CVE-2026-75650
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
Critical vulnerabilities, curated daily for security professionals
Enterprise edge and management infrastructure dominate the day's disclosures, with Check Point Quantum Security Gateway, Dell Secure Connect Gateway, and WebPros cPanel all carrying critical remote-exploitation flaws. Yesterday's disclosures produced 11 critical CVEs (down 77 percent from 47 the prior day) and 30 high-priority CVEs (down 72 percent from 109), a total of 41 tracked vulnerabilities. CVE-2026-87827 (CVSS 10) affects KGUARD DVR devices, CVE-2026-67401 (CVSS 9.9) affects WebPros cPanel, and CVE-2026-19583 (CVSS 9.9) affects Rapid7 Velociraptor, an incident response agent deployed with broad endpoint access. Nine vulnerabilities have confirmed active exploitation, including flaws in Citrix NetScaler ADC, Cisco Secure Firewall Management Center, Adobe Commerce, and N-able N-central, a pattern consistent with continued targeting of remote access and managed service tooling. Prioritize internet-facing gateways and administrative consoles: inventory exposed Check Point, Citrix, and Cisco management interfaces, restrict them to trusted management networks, and confirm fix status for each product in the vendor's own advisory before scheduling maintenance windows.
Immediate action: Network security appliances and remote management platforms need attention first: Check Point Quantum, Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center, Fortinet FortiOS, and N-able N-central all appear in today's critical or actively exploited sets, and their administrative interfaces should be restricted to trusted networks where patching cannot happen immediately. Browser and endpoint updates for Google Chrome and Microsoft Windows should follow through normal accelerated channels. Confirm the fix status and affected version ranges for each product in the vendor's own advisory before planning remediation.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
N-able N-central is vulnerable to a pre-authentication remote code execution flaw via static code injection, allowing unauthenticated attackers to execute arbitrary code on the target system.
This vulnerability allows unauthenticated attackers to bypass authentication on Citrix NetScaler ADC and Gateway appliances via an alternate path or channel.
A heap-based buffer overflow in Fortinet FortiOS and FortiSwitchManager allows unauthenticated attackers to execute unauthorized code or commands via specially crafted packets.
An improper system process at boot time in Cisco FMC allows unauthenticated attackers to bypass authentication and execute scripts via HTTP requests to obtain root OS access.
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A link following vulnerability in the Windows Update Stack allows a local attacker with authorized access to elevate privileges on the affected system.
A heap-based buffer overflow in the Windows ALPC subsystem allows an authenticated attacker to achieve local privilege escalation.
A memory corruption vulnerability in the Google Chrome V8 engine allows remote attackers to execute arbitrary code via a crafted HTML page.
The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to unauthenticated arbitrary file upload, which can lead to remote code execution.
MaxSite CMS uses a hardcoded session encryption key, allowing unauthenticated attackers to forge administrator session cookies and bypass authentication via crafted session data.
A heap-based buffer overflow in VPN certificate ASN.1 decoding enables unauthenticated remote attackers to execute arbitrary code on affected Check Point Quantum Security systems.
An improper certificate trust validation vulnerability exists in Check Point Quantum Security Gateways during VPN negotiation, allowing unauthenticated remote code execution.
Dell Secure Connect Gateway 5.0 is vulnerable to an authentication bypass due to insufficient verification of data authenticity, allowing unauthenticated remote attackers to obtain administrative tokens.
A SQL injection vulnerability in the cPanel EmailTrack component allows an authenticated user with mail-enabled account privileges to achieve remote code execution as the root user.
A path normalization flaw in Perforce Akana allows unauthenticated remote code execution via the Policy Manager console by bypassing authentication filters and injecting arbitrary script code.
KGUARD DVR devices expose a command execution service on all network interfaces without authentication, allowing remote attackers to execute arbitrary system commands and compromise the device.
Rapid7 Velociraptor fails to enforce proper permission checks for client monitoring artifacts, allowing authenticated users to execute restricted commands on endpoints.
An SQL injection vulnerability in the Armiya Information Technologies Access Control System allows unauthenticated attackers to execute arbitrary SQL commands.
GeoVision GV-LPC2211 V1.13 is vulnerable to authentication bypass via capture and replay of WS-Security PasswordDigest tokens due to missing nonce and freshness enforcement.
