowing unauthenticated attackers to execute arbitrary system commands.
An access control flaw in the TOTOLINK T6 router allows unauthenticated attackers to delete MAC filter rules by sending a malicious POST request to a specific CGI endpoint.
An improper access control flaw in the TOTOLINK T6 router allows unauthenticated remote attackers to modify WPS settings via a crafted POST request to the administrative CGI interface.
An incorrect access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to reconfigure Wi-Fi settings via a crafted POST request.
An access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to trigger forced reboots by sending a crafted POST request to the cgi-bin interface.
An access control flaw in the TOTOLINK T6 delDevice function allows unauthenticated attackers to delete managed slave devices via crafted POST requests.
An improper access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to modify mesh pairing configurations via a crafted POST request to the cstecgi.cgi endpoint.
An unauthenticated access control vulnerability in the TOTOLINK T6 router allows attackers to redirect device traffic to an upstream Wi-Fi network via a crafted POST request.
An access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to modify the device operating mode via a crafted POST request to the cgi-bin interface.
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to trigger a wireless pairing window via a crafted POST request.
An improper access control flaw in TOTOLINK T6 allows unauthenticated attackers to manipulate WAN dial settings via crafted POST requests to the device.
An unauthenticated server-side request forgery (SSRF) vulnerability in the /har/test endpoint allows attackers to force the server to send arbitrary HTTP requests to internal network resources.
TOTOLINK T6 routers contain an incorrect access control vulnerability in the setParentalRules function, allowing unauthenticated attackers to modify parental controls via crafted POST requests.
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to modify browsing policies via crafted POST requests to the cstecgi.cgi endpoint.
An access control flaw in the TOTOLINK T6 router allows unauthenticated attackers to modify wireless configuration settings via a crafted POST request.
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to modify access device policies via a crafted POST request to the cgi-bin interface.
A SQL injection vulnerability in Ocsreports allows authenticated operators to execute arbitrary database queries via the selected_grp_dupli parameter in the admin_double function.
The Federator component in Eclipse aeriOS fails to validate TLS certificates by default, allowing attackers to perform man-in-the-middle attacks and intercept sensitive credentials.
A vulnerability in the NGINX JavaScript (njs) engine allows unauthenticated attackers to bypass access controls via crafted HTTP requests that trigger error conditions during asynchronous processing.
Worklenz versions up to 3.0.0 contain a SQL injection vulnerability in pagination functions, allowing authenticated users to extract sensitive database content via malicious sort-field parameters.
Cisco IOS XR Software contains an insufficient control flow management vulnerability, identified as CWE-691, which may allow an unauthenticated attacker to cause a denial of service condition.
A TLS handshake failure in the HTTPX2 library allows for plaintext transmission of WebSocket traffic when utilizing a SOCKS5 proxy, potentially exposing sensitive authentication data.
Cisco IOS XR Software contains a protection mechanism failure (CWE-693) that could allow an unauthenticated attacker to cause a denial of service or impact system integrity.
A heap-based out-of-bounds write vulnerability in the NGINX JavaScript (njs) XML module allows unauthenticated remote attackers to cause service disruption or potential code execution.
A use after free vulnerability in the Skia graphics library within Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Hermes Agent is vulnerable to remote code execution via a malicious git repository that triggers arbitrary OS commands during git status index refreshes.
A use-after-free vulnerability in the Google Chrome Compositing component allows a remote attacker to achieve arbitrary code execution outside the sandbox via a crafted HTML page.
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A type confusion vulnerability in the Google Chrome Compositing component allows a remote attacker to execute arbitrary code via a crafted HTML page.
A vulnerability in Google Chrome CacheStorage allows a remote attacker to execute arbitrary code within the sandbox by enticing a user to visit a crafted HTML page.
An unauthenticated file upload vulnerability in GeoNetwork allows remote attackers to write arbitrary files to the server directory, potentially leading to unauthorized system access.
A SQL injection vulnerability in the Ocsreports save_query_list endpoint allows authenticated operators to manipulate database queries via the del_check parameter.
CRMEB contains an authentication bypass vulnerability in the verifyAuth method of SystemRoleServices.php that allows unauthorized access to restricted admin endpoints due to a flawed role check.
A buffer over-read vulnerability in the MOOS core-moos library allows unauthenticated attackers to access out-of-bounds memory via a crafted four-byte TCP packet.
