CVE-2026-49869
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
Critical vulnerabilities, curated daily for security professionals
Browser and mail client vulnerabilities in Google Chrome, Mozilla Firefox, and Thunderbird lead yesterday's disclosures, alongside a cluster of critical WordPress plugin flaws and two IBM enterprise products. The day produced 29 critical CVEs (down 44% from 52) and 67 high-priority CVEs (down 14% from 78), a marked drop in volume from the prior day. Notable critical issues include CVE-2026-84129 affecting Mozilla Firefox and Thunderbird (CVSS 9.8), CVE-2026-18658 in IBM Operational Decision Manager (CVSS 9.8), and CVE-2026-83627 in the wpmudev Hummingbird Performance WordPress plugin (CVSS 9.8). Confirmed active exploitation spans 10 CVEs, including SonicWall SMA1000 appliances, PaperCut MF/NG print management, JFrog Artifactory, and a Chrome flaw, indicating attacker focus on edge devices and developer infrastructure. No patches were confirmed at disclosure time, so defenders should verify vendor advisories directly and apply compensating controls where fixes are not yet available.
Immediate action: Prioritize updating Google Chrome, Mozilla Firefox, and Thunderbird across endpoints, and audit WordPress installations for Hummingbird Performance, ComboBlocks, MStore API, and AI Website Builder plugins. Internet-facing SonicWall SMA1000, PaperCut MF/NG, JFrog Artifactory, and Kestra deployments are under active exploitation and should be isolated or patched first. No patches were confirmed at disclosure, so check vendor advisories directly and apply vendor mitigations or network restrictions until fixes are available.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
JFrog Artifactory contains an authentication weakness that may allow an unauthenticated attacker to obtain administrative privileges via remote network access.
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition that allows remote attackers to execute arbitrary database commands via the /pa endpoint.
A pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the SonicWall SMA1000 Work Place interface allows remote unauthenticated attackers to perform unauthorized operations.
A post-authentication OS command injection vulnerability exists in the SonicWall SMA1000 Appliance Management Console, allowing an authenticated administrator to execute arbitrary OS commands.
PaperCut MF and NG are vulnerable to unsafe dynamic class loading in database utilities, allowing attackers to execute arbitrary Java bytecode via manipulated system configuration parameters.
An improper access control flaw in PaperCut MF/NG allows unauthenticated remote attackers to modify system configurations by bypassing validation checks for administrative functions.
LiteLLM proxy server contains a critical authentication vulnerability that allows unauthenticated access to sensitive functions.
A critical HTTP request smuggling vulnerability exists in the Starlette framework due to improper validation of the Host header, allowing for security restriction bypasses.
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
The Hummingbird WordPress plugin is vulnerable to unauthenticated remote code execution due to improper sanitization of cookie data written to a web-accessible log file.
The AI Website Builder WordPress plugin lacks authorization checks on REST API routes, enabling unauthenticated attackers to execute arbitrary code, modify site content, and install malicious plugins.
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to unauthenticated hook injection, allowing remote attackers to execute arbitrary actions via specific functions in the plugin code.
The MStore API WordPress plugin is vulnerable to authentication bypass via JWT forgery due to missing cryptographic signature verification in the FirebasePhoneAuthHelper component.
IBM Operational Decision Manager is vulnerable to unauthenticated SQL injection, allowing attackers to execute arbitrary commands and potentially achieve remote code execution.
A use after free vulnerability in the Proxy component of Google Chrome allows a remote attacker to execute arbitrary code via crafted network traffic.
An incorrect authorization vulnerability in the Google Chrome FileSystem allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page and social engineering.
An improper access control flaw in the IBM Instana Agent Operator allows authenticated tenants to hijack or destroy cluster-level RBAC permissions of other tenants.
A vulnerability in Mozilla Thunderbird allows unauthenticated attackers to execute local or network-hosted files via malicious calendar invitations, bypassing attachment security protections on Windows.
A site isolation vulnerability exists in the DOM Navigation component of Mozilla Firefox and Thunderbird, potentially allowing unauthenticated remote code execution.
A vulnerability in Mozilla Thunderbird allows unauthenticated attackers to trigger uninitialized memory usage via specially crafted MIME bodies, leading to potential information disclosure or crashes.