A buffer overflow vulnerability in the WebRTC component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A use-after-free vulnerability in Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
A use-after-free vulnerability in the V8 engine of Google Chrome allows a remote attacker to execute arbitrary code via a crafted HTML page.
A use after free vulnerability in Google Chrome's input handling allows a remote attacker to execute arbitrary code via a crafted HTML page.
A buffer overflow vulnerability in the WebRTC component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
A use after free vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A use after free vulnerability in the Chromecast component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
A use-after-free vulnerability in the Google Chrome DevTools component allows a remote attacker to execute arbitrary code within the sandbox via a crafted HTML page and social engineering.
A use after free vulnerability in the V8 engine of Google Chrome allows a remote attacker to execute arbitrary code via a crafted extension.
A memory safety flaw in Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A memory corruption vulnerability in the Google Chrome Codecs component allows a remote attacker to execute arbitrary code via a specially crafted HTML page.
A memory corruption vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a malicious browser extension.
A double free vulnerability in the PDFium component of Google Chrome on Windows allows remote attackers to execute arbitrary code via a malicious PDF file.
A type confusion vulnerability in the V8 JavaScript engine of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a specially crafted HTML page.
A type confusion vulnerability in the XML processing component of Google Chrome allows remote attackers to execute arbitrary code via a malicious HTML page.
Disclosed Sep 4 without a CVSS score; tracked by CVE Brief from Sep 5; scored Sep 9, analysis completed Sep 10.
An authenticated remote code execution vulnerability in the admin_config.php component of SeaCMS v13.6 allows attackers to execute arbitrary code via a crafted POST request.
Disclosed Sep 5 without a CVSS score; scored Sep 10, analysis completed Sep 10.
The Music Store WordPress plugin fails to sanitize user input, allowing unauthenticated SQL injection.
Disclosed Sep 8; held until the analysis firmed up on Sep 10.
Dell Secure Connect Gateway contains a missing authentication vulnerability in critical functions, allowing unauthenticated remote attackers to gain unauthorized access to the system.
Disclosed Sep 7 without a CVSS score; scored Sep 9, analysis completed Sep 10.
Apache Ant ftp and scp tasks are vulnerable to a path traversal flaw that allows a malicious server to overwrite arbitrary files outside the target directory using the permissions of the user.
Disclosed Sep 5 without a CVSS score; scored Sep 10, analysis completed Sep 10.
The IPGP Visitors Origin WordPress plugin before 1.6 is vulnerable to Reflected Cross-Site Scripting (XSS) due to improper sanitization of user input.
GitPython before 3.1.60 is vulnerable to arbitrary code execution due to improper validation of the git directory location, allowing attackers to impersonate directories via tracked files.
GeoVision GV-LPC2011 and GV-LPC2211 devices running version 1.13 are vulnerable to unauthorized configuration overwrites and administrative password replacement by guest users via the SSVR interface.
GeoVision GV-LPC2211 version 1.13 is vulnerable to OS command injection via the ONVIF ConsumerReference.Address parameter, allowing authenticated users to execute arbitrary commands as root.
A use-after-free vulnerability in the Linux kernel Bluetooth ISO implementation allows unauthenticated attackers to trigger memory corruption via concurrent socket closure operations.
A memory management flaw in the Linux kernel KVM s390 vsie implementation allows a nested guest to retain unauthorized access to crypto devices via stale bits in the crycb.
A heap-based out-of-bounds write vulnerability in VLC media player allows remote code execution via a crafted PNG image file that triggers an integer overflow during picture buffer allocation.
Disclosed Sep 8; held until the analysis firmed up on Sep 10.
Next4Biz CSM contains a path traversal vulnerability that allows unauthenticated remote attackers to access sensitive files on the underlying system.
Disclosed Sep 4 without a CVSS score; tracked by CVE Brief from Sep 5; scored Sep 9, analysis completed Sep 10.
An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via a crafted POST request.
Disclosed Sep 7 without a CVSS score; tracked by CVE Brief from Sep 8; scored Sep 9, analysis completed Sep 10.
Protocol::HTTP2 versions before 1.14 allow memory exhaustion via closed streams that are not properly removed from the connection stream table.
Disclosed Sep 7 without a CVSS score; tracked by CVE Brief from Sep 8; scored Sep 9, analysis completed Sep 10.
Net::IP::LPM versions before 1.12 for Perl incorrectly validate prefix lengths, leading to lookup table poisoning and potential security policy bypasses.