CVE-2026-49869
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
Critical vulnerabilities, curated daily for security professionals
Yesterday's disclosures were led by a CVSS 10 vulnerability in Adobe Commerce and a pair of critical flaws in Dell Secure Connect Gateway, alongside maximum-severity issues in D-Link and TOTOLINK routers. Critical CVEs rose to 35, a 75% increase over the prior day, while high-priority CVEs climbed to 81, up 45%. Notable entries include CVE-2026-75650 (Adobe Commerce, CVSS 10), CVE-2026-80238 and CVE-2026-61410 (Dell Secure Connect Gateway), CVE-2026-19593 (OpenAI Codex Desktop, CVSS 9.8), and CVE-2026-84133 (Mozilla Firefox and Thunderbird, CVSS 9.8). Enterprise e-commerce, remote support gateways, SAP NetWeaver, and developer tooling feature prominently, with 8 CVEs carrying confirmed active exploitation, including JFrog Artifactory, SonicWall SMA1000, LiteLLM, Starlette, and Google Chrome. Defenders should prioritize internet-facing Adobe Commerce storefronts and Dell and SonicWall gateway appliances, restrict management interfaces on affected routers, and confirm fix status for each product in the vendor advisory.
Immediate action: Prioritize patching Adobe Commerce, Dell Secure Connect Gateway, SonicWall SMA1000, JFrog Artifactory, and Google Chrome, and isolate or restrict management access to affected D-Link and TOTOLINK routers. Confirm fix status and affected versions for each product in the vendor's advisory before scheduling remediation.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Kestra contains an authentication bypass vulnerability due to an improper path validation, allowing unauthenticated attackers to execute arbitrary workflows and achieve Remote Code Execution.
JFrog Artifactory contains an authentication weakness that may allow an unauthenticated attacker to obtain administrative privileges via remote network access.
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition that allows remote attackers to execute arbitrary database commands via the /pa endpoint.
A pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the SonicWall SMA1000 Work Place interface allows remote unauthenticated attackers to perform unauthorized operations.
A post-authentication OS command injection vulnerability exists in the SonicWall SMA1000 Appliance Management Console, allowing an authenticated administrator to execute arbitrary OS commands.
LiteLLM proxy server contains a critical authentication vulnerability that allows unauthenticated access to sensitive functions.
A critical HTTP request smuggling vulnerability exists in the Starlette framework due to improper validation of the Host header, allowing for security restriction bypasses.
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
LibreNMS before 26.8.0 contains an authentication bypass in the REST API, allowing unauthenticated attackers to exploit MySQL type coercion to access sensitive endpoints and achieve remote code execution.
Dell Secure Connect Gateway 5.0 contains an execution with unnecessary privileges vulnerability due to an exposed Docker socket, allowing local attackers to achieve root-level host access.
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
SAP GUI for Java fails to enforce trust level policies for functions triggered by backend systems, potentially allowing remote attackers to execute arbitrary commands on client machines.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
OpenAI Codex Desktop automatically executes arbitrary attacker-controlled programs when opening a Git repository with a malicious .git/config file, leading to full user privilege compromise.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
A site isolation vulnerability exists within the DOM Push Subscriptions component of Mozilla Firefox and Thunderbird, allowing potential full system compromise.
Disclosed Sep 5 without a CVSS score; scored Sep 7, analysis completed Sep 7.
The SEO Flow WordPress plugin contains an improper privilege management vulnerability that allows unauthenticated attackers to gain administrative site access via crafted API requests.
A missing authorization vulnerability in Dell Secure Connect Gateway 5.0 allows unauthenticated remote attackers to execute arbitrary commands on the target system.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
An access control flaw in the TOTOLINK T6 meshSlaveUpdate function allows unauthenticated attackers to trigger unauthorized firmware updates via crafted MQTT messages.
A stack-based buffer overflow in D-Link DIR-822A allows unauthenticated remote attackers to execute arbitrary code via the udhcpcd component.
A flaw in 389 Directory Server allows unauthenticated attackers to gain administrative privileges by leveraging stale SASL identity properties during failed bind attempts.
