CVE-2026-49869
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
Critical vulnerabilities, curated daily for security professionals
Yesterday's disclosures centered on Google Chrome, Mikrotik RouterOS, and a cluster of WordPress plugins, alongside continued exploitation of SonicWall SMA1000 and PaperCut MF/NG. Critical CVEs rose to 33, a 14% increase from the prior day, while high-priority CVEs fell 19% to 54. Notable critical entries include CVE-2026-84352 and CVE-2026-84325 in Google Chrome, CVE-2026-86060 and CVE-2026-67276 in Mikrotik RouterOS, and CVE-2026-10196 in the Mail Mint WordPress plugin. Attack patterns skew toward remote code execution and authentication weaknesses in edge appliances, print management servers, and AI tooling such as HKUDS AutoAgent and BerriAI LiteLLM, with 10 vulnerabilities carrying confirmed active exploitation. Defenders should prioritize internet-facing SonicWall, Mikrotik, and PaperCut systems, restrict management interfaces to trusted networks, and confirm fix status against each vendor's advisory before assuming coverage.
Immediate action: Prioritize SonicWall SMA1000, PaperCut MF/NG, Mikrotik RouterOS, and Google Chrome, where active exploitation or critical scores affect widely deployed, internet-facing systems, and update JFrog Artifactory, Kestra, LiteLLM, and Starlette instances where exposed. Confirm fix status and affected versions in each vendor's advisory, and restrict management access to trusted networks until patches are applied.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
JFrog Artifactory contains an authentication weakness that may allow an unauthenticated attacker to obtain administrative privileges via remote network access.
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition that allows remote attackers to execute arbitrary database commands via the /pa endpoint.
A pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the SonicWall SMA1000 Work Place interface allows remote unauthenticated attackers to perform unauthorized operations.
A post-authentication OS command injection vulnerability exists in the SonicWall SMA1000 Appliance Management Console, allowing an authenticated administrator to execute arbitrary OS commands.
PaperCut MF and NG are vulnerable to unsafe dynamic class loading in database utilities, allowing attackers to execute arbitrary Java bytecode via manipulated system configuration parameters.
An improper access control flaw in PaperCut MF/NG allows unauthenticated remote attackers to modify system configurations by bypassing validation checks for administrative functions.
LiteLLM proxy server contains a critical authentication vulnerability that allows unauthenticated access to sensitive functions.
A critical HTTP request smuggling vulnerability exists in the Starlette framework due to improper validation of the Host header, allowing for security restriction bypasses.
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
The Mail Mint WordPress plugin is vulnerable to PHP Object Injection via deserialization of untrusted input, allowing unauthenticated remote code execution.
AutoAgent is vulnerable to unauthenticated remote code execution via a TCP command server that accepts and executes arbitrary bash commands as root.
A use after free vulnerability in the WebGL component of Google Chrome on Android allows remote attackers to execute arbitrary code via a crafted HTML page.
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to hijack any user account.
Google Chrome contains an improper input validation flaw in the DataTransfer component that allows remote attackers to bypass system access restrictions via social engineering.
WWBN AVideo contains an unauthenticated path traversal vulnerability in notify.ffmpeg.json.php, allowing attackers to write arbitrary files to the system via the avideoRelativePath parameter.
The Frontend Admin by DynamiApps plugin for WordPress allows unauthenticated attackers to perform account takeover by overwriting user email addresses via improper authorization checks.
A flaw in the RouterOS SSH login path allows attackers to bypass privilege restrictions by using a specially crafted username, leading to full administrative access.
The MemberDash WordPress plugin is vulnerable to authorization bypass via an Insecure Direct Object Reference, allowing unauthenticated attackers to hijack any user account, including administrators.
MikroTik RouterOS improperly validates RSA public keys during SSH authentication, allowing attackers to forge signatures and gain unauthorized access to an SSH command channel.
N-able N-central is vulnerable to a pre-authentication remote code execution flaw via static code injection, allowing unauthenticated attackers to execute arbitrary code on the target system.
A buffer overflow vulnerability in the Tenda HG10 router allows remote unauthenticated attackers to trigger a denial of service via a crafted HTTP POST request to the /boaform/admin/formURL endpoint.
The cua-computer-server incorrectly skips authentication when the CONTAINER_NAME environment variable is unset, allowing unauthenticated remote attackers to execute arbitrary system commands.
A remote OS command injection vulnerability exists in the Tenda CP3 camera within the CAutoAddWifi::ThreadProc function of the Kylin component.
The Tenda HG10 router contains an OS command injection vulnerability in the Boa web server interface, allowing remote attackers to execute arbitrary system commands via the fmgpon_loid parameter.
A privilege management vulnerability in the CRedirServer::SetRedirectEnable function of Tenda CP3 version 27.5.57.101 allows remote attackers to manipulate system privileges.
A remote OS command injection vulnerability exists in Tenda CP3 version 27.5.57.101, specifically within the Network Configuration Management component.
