CVE-2026-49869
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
Critical vulnerabilities, curated daily for security professionals
Browser engines and network edge devices dominate Sunday's disclosures, with Google Chrome carrying three critical CVEs (CVE-2026-84353, CVE-2026-84333, CVE-2026-85043) alongside a CVSS 9.8 flaw in Mozilla Firefox and Thunderbird (CVE-2026-84134). Critical CVEs fell 39% to 20 from 33 the prior day, while high-priority CVEs rose 4% to 56, for a total of 76 vulnerabilities. Other notable critical entries include CVE-2026-84147 (CVSS 10) in the Manacle Technologies Multi-tenant ERP System, CVE-2026-79697 and CVE-2026-79698 (CVSS 9.9) in Advantech WISE-6610 series industrial gateways, and CVE-2026-51693 (CVSS 9.8) in the TOTOLINK T6 router. The pattern favors internet-facing and remote-access infrastructure: 10 CVEs are confirmed actively exploited, including SonicWall SMA1000 appliances, PaperCut MF/NG, JFrog Artifactory, Kestra, Sangoma Switchvox, and the Python web stack (Starlette, LiteLLM). Prioritize updating browsers and restricting management interfaces on SonicWall, Advantech, and TOTOLINK devices to trusted networks, and confirm fix status for each product in the vendor advisory before assuming coverage.
Immediate action: Push updates to Google Chrome, Mozilla Firefox, and Thunderbird fleet-wide, and treat SonicWall SMA1000, PaperCut MF/NG, JFrog Artifactory, Kestra, and Sangoma Switchvox as the highest-priority patch targets given confirmed exploitation. Development teams should inventory services using Starlette and LiteLLM and update them promptly. Confirm fix status and affected version ranges for each product in the vendor's advisory, and restrict exposed management interfaces on Advantech, TOTOLINK, and NEC devices until updates are applied.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
JFrog Artifactory contains an authentication weakness that may allow an unauthenticated attacker to obtain administrative privileges via remote network access.
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition that allows remote attackers to execute arbitrary database commands via the /pa endpoint.
A pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the SonicWall SMA1000 Work Place interface allows remote unauthenticated attackers to perform unauthorized operations.
A post-authentication OS command injection vulnerability exists in the SonicWall SMA1000 Appliance Management Console, allowing an authenticated administrator to execute arbitrary OS commands.
PaperCut MF and NG are vulnerable to unsafe dynamic class loading in database utilities, allowing attackers to execute arbitrary Java bytecode via manipulated system configuration parameters.
An improper access control flaw in PaperCut MF/NG allows unauthenticated remote attackers to modify system configurations by bypassing validation checks for administrative functions.
LiteLLM proxy server contains a critical authentication vulnerability that allows unauthenticated access to sensitive functions.
A critical HTTP request smuggling vulnerability exists in the Starlette framework due to improper validation of the Host header, allowing for security restriction bypasses.
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A use after free vulnerability in the Shared Tab Groups component of Google Chrome on Android allows remote attackers to execute arbitrary code via a crafted HTML page.
A use after free vulnerability in the Dawn component of Google Chrome on Android allows remote attackers to execute arbitrary code via a crafted HTML page.
An incomplete cleanup vulnerability in the Google Chrome network stack allows a remote, unauthenticated attacker to bypass system access restrictions using crafted network traffic.
A critical flaw exists in the Profile Backup component of Mozilla Firefox and Thunderbird, potentially allowing unauthenticated remote code execution.
An unauthenticated remote code execution vulnerability in the Manacle Technologies Multi-tenant ERP System allows attackers to upload arbitrary files via a vulnerable API endpoint.
An authentication bypass in the NEC UNIVERGE IX-R/IX-V WebGUI allows unauthenticated remote attackers to execute arbitrary CLI commands via message tampering.
An authorization bypass in the Manacle Technologies Multi-tenant ERP System API allows unauthenticated attackers to access sensitive user data via parameter manipulation.
A command injection vulnerability in the basicstation_apply function of Advantech WISE-6610 series gateways allows remote attackers to execute arbitrary commands via the act argument.
A command injection vulnerability in the Node-RED Library function nodered_lib_apply allows remote authenticated attackers to execute arbitrary system commands via the act argument.
An incorrect access control vulnerability in the TOTOLINK T6 setVpnPassCfg function allows unauthenticated attackers to weaken edge filtering via a crafted POST request.
Exposure of the .git directory in the Manacle Technologies Multi-tenant ERP System allows unauthenticated attackers to download source code and metadata from the repository.
Incorrect access control in the TOTOLINK T6 firmware allows unauthenticated attackers to send crafted MQTT messages to modify QoS settings via the cs_broker component.
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to expose internal services via a crafted POST request.