An out-of-bounds write vulnerability exists in the L2TP Control Message Parser function tunnel_set_params of D-Link DIR-822A, allowing remote code execution via a specially crafted message.
A critical OS command injection vulnerability in the Linksys RE7000 PingTest handler allows remote attackers to execute arbitrary commands with root privileges via crafted network parameters.
The management API in knowns versions before 0.30.0 is exposed without authentication by default, allowing unauthenticated attackers to provision tunnels and expose the API publicly.
An unauthenticated vulnerability in FreeIPA allows attackers to create arbitrary Kerberos principals and grant themselves administrative privileges via the self-managed OTP token ACI.
A deserialization of untrusted data vulnerability exists in Hitachi Cosminexus Component Container, potentially allowing unauthenticated remote code execution.
A deserialization of untrusted data flaw in Next4Biz CSM allows unauthenticated remote code injection.
A stack-based buffer overflow exists in the udhcpd component of D-Link DIR-895L firmware A1_102b07 due to improper handling of DHCP packets in the sendOffer/sendACK functions.
The Bahçelievler Muncipality BiHayat App is vulnerable to an authentication bypass due to improper restriction of excessive authentication attempts.
An unauthenticated memory safety vulnerability in the Extended Passport Protocol processing library may allow remote code execution or system instability via a malformed network request.
The Siemens Reyrolle 7SR5 web interface contains a vulnerability that allows attackers to predict session IDs, leading to unauthenticated access and potential unauthorized device control.
Hitachi Cosminexus Component Container is affected by an OS command injection vulnerability, allowing unauthenticated remote attackers to execute arbitrary commands on the underlying system.
A command argument injection vulnerability in Hitachi Cosminexus Component Container allows unauthenticated remote attackers to execute arbitrary commands.
A vulnerability in the SAP NetWeaver Message Server allows unauthenticated attackers to register unauthorized application server components.
An improper authentication vulnerability in the JetBrains YouTrack Helpdesk feature allows unauthenticated attackers to perform account takeovers by spoofing email addresses.
JetBrains Hub contains a flaw allowing unauthenticated attackers to register a trusted service, resulting in the acquisition of superuser privileges.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
A buffer overflow vulnerability in the Tenda A18 router allows unauthenticated remote attackers to execute arbitrary code by sending malicious input to the fromSetCmdlineRun function.
The @sap/cds-mtxs library contains a vulnerability where insufficient checks allow unauthenticated attackers to steal credentials and manipulate tenant data in multitenant CAP applications.
Knowns before 0.30.0 contains a path traversal vulnerability in import routes, allowing unauthenticated attackers to overwrite arbitrary files on the server.
A vulnerability in the OIS web module of Siemens Siveillance Control and Control Pro allows an authenticated attacker to upload arbitrary files, potentially resulting in root-level system compromise.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
An unauthenticated remote attacker can escalate privileges by exploiting an exposed authTokenKey within the admin configuration endpoint of fast-note-sync-service versions 2.13.7 and earlier.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
An access control flaw in the TOTOLINK T6 remoteCloudUpdateCheck function allows unauthenticated attackers to trigger unauthorized cloud update workflows via crafted MQTT messages.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
An access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to manipulate mesh metadata and state via crafted MQTT messages, potentially leading to full system compromise.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
An incorrect access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to manipulate mesh neighbor records by sending crafted MQTT messages to the cs_broker component.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
An access control vulnerability in TOTOLINK T6 allows unauthenticated attackers to overwrite the slave IP inventory via crafted MQTT messages sent to the cs_broker component.
SourceCodester Class and Exam Timetabling System 1.0 contains a SQL injection vulnerability in the delete_subject.php file due to improper validation of the id parameter.
SourceCodester Online Voting System 1.0 contains an unauthenticated SQL injection vulnerability in the /voting/ajax.php?action=save_category file via the category parameter.
An improper authentication vulnerability in light0011 cms allows unauthenticated remote attackers to impersonate other users by manipulating the username cookie.