Tenda CP3 version 27.5.57.101 is vulnerable to remote OS command injection via the interface_name or host arguments in Net/NetCheckPing.cpp.
A remote OS command injection vulnerability exists in Tenda CP3 version 27.5.57.101 within the SystemAsh function, allowing attackers to execute arbitrary commands via the AlarmVoiceURL argument.
WWBN AVideo contains a broken access control vulnerability in the videoViewsInfo endpoint, allowing unauthenticated attackers to retrieve sensitive user data and hijack administrative sessions.
A use-after-free vulnerability in the Linux kernel KVM subsystem allows for potential system compromise due to improper handling of child shadow page roles.
The TOTOLINK T6 router contains an access control flaw in the delSmartQosCfg function, allowing unauthenticated attackers to remove Smart QoS rules via a crafted POST request.
The TOTOLINK T6 router has an access control vulnerability in the delStaticDhcpRules function, allowing unauthenticated attackers to delete static DHCP reservations via a crafted POST request.
An incorrect access control vulnerability in the TOTOLINK T6 killProcess function allows unauthenticated attackers to terminate critical services via a crafted POST request.
An access control vulnerability in the TOTOLINK T6 FirmwareUpgrade function allows unauthenticated attackers to delete Wi-Fi schedule entries using crafted POST requests.
An incorrect access control flaw in the TOTOLINK T6 router allows unauthenticated attackers to trigger mesh slave update processes via a crafted POST request to the cstecgi.cgi endpoint.
An incorrect access control vulnerability in the UploadFirmwareFile function of the TOTOLINK T6 router allows unauthenticated remote attackers to upload arbitrary firmware images.
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to expose internal hosts via crafted POST requests.
An access control flaw in the TOTOLINK T6 firmware allows unauthenticated attackers to trigger mass firmware updates on mesh slave devices via crafted MQTT messages.
An access control flaw in the TOTOLINK T6 router allows unauthenticated attackers to delete VLAN configurations via a crafted POST request to the web management interface.
An incorrect access control vulnerability in the TOTOLINK T6 delParentalRules function allows unauthenticated attackers to remove parental control rules via a crafted POST request.
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to modify MAC filter rules by sending a crafted POST request to the cgi-bin endpoint.
An unauthenticated access control vulnerability in the TOTOLINK T6 router allows attackers to modify WAN configuration settings via crafted POST requests to the cgi-bin interface.
YesWiki is vulnerable to an unauthenticated SQL injection in its Bazar entry-listing APIs, allowing attackers to infer sensitive database contents through boolean SQL expressions.
Bilibili Desktop disables process-wide TLS certificate validation and executes unsigned remote JavaScript, allowing an on-path attacker to achieve remote code execution and credential theft.
The HivePress Authentication plugin for WordPress is vulnerable to an authentication bypass due to improper Facebook token validation, allowing unauthenticated account takeover.
Acunetix for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine that allows low-privileged users to execute arbitrary code with SYSTEM privileges.
The DirectIo64.sys kernel driver in multiple PassMark products contains an improper access control vulnerability that allows unprivileged local users to perform privileged hardware operations.
A use after free vulnerability in the Google Chrome browser allows a remote attacker to achieve arbitrary code execution outside the sandbox via a crafted HTML page.
A buffer overflow vulnerability in the GPU component of Google Chrome on Windows allows remote attackers to achieve arbitrary code execution outside the browser sandbox.
SQL Chat contains four unauthenticated API endpoints that allow attackers to execute arbitrary SQL queries against attacker-specified hosts, facilitating internal network pivoting.
An incorrect authorization vulnerability in the TabStrip component of Google Chrome allows remote attackers to potentially escape the sandbox and execute arbitrary code via a crafted HTML page.
A local OS command injection vulnerability exists in the Amazon Linux log4j-cve-2021-44228-hotpatch package, potentially allowing local users to gain root privileges.
IBM Langflow OSS allows authenticated attackers to perform arbitrary file reads and exfiltrate sensitive server credentials via path traversal in the files parameter.
SolidInvoice before 3.0.1 allows authenticated attackers to perform PHP object injection via a writable LiveComponent context prop, leading to potential remote code execution.
AppFlowy-Cloud 0.9.64 fails to verify workspace ownership of collaboration objects, allowing authenticated attackers to access or modify data across unauthorized workspaces.
A vulnerability in Amazon ion-java allows unauthenticated remote attackers to trigger a denial of service via a crafted compressed document that causes excessive memory consumption.
Axolotl versions through 0.18.0 contain a remote code execution vulnerability in the multipack patch path due to an insecure default configuration of the trust_remote_code parameter.
The Nokri WordPress theme is vulnerable to unauthorized privilege escalation due to a missing capability check in the nokri_account_member_permissions function.
A crafted backup archive can trigger OS command injection in laravel-backup-restore versions prior to 1.9.4 during the database restore process.
IBM ContextForge MCP Gateway is vulnerable to a DNS rebinding attack, which could allow a remote authenticated attacker to obtain sensitive information during tool invocation.