Voltronic Power SNMP Web Pro 1.1 is vulnerable to unauthenticated remote code execution via the upload.cgi endpoint, allowing attackers to execute arbitrary commands with root privileges.
The Aim remote tracking server contains a critical authentication bypass vulnerability that allows unauthenticated attackers to execute arbitrary methods and manipulate experiment data.
The TEN Framework TMAN Designer API contains unauthenticated file read and write vulnerabilities, allowing attackers to perform arbitrary file operations and achieve remote code execution.
SadTalker is vulnerable to OS command injection in the video muxing process, allowing unauthenticated attackers to execute arbitrary system commands via malicious audio filenames.
DocsGPT 0.15.0 and earlier contains a server-side template injection vulnerability in the custom prompt feature, allowing unauthenticated attackers to achieve remote code execution.
The excel-mcp-server fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing unauthenticated attackers to perform arbitrary file read and write operations.
Zerox 1.1.20 contains an OS command injection vulnerability in its file download mechanism that allows unauthenticated attackers to execute arbitrary commands via crafted document URLs.
PowerJob Worker 5.1.2 and earlier exposes the /worker/deployContainer endpoint without authentication, allowing remote attackers to execute arbitrary code.
An improper neutralization of CRLF sequences in the IXON VPN Client allows an unauthenticated attacker to execute arbitrary commands with root or SYSTEM privileges.
An incorrect access control vulnerability in the LoadDefSettings function of TOTOLINK T6 allows unauthenticated attackers to reset device configurations and trigger reboots via crafted POST requests.
TOTOLINK T6 routers contain an incorrect access control vulnerability in the setWiFiMeshName function, allowing unauthenticated attackers to rename mesh entries via a crafted POST request.
An access control vulnerability in TOTOLINK T6 allows unauthenticated remote attackers to disconnect wireless clients by sending a crafted MQTT message to the cs_broker component.
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to overwrite cloud-result tracking files via crafted MQTT messages.
An unauthenticated access control vulnerability in the TOTOLINK T6 mesh management component allows remote attackers to delete slave devices and reboot the system via crafted MQTT messages.
An incorrect access control vulnerability in the TOTOLINK T6 updatePriChannel function allows unauthenticated attackers to manipulate mesh channel settings via crafted MQTT messages.
An incorrect access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to force unauthorized mesh configuration synchronization via crafted MQTT messages.
An improper access control flaw in the TOTOLINK T6 clearSyslog function allows unauthenticated attackers to delete system logs by sending a malicious POST request to the cgi-bin interface.
An access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to retrieve sensitive mesh configuration data via a crafted POST request.
A server-side request forgery (SSRF) vulnerability in YesWiki allows unauthenticated attackers to perform arbitrary outbound HTTP requests, enabling internal network scanning and metadata extraction.
YesWiki is vulnerable to SQL injection via the ApiController::deletePage function, allowing authenticated users to execute arbitrary SQL queries and exfiltrate data from the underlying database.
The Welcart e-Commerce plugin for WordPress allows unauthenticated attackers to perform PHP Object Injection, potentially leading to arbitrary file deletion and remote code execution.
A path traversal vulnerability in the Google Cloud ADK builder endpoint allows unauthenticated remote attackers to read arbitrary files via a crafted file_path parameter.
A privilege escalation vulnerability in the Abandoned Cart Pro for WooCommerce plugin allows authenticated subscribers to manipulate SMTP settings and intercept administrative access tokens.
A stack-based buffer overflow in the PJSIP GnuTLS backend allows unauthenticated attackers to trigger memory corruption or control flow hijacking via a crafted peer certificate during the TLS handshake.
YesWiki versions prior to 4.6.6 contain a SQL injection vulnerability in the ReactionManager::deleteUserReaction function, allowing authenticated users to execute arbitrary SQL commands.
Grav CMS before 2.0.19 is vulnerable to remote code execution via the Twig sort filter due to an improper sandbox configuration that allows unauthorized access to the spl_autoload function.
Interinfo DreamMaker contains a SQL injection vulnerability allowing authenticated remote attackers to execute arbitrary database commands.
Nango before 0.71.6 suffers from a missing authentication vulnerability in the runner tRPC server, allowing unauthenticated attackers to achieve remote code execution.