The light0011 cms application suffers from an unrestricted file upload vulnerability in its Home controller, allowing remote attackers to upload arbitrary files without authentication.
A missing authentication vulnerability in the saveuser.php endpoint of SourceCodester Simple Traffic Offense System v1.0 allows unauthenticated attackers to create new administrative accounts.
A flaw in the Eclipse Ankaios Control Interface authorizer allows authenticated workloads to bypass authorization checks and access or modify unauthorized cluster states using specific wildcard masks.
The ash-project ash_lua component contains an improper protection of alternate path vulnerability that allows unauthorized reading of sensitive resource attributes via crafted Lua scripts.
An unauthenticated resource exhaustion vulnerability in ash_authentication_oauth2_server allows attackers to consume excessive database storage and memory via the /authorize endpoint.
Disclosed Sep 5; held until the analysis firmed up on Sep 8.
A missing authorization vulnerability in Microsoft Fabric allows an authenticated attacker to elevate privileges over a network.
The league/commonmark library contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension, allowing unauthenticated attackers to trigger a denial of service via CPU exhaustion.
Dell Secure Connect Gateway contains a missing authentication vulnerability that allows unauthenticated remote attackers to gain unauthorized access to critical functions.
Dell Secure Connect Gateway contains a missing authentication vulnerability allowing unauthenticated remote attackers to potentially gain unauthorized access to critical functions.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
A use-after-free and heap-memory disclosure vulnerability in Mozilla Thunderbird allows a malicious IMAP server to leak heap contents into the prefs.js file via a crafted ID response.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
A vulnerability in the WebGPU component of Mozilla Firefox and Thunderbird allows for unauthorized information disclosure.
Dell Secure Connect Gateway contains an improper privilege management vulnerability that allows a local attacker to achieve unauthorized elevation of privileges.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
OpenAI Codex Desktop for Windows and macOS improperly trusts local Git configuration, allowing malicious repositories to execute unauthorized code via Git hooks upon opening.
Dell Secure Connect Gateway contains a hard-coded credentials vulnerability that allows unauthenticated remote attackers to gain unauthorized access to the affected system.
Dell Secure Connect Gateway contains an improper certificate validation vulnerability that allows unauthenticated remote attackers to gain unauthorized access to the system.
The WP Fusion (Pro) plugin for WordPress is vulnerable to privilege escalation in versions up to 3.47.13 due to insufficient authorization checks in the ThriveCart Auto Login handler.
Dell Secure Connect Gateway contains an improper handling of exceptional conditions flaw allowing an unauthenticated remote attacker to bypass protection mechanisms.
Dell Secure Connect Gateway contains an improper certificate validation vulnerability that allows unauthenticated remote attackers to gain unauthorized access.
Dell Secure Connect Gateway 5.0 contains a path traversal vulnerability that allows an unauthenticated remote attacker to potentially achieve remote execution on the target system.
Dell Secure Connect Gateway contains an improper certificate validation vulnerability that allows remote, unauthenticated attackers to potentially gain unauthorized access to the affected system.
Dell Secure Connect Gateway contains a relative path traversal vulnerability that allows an unauthenticated remote attacker to potentially achieve remote code execution.
Dell Secure Connect Gateway contains an improper certificate validation vulnerability that allows unauthenticated remote attackers to bypass protection mechanisms.
Dell Secure Connect Gateway 5.0 contains an incorrect operator vulnerability that allows unauthenticated remote attackers to gain unauthorized access to the system.
Dell Secure Connect Gateway contains an OS command injection vulnerability, allowing unauthenticated remote attackers to execute arbitrary system commands.
A heap buffer overflow in the SASL I/O layer of 389 Directory Server allows an authenticated remote attacker to trigger a denial of service or potentially achieve remote code execution.
Disclosed Sep 5 without a CVSS score; scored Sep 7, analysis completed Sep 7.
The RegistrationMagic plugin for WordPress fails to validate Facebook access token audience, allowing unauthenticated attackers to bypass authentication or register unauthorized accounts.