An authentication-based authorization flaw in IBM Observability with Instana allows an attacker to misappropriate etcd mTLS credentials by bypassing namespace validation.
Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname that allows memory corruption via crafted HDF5 files with oversized attribute names.
Coolify through 4.3.17 contains an authentication bypass in the OAuth callback handler that allows attackers to hijack accounts via email matching without verifying provider assertions.
PassMark software products contain a privilege escalation vulnerability in the DirectIo64.sys kernel driver, allowing local users to bypass security controls and modify hardware configuration.
The JetBackup WordPress plugin fails to validate user capabilities during site restores, allowing a subscriber to escalate privileges to administrator.
A buffer overflow vulnerability in the Tenda HG10 router's Boa web server allows remote attackers to trigger memory corruption via the if parameter in the formWanRedirect function.
A privilege escalation flaw in the grav-plugin-api InvitationsController allows authenticated users to create super-admin accounts via malformed dot-keyed access flags.
An authentication bypass vulnerability in N-able N-central versions prior to 2026.3 HF 3 allows authenticated users to bypass security controls on internal-only APIs.
MikroTik RouterOS contains a memory disclosure and remote denial of service vulnerability in the bandwidth-test service that allows unauthenticated attackers to trigger a kernel restart.
Mikrotik RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path due to the use of a stale uninitialized principal pointer, allowing unauthorized root file access.
The grav-plugin-api fails to validate group-inherited permissions, allowing authenticated users with specific API access to modify super-admin accounts and achieve full administrative control.
The Grav API plugin is vulnerable to an authentication bypass via Host header injection, allowing unauthenticated attackers to hijack password reset tokens and perform full account takeover.
Webstudio versions through 0.296.0 contain an unauthenticated server-side request forgery (SSRF) vulnerability in proxy routes when the RESIZE_ORIGIN environment variable is improperly configured.
Aider-AI aider automatically executes arbitrary commands from a local .aider.conf.yml file found in the repository root without user confirmation, enabling remote code execution for attackers.
A URL parser discrepancy in IBM Langflow OSS allows authenticated attackers to perform Server-Side Request Forgery (SSRF) and access sensitive information from internal services.
The undici WebSocket client is vulnerable to an uncaught TypeError during the handshake process, allowing unauthenticated remote attackers to crash the entire Node.js process.
IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a vulnerability that allows remote attackers to access sensitive information due to improper credential scrubbing.
The Douyin_TikTok_Download_API contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated request of arbitrary URLs.
A stack-based buffer overflow exists in the xmlSnprintfElements function within libxml2, potentially allowing for memory corruption and unauthorized system impact.
Pterodactyl Panel before 1.14.1 fails to validate permissions when creating scheduled tasks, allowing authenticated subusers to execute unauthorized console commands, power actions, or backups.
The libpcap BPF interpreter fails to validate scratch memory register indices, allowing crafted filter programs to read or write to arbitrary process memory.
A kernel driver vulnerability in DirectIo64.sys allows local unauthenticated attackers to dump physical memory by exploiting an exposed IOCTL.
A hard-coded credential flaw in the PassMark DirectIo64.sys kernel driver allows local attackers to perform arbitrary physical memory writes and bypass security validation gates.
A template engine vulnerability in the Amazon awslabs.dynamodb-mcp-server CDK generator allows context-dependent attackers to achieve arbitrary code execution via crafted data model files.
Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows an attacker to write files to arbitrary locations on the host system, leading to code execution.
IBM App Connect Enterprise and Integration Bus for z/OS are vulnerable to an XML external entity (XXE) attack via the SAP Adapter, potentially allowing unauthorized information disclosure.
MindsDB through 26.1.0 contains an unauthenticated server-side request forgery (SSRF) vulnerability in the web crawler handler that allows attackers to fetch arbitrary internal or external URLs.
The firecrawl-mcp-server contains an arbitrary local file read vulnerability in the firecrawl_parse tool due to a lack of directory containment validation on the filePath argument.
The Linux kernel contains an out of bounds write vulnerability in the network subsystem due to improper handling of link layer header padding when device configurations change.
A use-after-free vulnerability in the Linux kernel pata_sl82c105 driver allows local attackers to potentially achieve arbitrary code execution or cause system instability.
A buffer overflow vulnerability exists in the Linux kernel Thunderbolt subsystem due to improper array indexing when calculating bandwidth group reservations.
A race condition in the Linux kernel amba-pl011 serial driver allows a local attacker to trigger use-after-free conditions by improperly synchronizing DMA teardown and RX polling timers.
A missing authorization flaw in nebula-mesh allows authenticated users to bypass SSRF protection, enabling unauthorized access to internal network resources.
A denial of service vulnerability in llama.cpp allows unauthenticated remote attackers to trigger memory exhaustion via a negative top_n value in POST requests to the /rerank endpoint.
Chew Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation flaw in its installation script that may result in passwordless root and alpha account access.
An incorrect access control vulnerability in the TOTOLINK T6 delPortForwardRules function allows unauthenticated attackers to delete port-forwarding rules via a crafted POST request.