The Canva Android App fails to restrict headers returned to external origins in privileged WebViews, allowing a threat actor to access a user's session.
RTMKit versions 2.1.5 and earlier contain a PHP object injection vulnerability that allows authenticated contributors to execute arbitrary code.
A CSRF vulnerability in the MISP cullEmptyEvents action allows remote attackers to trigger the unauthorized, irreversible deletion of published empty event records via a crafted HTTP GET request.
DbGate versions through 7.2.6 contain a path traversal vulnerability in the jsldata controller, allowing authenticated attackers to perform arbitrary file reads and writes via the file:// scheme.
A flaw in the Linux kernel Btrfs file system fails to initialize inode mapping flags for cached inodes, leading to kernel assertions and system crashes under specific memory conditions.
The J2Store extension for Joomla is vulnerable to unauthenticated PayPal callback forgery, allowing attackers to manipulate order statuses and commit payment confirmation fraud.
An authorization bypass vulnerability in Microsoft Azure Cosmos DB allows an authenticated attacker with low privileges to perform network spoofing via a user-controlled key.
A privilege escalation vulnerability in the MicroSCADA SYS600 RBAC mechanism allows local authenticated users to gain administrator-level access to the underlying Windows host.
A path traversal vulnerability in the Eclipse aeriOS Self-orchestrator REST API allows unauthenticated remote attackers to write or delete files outside of intended directories.
MOOS core-moos fails to validate client identity in MOOSDB, allowing authenticated attackers to spoof message origins and disrupt third-party subscriptions.
WWBN AVideo contains a CSRF and path traversal vulnerability in stopLive.php, allowing unauthorized deletion of directories when an administrator interacts with a malicious page.
The Customer Reviews for WooCommerce plugin fails to sanitize user-submitted review content, enabling unauthenticated attackers to execute Stored Cross-Site Scripting (XSS) attacks.
An injection vulnerability in the NGINX Ingress Controller configuration generator allows authenticated users to inject arbitrary configuration directives via unsanitized Ingress annotations.
An injection vulnerability in the NGINX Gateway Fabric configuration generator allows authenticated attackers to inject arbitrary NGINX configuration directives via unsanitized resource fields.
A privilege escalation vulnerability in Kibana allows authenticated users with Fleet management rights to elevate Elastic Agent credentials to full cluster administration privileges.
A path normalization flaw in Eclipse Arrowhead allows authenticated users to bypass management authorization gates via percent-encoded URL paths, potentially resulting in full administrative takeover.
SiYuan versions 3.8.1 and earlier contain an incomplete blocklist in the IsForbiddenAbsPath function, allowing authenticated users to retrieve sensitive TLS and CA private keys.
The Auto x LINE WordPress plugin lacks authorization checks on REST endpoints, allowing unauthenticated users to modify plugin settings and clear logs.
Kibana contains an incorrect authorization vulnerability that allows authenticated users with low privileges to perform unauthorized configuration modifications.
The Ultimate Member WordPress plugin fails to validate role assignments during registration, allowing unauthenticated users to escalate privileges to administrator-equivalent access.
The shared-files-pro WordPress plugin fails to validate file paths during featured image creation, enabling unauthenticated arbitrary file read.
A buffer overflow in the Tenda HG10 web server allows authenticated attackers to cause a denial of service or potentially execute arbitrary code via the ssid parameter.
n8n contains an expression sandbox escape in the $fromAI handler that allows authenticated users with workflow-build privileges to achieve remote code execution via prototype chain manipulation.
The toon-format toon library is vulnerable to prototype pollution via specifically crafted TOON data, which can lead to denial of service or remote code execution when downstream gadgets are present.
pAntler essential-moos contains a remote code execution vulnerability in the MOOSDB communication handler that allows unauthenticated attackers to execute arbitrary system commands via crafted messages.
Progress Telerik UI for ASP.NET AJAX contains an integrity protection flaw in the RadEditor file browser that could allow an attacker with encryption keys to achieve remote code execution.
SiYuan versions prior to 3.8.2 insecurely log API tokens in plaintext, allowing authenticated attackers to gain administrative access via the getFile endpoint.
A signature validation flaw in the Siemens Mendix SAML module allows unauthenticated remote attackers to perform account hijacking in specific SSO configurations.
Administrative operations within the WSO2 Carbon Console fail to properly validate input, allowing an attacker with administrative privileges to execute arbitrary OS commands remotely.