A missing TLS and authentication implementation in the IntelliJ IDEA IJent gRPC server allows local code execution on Remote Development hosts.
Disclosed Sep 5 without a CVSS score; scored Sep 7, analysis completed Sep 7.
The HT Menu WordPress plugin fails to perform capability checks or output sanitization, allowing authenticated subscribers to inject malicious JavaScript into navigation menus.
A deserialization vulnerability exists in the Artemis component of JBoss EAP 7.4, allowing unauthorized classes to be deserialized due to improperly configured allow-lists and block-lists.
Disclosed Sep 2 without a CVSS score; scored Sep 6, analysis completed Sep 6.
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to improper authentication, allowing unauthenticated attackers to overwrite administrator passwords via the front-end forms module.
Disclosed Sep 2 without a CVSS score; scored Sep 6, analysis completed Sep 6.
The RegistrationMagic WordPress plugin fails to properly sanitize registration form input, enabling unauthenticated Stored Cross-Site Scripting (XSS) attacks targeting administrative users.
The handleCodeReplace function in knowns before 0.30.0 is vulnerable to path traversal, allowing unauthenticated attackers to overwrite arbitrary files on the host system.
A flaw in 389 Directory Server allows unauthenticated LDAP clients to bypass access control checks, potentially enabling unauthorized modification of directory entries.
A privilege escalation vulnerability exists in the Reyrolle 7SR5 web interface due to improper server-side authorization checks, allowing authenticated attackers to bypass role-based access controls.
LibreNMS before 26.8.0 is vulnerable to argument injection in the graph_title parameter, enabling authenticated attackers to bypass authorization and execute arbitrary rrdtool commands.
MISP versions up to 2.5.45 are vulnerable to uncontrolled resource consumption via unauthenticated, unbounded request fields in the password-reset and API-access endpoints.
A directory traversal vulnerability in the embedded HTTP server of Siemens SIMOVE Fleetmanager and SIPLANT allows unauthenticated remote attackers to read arbitrary files from the host system.
A command injection vulnerability exists in the Cockpit 389 Console due to improper sanitization of LDAP distinguished names, allowing an authenticated user to execute commands with root privileges.
A command injection vulnerability exists in the udhcpcd component of the D-Link DIR-895L router, allowing remote unauthenticated attackers to execute arbitrary commands via the Hostname argument.
JetBrains YouTrack is vulnerable to an Insecure Direct Object Reference (IDOR) flaw in the REST API, allowing authenticated users to access restricted resources.
JetBrains YouTrack contains a privilege escalation vulnerability due to unchecked group membership changes, allowing authenticated users to gain unauthorized elevated permissions.
An out-of-bounds write vulnerability in the Siemens Reyrolle 7SR5 device allows unauthenticated remote attackers to trigger a denial-of-service condition via a crafted HTTP message.
An unauthenticated remote attacker can cause a denial of service on Siemens Reyrolle 7SR5 devices by sending excessive concurrent HTTP requests, leading to a device crash and reboot.
An unauthenticated path traversal vulnerability exists in the knowns template preview endpoint, allowing remote attackers to read arbitrary files from the server filesystem.
A NULL pointer dereference in 389 Directory Server allows an unauthenticated remote attacker to cause a denial of service by sending crafted LDAP search requests.
A heap-based buffer overflow in the MediaTek chipset video decoder component allows for local escalation of privileges without user interaction.
Siemens Reyrolle 7SR5 devices generate session tokens with insufficient entropy, allowing unauthenticated remote attackers to predict identifiers and bypass authentication.
A predictable random number generator in Siemens Reyrolle 7SR5 devices allows unauthenticated remote attackers to guess session identifiers and impersonate legitimate users.
An out-of-bounds read vulnerability exists in the lds function of the 92181 markdown library within the md.c file, allowing for remote exploitation.
A critical authentication bypass in the Tenda AC9 router allows unauthenticated remote attackers to change the administrator password via the /goform/fast_setting_wifi_set endpoint.