An unauthenticated access control vulnerability in the TOTOLINK T6 router allows attackers to modify storage service configurations via crafted POST requests to the cgi-bin interface.
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to reconfigure or disable wireless networks via a crafted POST request.
TOTOLINK T6 routers contain an incorrect access control vulnerability in the recvClearPairCfg function, allowing unauthenticated attackers to trigger device reboots via crafted MQTT messages.
An unauthenticated access control vulnerability in the TOTOLINK T6 router allows attackers to modify guest wireless network configurations via a crafted POST request.
An incorrect access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to modify guest wireless settings via a crafted POST request to the cstecgi.cgi endpoint.
An incorrect access control vulnerability in the TOTOLINK T6 firmware allows unauthenticated attackers to modify firmware upgrade workflows via crafted POST requests.
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated remote attackers to extract sensitive configuration data via a crafted POST request.
A SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows unauthenticated remote attackers to execute arbitrary SQL commands via the room_name parameter.
SourceCodester Class and Exam Timetabling System 1.0 contains a SQL injection vulnerability in the /admin/modal_add_product.php file via the fname parameter, allowing remote unauthenticated exploitation.
A SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows unauthenticated attackers to execute arbitrary SQL commands via the course parameter in modal_add_coursea.php.
A SQL injection vulnerability in the Class and Exam Timetabling System 1.0 allows unauthenticated remote attackers to execute arbitrary SQL commands via the course parameter in modal_add_course2.php.
A SQL injection vulnerability exists in the SourceCodester Class and Exam Timetabling System 1.0 via the course parameter in /admin/modal_add_course1.php, allowing unauthenticated remote code execution.
SourceCodester Class and Exam Timetabling System 1.0 is vulnerable to unauthenticated SQL injection via the course parameter in /admin/modal_add_course.php, allowing remote database manipulation.
An unauthenticated SQL injection vulnerability in Mstfakts College-Management-System allows remote attackers to extract sensitive database information via the book search functionality.
An unauthenticated SQL injection vulnerability exists in the CommonController component of the jaychouchannel Tourism-Management-System, allowing remote attackers to manipulate database queries.
The School Management System 1.0 is vulnerable to SQL injection via the email parameter in User_Login.php, allowing unauthenticated remote attackers to execute arbitrary database queries.
A SQL injection vulnerability in the login function of rabindralamsal inventory-management-system version 1.0.0 allows unauthenticated remote attackers to bypass authentication.
SourceCodester Class and Exam Timetabling System 1.0 is vulnerable to unauthenticated SQL injection via the room_name parameter in the /admin/modal_add_room2.php file.
SourceCodester Class and Exam Timetabling System 1.0 contains a SQL injection vulnerability in the room_name parameter within modal_add_rooma.php, allowing unauthenticated remote code execution.
A SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows remote attackers to execute arbitrary database queries via the sy parameter in modal_add_schoolyr.php.
The Code-Projects Task Management System in PHP version 1.0 contains a SQL injection vulnerability in the login functionality via the email parameter in index.php.
Code-Projects Content Management System 1.0 is vulnerable to unauthenticated SQL injection via the user_name parameter in the login.php script, allowing potential unauthorized database access.
A SQL injection vulnerability exists in the SourceCodester Online Voting System version 1.0, specifically within the username parameter of the /ajax.php?action=login endpoint.
A SQL injection vulnerability in SourceCodester Online Voting System 1.0 allows unauthenticated remote attackers to manipulate the id parameter in /ajax.php?action=delete_category.
A SQL injection vulnerability in SourceCodester Online Voting System 1.0 allows unauthenticated remote attackers to manipulate the id parameter in /ajax.php?action=save_user to execute malicious queries.
A SQL injection vulnerability in SourceCodester Online Voting System 1.0 allows unauthenticated remote attackers to execute arbitrary SQL commands via the id parameter in /ajax.php?action=delete_voting.
SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0 contains multiple Insecure Direct Object Reference (IDOR) vulnerabilities allowing unauthorized data access and manipulation.
SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0 contains hard-coded credentials in db.php and insecure default passwords, facilitating remote unauthorized access.
An unauthenticated server-side request forgery (SSRF) vulnerability exists in the HTML-to-PDF endpoint of the projeto-siga siga application, allowing attackers to reach internal network resources.
A vulnerability in the sfturing hosp_order application allows unauthenticated attackers to bypass authorization and cancel arbitrary medical appointments via the orderRecordsService.cancelOrder function.
The sfturing hosp_order application contains an authorization bypass vulnerability in the Order Handler component, allowing unauthenticated remote attackers to modify appointments and access user data.
A critical authorization bypass in sfturing hosp_order allows unauthenticated remote attackers to create appointments and access sensitive patient personal information via the OrderController.