A use-after-free vulnerability exists in the Linux kernel ovpn driver due to improper management of deferred work items during module exit, potentially allowing code execution.
A missing authorization vulnerability in the 2Checkout payment gateway for WHMCS allows unauthenticated attackers to retrieve sensitive customer data via a specific API endpoint.
MOOS ui-moos contains a buffer overflow in ScopeTabPane.cpp and ScopeGrid.cpp due to improper length validation when formatting client and variable names, which can lead to remote code execution.
The J2Store extension for Joomla is vulnerable to unauthenticated cart record tampering due to improperly restricted access controls in the FOF framework, allowing attackers to modify cart data.
XING CPTrans-ME-X is vulnerable to an exposure of sensitive system information due to improper input processing on the administrative port, allowing unauthenticated remote access to internal data.
A logic error in the Gardens v2 governance framework allows unauthorized transfer of escrowed tokens via the syncOutflow function during a disputed proposal.
A logic error in the StreamingEscrow dispute resolution path of the 1Hive gardens-v2 governance framework allows for the unauthorized drainage of escrow balances to proposal beneficiaries.
A flaw in the Rancher Manager GlobalRole controller allows authenticated users with specific permissions to overwrite and revoke the rules of critical ClusterRoles, including cluster-admin.
A use of weak credentials vulnerability in B&R Industrial Automation GmbH mapp Audit within mapp Services allows potential system compromise.
A lack of brute-force protection in MISP's email-based OTP authentication flow allows authenticated users to bypass multi-factor authentication via excessive verification attempts.
A path traversal vulnerability in Plesk allows local users with low privileges to escalate their access and execute arbitrary code with root permissions.
Label Studio versions 1.23.0 and earlier fail to validate webhook URLs, allowing authenticated users to perform Server-Side Request Forgery (SSRF) against internal network services.
A local privilege escalation flaw in MicroSCADA SYS600 allows OS-authenticated users to read and modify application objects without proper application-level authentication.
A buffer overflow vulnerability exists in the Linux kernel fp9931 regulator driver due to an incorrect voltage selector table mapping, potentially leading to out of bounds memory access.
A use-after-free vulnerability in the Linux kernel MediaTek power domain driver allows for potential memory corruption due to improper device node reference management.
A NULL pointer dereference vulnerability in the Linux kernel psxpad-spi driver allows for system instability or crashes due to missing driver data initialization during the probe process.
A prototype pollution vulnerability in the toml-node TOML parser allows unauthenticated attackers to inject properties into Object.prototype, potentially leading to code execution or denial of service.
The Medplum OAuth2 registration endpoint improperly discloses client secrets for preconfigured clients, potentially allowing unauthorized access to sensitive healthcare application data.
A missing authorization vulnerability in the WP Compress plugin allows unauthenticated attackers to modify plugin settings.
InsydeH2O UEFI firmware stores hard drive passwords in plaintext within a UEFI variable, potentially allowing unauthorized access to sensitive data.
A broken access control vulnerability in the Agentimus plugin allows authenticated subscribers to perform unauthorized actions, potentially leading to unauthorized data modification or access.
The vhr application fails to perform authorization checks on the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by providing a target profile ID.
A bounds checking vulnerability exists in the Linux kernel amdkfd driver, allowing out-of-bounds reads due to improper validation of CRAT table subtype lengths.
A missing authorization vulnerability in the Nuclio Dashboard allows authenticated users to bypass OPA checks and modify or delete projects and associated serverless resources.
A command injection vulnerability in the Amazon CodeCatalyst blueprint resynthesis framework allows authenticated users to execute arbitrary commands via crafted .ownership-file entries.
An out-of-bounds access vulnerability exists in the Linux kernel batman-adv component due to improper validation of ethernet header data accessibility.
The XueZhiSi Open Source Exam System allows authenticated teachers to delete administrator accounts due to a lack of authorization checks in the user deletion API.
WWBN AVideo contains an SSRF filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 hex-encoded addresses, allowing access to internal services.
An incorrect access control vulnerability in the TOTOLINK T6 getRemoteCfg function allows unauthenticated attackers to retrieve remote management and port information via a crafted POST request.
A path traversal vulnerability in the MetaGPT SPO extension allows unauthenticated attackers to read arbitrary files by supplying malicious input to the set_file_name function.
An access control flaw in the TOTOLINK T6 router allows unauthenticated remote attackers to delete URL filtering rules by sending a malicious POST request to the cgi-bin interface.