Knowns versions before 0.30.0 are vulnerable to path traversal in MCP tool arguments, allowing authenticated attackers to perform unauthorized file operations outside the project directory.
Eclipse Jetty is vulnerable to a denial of service attack via unauthenticated WebSocket frames that trigger excessive memory allocation, potentially exhausting the JVM heap.
SAP Integration Suite is vulnerable to XML External Entity (XXE) injection due to improper validation of XML documents, allowing low-privileged attackers to read sensitive server files.
A shared token cache in JetBrains YouTrack allows authenticated users to perform cross-tenant theft of GitHub App installation tokens.
A heap-based buffer overflow in the MediaTek chipset video decoder allows local escalation of privilege without requiring special execution permissions.
Siemens Desigo CC clients are vulnerable to code injection via malicious graphics documents, allowing an attacker to execute commands and write arbitrary files to the host operating system.
Knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only, allowing unauthorized privilege escalation.
A flaw in the FreeIPA idp-add command allows authenticated users to read process environment variables and cause denial of service via improper input validation before LDAP access control checks.
SAP NetWeaver Business Client is vulnerable to arbitrary code execution due to insufficient validation of locally stored data during application startup.
Knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file.
JetBrains IntelliJ IDEA contains a vulnerability where missing project-trust confirmation before building a Dev Container allows for host-level code execution.
A missing authentication vulnerability in the ASUS Control Center Express Agent allows an unauthenticated nearby attacker to gain host control if an active user session exists.
SAP NetWeaver allows unauthenticated users to hijack sessions via a crafted packet that triggers the reprocessing of buffered requests under specific timing conditions.
JetBrains YouTrack prior to 2026.2.18634 contains a flaw where cloning a whiteboard permits unauthorized modifications to links on issues that the user should not be able to access.
JetBrains YouTrack contains an improper authorization vulnerability where authenticated users can modify linked entities via PUT requests without possessing the required update permissions.
An off-by-one vulnerability in the L2TP Control Message Parser of D-Link DIR-605 allows remote attackers to trigger memory corruption via the peer_hostname argument.
A resource exhaustion vulnerability in the WooCommerce plugin for WordPress allows unauthenticated attackers to trigger a Denial of Service (DoS) condition via excessive HTTP requests.
A missing authorization vulnerability in the Csomagpontok és szállítási címkék WooCommerce-hez plugin allows unauthenticated attackers to manipulate access control settings.
PocketMine-MP fails to validate the length of skin data fields provided by players, allowing unauthenticated attackers to cause server crashes via oversized input.
A denial of service vulnerability exists in the commonmark AttributesExtension due to inefficient algorithmic complexity during attribute processing.
Multiple denial of service vulnerabilities in league/commonmark allow unauthenticated attackers to trigger excessive CPU consumption via crafted Markdown input.
A denial of service vulnerability exists in the commonmark Attributes extension due to inefficient quadratic-time sibling list scanning, allowing resource exhaustion via malformed input.
The league/commonmark library is vulnerable to a denial of service attack via algorithmic complexity when processing Markdown headings that result in slug collisions.
A denial of service vulnerability exists in the commonmark Footnote extension due to inefficient handling of duplicate footnote definitions, leading to excessive resource consumption.
Hitachi Cosminexus Component Container contains an XML external entity (XXE) vulnerability, allowing unauthenticated attackers to potentially access sensitive information.
Disclosed Sep 3 without a CVSS score; scored Sep 7, analysis completed Sep 7.
A memory safety vulnerability exists in the Linux kernel Loongson2 MMC driver, where incorrect scatterlist iteration leads to out of bounds memory access.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 7, analysis completed Sep 7.
A denial of service vulnerability exists in the Kamailio IMS P-CSCF registration handling components, allowing unauthenticated remote attackers to disrupt service availability.
Disclosed Sep 1 without a CVSS score; tracked by CVE Brief from Sep 2; scored Sep 6, analysis completed Sep 6.
A Broken Object Level Authorization vulnerability in Grashjs Atlas CMMS allows authenticated users to access and modify company records belonging to other tenants by manipulating numeric IDs.