Mstfakts College-Management-System contains an authentication flaw in the registration process that allows unauthenticated attackers to hijack pre-provisioned student or lecturer identities.
Bifrost HTTP transport before 2.0.0 allows unauthenticated remote code execution via a malicious plugin path when management authentication is disabled.
OpenVPN on Windows is vulnerable to a binary planting attack during network configuration steps, allowing local authenticated users to execute arbitrary code via an untrusted search path.
PocketMine-MP versions before 4.7.2 are vulnerable to a denial of service attack via malformed skin geometry JSON data, which triggers an unhandled exception and crashes the server.
OpenVPN on Windows contains a command injection vulnerability in argument parsing, allowing remote authenticated users to execute arbitrary commands by supplying a crafted certificate subject.
WWBN AVideo contains a cross-site scripting vulnerability in the YPTSocket plugin, allowing unauthenticated attackers to execute arbitrary JavaScript in the browsers of other users.
A vulnerability in the HPE Networking Fabric Composer API allows unauthenticated remote attackers to access system information and modify sensitive configuration settings.
A broken access control vulnerability in the SureCart WordPress plugin allows authenticated users to modify other accounts, including administrator accounts, potentially leading to full account takeover.
A vulnerability in PostgreSQL Anonymizer allows authenticated, low-privileged users to execute arbitrary code via malicious SQL operators, domain casts, or subqueries.
The Kirki WordPress plugin is vulnerable to stored Cross-Site Scripting (XSS) due to improper HTML entity decoding, allowing unauthenticated attackers to execute malicious JavaScript.
A flaw in Hugging Face Transformers allows unauthorized writing of remote Python files to local disk by performing file caching before mandatory security trust checks.
The Photo Gallery by 10Web WordPress plugin is vulnerable to reflected Cross-Site Scripting (XSS) due to improper sanitization of request parameters on administrative pages.
The Social Media Share Buttons & Social Sharing Icons WordPress plugin is vulnerable to reflected Cross-Site Scripting (XSS) due to improper input escaping in JavaScript event handlers.
OpenVPN contains an integer overflow in the handling of ACK packet ID retransmissions, allowing unauthenticated remote attackers to trigger a denial of service via crafted network inputs.
ZenHive mpp fails to validate input in sponsored payments, allowing unauthenticated remote clients to inflate gas costs and force the sponsor to pay for arbitrary EIP-7702 account delegations.
ZenHive mpp fails to validate the key_authorization field in sponsored payments, allowing unauthenticated attackers to inflate gas costs and provision unauthorized access keys at the sponsor's expense.
An unauthenticated peer can cause a denial of service in the golang.org/x/crypto/ssh package by flooding incomingRequests, which triggers a connection deadlock.
A buffer overflow in the Bluetooth CGMS RACP write handler in the Nordic nRF Connect SDK allows an authenticated BLE peer to perform an out-of-bounds write to adjacent BSS memory.
An unrestricted file upload vulnerability exists in U+Smart Enjoyment WebSite, allowing unauthenticated remote attackers to upload arbitrary files via the /Report/Upload/UploadFormImg.ashx endpoint.
A memory safety vulnerability in the Linux kernel ovpn module allows for out-of-bounds reads due to improper validation of socket ownership before dereferencing internal data.
An out-of-bounds write vulnerability in Samsung Opensource Walrus allows for buffer overflow conditions, potentially leading to unauthorized system impact.
Oxford Nanopore MinKNOW versions prior to 24.06 contain a vulnerability where authentication is improperly validated based on the client source IP address.
OpenMAIC versions before 1.0.1 contain a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to access sensitive cloud metadata services.
The h3 library fails to validate cookie chunk counts, allowing unauthenticated attackers to trigger an O(n²) loop that causes a denial of service.
An access control flaw in the TOTOLINK T6 router allows unauthenticated remote attackers to modify dynamic DNS settings by sending a specifically crafted POST request to the cstecgi.cgi endpoint.
Net::DNS for Perl is vulnerable to memory exhaustion via uncontrolled recursion when processing misplaced TSIG records, potentially leading to denial of service in proxy or forwarding applications.
A memory safety vulnerability in the Linux kernel BPF subsystem allows improper access to socket structures, potentially leading to unauthorized memory operations via mini-sockets.
MISP's UiBeta theme collection view performs unauthorized secondary queries of member events, allowing authenticated users to bypass access controls and view sensitive event data.
An access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to trigger a denial of service or reduce wireless signal power via a crafted POST request.
An incorrect access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to retrieve sensitive cloud firmware download status information via crafted POST requests.
An incorrect access control vulnerability in the TOTOLINK T6 router allows unauthenticated attackers to modify language configurations via a crafted POST request.