Blinko versions up to 1.8.8 contain an authorization bypass (IDOR) vulnerability in multiple tRPC procedures, allowing authenticated users to access or modify data belonging to other users.
OpenPanel before 2.3.0 contains a code injection vulnerability in chart formula expressions, allowing authenticated users to execute arbitrary operating system commands.
PCRE2 before 10.48 contains an out-of-bounds write vulnerability in pcre2_dfa_match due to a missing size check when reusing cached workspace blocks during recursive matching.
IBM i versions 7.3 through 7.6 contain an improper authorization vulnerability in the DDM target dispatcher that allows remote attackers to manipulate database transactions.
A SQL injection vulnerability in the ILIAS repository trash table allows authenticated users to execute arbitrary database queries, potentially leading to full system compromise.
Traefik versions 3.7.0 through 3.7.12 contain an authentication bypass in the Kubernetes Ingress provider that allows unauthorized access to routes requiring client certificate authentication.
A failure to escape regular expressions in the Thunderbird mail.allowed_attachment_hostnames setting allows unintended hosts to bypass security filters and serve remote attachments.
A missing authorization vulnerability in the Google Cloud Integration Connectors HTTP Connector allows authenticated users to escalate privileges and compromise Google Cloud Projects.
A cryptographic signature verification bypass in YesWiki allows unauthenticated attackers to process unauthorized payloads by triggering an error in PHP's openssl_verify function.
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to missing authorization, potentially allowing an attacker to extract system credentials, configurations, or flash contents.
sift.js is vulnerable to remote code execution due to improper enumeration of query keys, which allows execution of arbitrary JavaScript via prototype pollution or malicious query objects.
An incorrect authorization flaw in the Chromoting component of Google Chrome on Windows allows a local attacker to execute arbitrary code outside the browser sandbox.
A buffer over-read vulnerability in Mozilla Thunderbird allows unauthenticated remote attackers to trigger a one byte memory read via a maliciously crafted mail header.
OpenAI Codex CLI and Desktop versions are vulnerable to arbitrary code execution when processing attacker-prepared Git repositories that contain malicious core.fsmonitor configurations.
LaVague 0.2.35 contains a remote code execution vulnerability in the PythonFromMarkdownExtractor class due to the unsafe evaluation of untrusted language model output.
A sandbox bypass vulnerability in the Twig template engine allows unauthenticated attackers to execute arbitrary methods on Markup-derived objects within sandboxed environments.
A vulnerability in the Amazon EFS CSI Driver allows authenticated users to trigger unauthorized recursive file deletion on EFS filesystems via a crafted PersistentVolume volumeHandle.
IBM ContextForge MCP Gateway is vulnerable to server-side request forgery via DNS rebinding, which may allow an authenticated attacker to access sensitive information.
Traefik contains a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication on multi-host routers.
The Advanced Custom Fields: Extended WordPress plugin fails to validate user roles during registration, allowing unauthenticated attackers to register with elevated privileges and escalate to administrator.
The OAuth Single Sign On WordPress plugin fails to verify Steam identity assertions, allowing unauthenticated attackers to impersonate users and create unauthorized accounts.
A path traversal vulnerability in Note Mark allows authenticated users to achieve arbitrary file writes outside the intended directory during data export operations.
llama.cpp versions b5693 and earlier are susceptible to a reachable assertion error within the gguf_reader::read function, potentially leading to instability or denial of service.
A stack-based buffer overflow in the PJSIP PJSUA library allows remote attackers to cause a denial of service by sending excessive Service-Route headers in a registration response.
A stack-based buffer overflow exists in PJSIP due to improper handling of a=crypto attributes in SRTP/SDES media transport, potentially allowing remote code execution or memory corruption.
OpenPanel before 2.3.0 contains an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the site-checker endpoint, allowing attackers to probe internal network resources.
A CRLF injection vulnerability exists in Laravel's email validation logic, potentially allowing unauthenticated attackers to interfere with outbound email processing.
A misconfigured default setting in Inductive Automation Ignition allows any authenticated user with gateway script execution capabilities to create projects, potentially leading to unauthorized system changes.
IBM ContextForge MCP Gateway versions 1.0.7 and earlier contain a vulnerability in jq filter validation that allows authenticated remote attackers to steal sensitive credentials and escalate privileges.
IBM Langflow OSS versions 1.0.0 through 1.11.2 contain an authorization bypass vulnerability in the flow build process that allows remote authenticated attackers to execute arbitrary code.
An eval() injection vulnerability in the get_list function of lllyasviel Fooocus allows remote authenticated attackers to execute arbitrary code via crafted EXIF metadata in uploaded images.
A server-side request forgery vulnerability in IBM Langflow OSS allows unauthenticated remote attackers to access sensitive information.
The Elixir Mint HTTP client library is vulnerable to resource exhaustion, allowing a malicious remote server to cause a denial of service via uncontrolled memory growth.
OpenPanel before 2.3.0 contains an unauthenticated cross-site scripting vulnerability in the favicon proxy endpoint that allows remote attackers to execute scripts via malicious SVG files.
IBM i versions 7.3 through 7.6 are vulnerable to unauthorized access due to improper validation of client-supplied authentication parameters by a remote attacker.
IBM Langflow OSS versions 1.0.0 through 1.11.2 are vulnerable to a path traversal flaw allowing remote authenticated attackers to delete arbitrary files or directories.
GOLDENHORN ONEIT is vulnerable to Blind SQL Injection due to improper neutralization of special elements in SQL commands, potentially allowing unauthorized data access.
A heap-based buffer overflow in the PJSIP PJLIB-UTIL HTTP client allows remote attackers to trigger memory corruption or application termination via a crafted HTTP response.
Frappe CRM contains an authentication bypass vulnerability in the crm/api endpoint due to improperly handled invitation keys, allowing unauthorized access.
A flaw in SmallRye GraphQL allows unauthenticated remote attackers to trigger a Denial of Service through CPU exhaustion or memory errors using specially crafted float literals.
A cross-site request forgery vulnerability in Tycon Systems TPDIN-Monitor-WEB3 allows unauthenticated attackers to perform state changing operations on the device.
The goose application incorrectly handles recipe extensions and retry configurations, allowing unauthenticated attackers to execute arbitrary shell commands on the host system.
Snipe-IT contains an authorization bypass in the bulk delete feature, allowing authenticated users to perform unauthorized soft-delete actions on user accounts outside their scope.
Emlog versions 2.6.29 and prior contain a stored Cross-site Scripting (XSS) vulnerability due to improper sanitization of Markdown content processed by the Parsedown library.
Postgres MCP Pro 0.3.0 contains a restricted mode bypass vulnerability where lack of function validation in FROM clauses allows attackers to execute unauthorized file reading functions.
MISP contains a cross-site request forgery vulnerability in the sharing group quick-edit functionality, allowing unauthorized modification of sharing group memberships via crafted GET requests.
Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments.
Snipe-IT contains an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled, allowing authenticated users to modify cross-company data.
PALLET CONTROL products contain an incorrect default permission vulnerability, allowing a local attacker to execute arbitrary code with SYSTEM privileges.
An incorrect authorization vulnerability in MISP allows authenticated users to delete event attributes without the required permissions by bypassing standard event modification checks.
A command allowlist bypass vulnerability in cli-mcp-server 0.2.5 allows attackers to execute arbitrary commands by leveraging shell substitution syntax when ALLOW_SHELL_OPERATORS is enabled.
Fastify versions before 5.12.2 contain an input validation flaw where a malicious request body can replace the validated object, leading to unauthorized state changes and data disclosure.
A memory safety vulnerability in the PJSIP SDP negotiator allows remote memory corruption or denial of service when a specific interoperability feature is enabled.
A failure in the nebula-mesh certificate revocation mechanism allows revoked or offboarded hosts to maintain unauthorized network access for extended periods despite being marked as blocked.
A denial of service vulnerability exists in smol-toml where a specially crafted TOML input triggers an infinite loop, consuming all available processing resources.
A flaw in the showSyslog function of TOTOLINK T6 allows unauthenticated attackers to retrieve sensitive system logs via a crafted POST request.
An improper access control flaw in TOTOLINK T6 allows unauthenticated attackers to modify privileged Quality of Service (QoS) policies via crafted MQTT messages.