CVE-2026-75650
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
Critical vulnerabilities, curated daily for security professionals
WordPress ecosystem components dominate the day's critical disclosures, with StellarWP The Events Calendar, wpeverest Everest Forms, and ThemeREX Addons all carrying CVSS 9.8 flaws that expose large numbers of public-facing sites. Critical CVEs totaled 28 (down 51% from 57 the prior day) alongside 49 high-priority entries (down 47% from 93), for 77 CVEs overall. The highest-severity items include CVE-2026-14560 (CVSS 10) in the WordPress teddy-bear-customize-addon plugin, CVE-2026-82617 (CVSS 10) in Apache OpenNLP, and CVE-2026-87988 (CVSS 10) in MistralAI Mistral Vibe. Remote code execution and authentication bypass remain the dominant patterns, and the 14 actively exploited entries reach infrastructure that sits at the network edge, including Citrix NetScaler, Fortinet FortiOS, Cisco Secure Firewall Management Center, MikroTik RouterOS, and ConnectWise ScreenConnect. Prioritize internet-facing remote access and management planes first, restrict administrative interfaces to trusted networks, and confirm fix status for each affected component in the vendor's own advisory.
Immediate action: Internet-facing remote access and management systems need attention first: Citrix NetScaler ADC and Gateway, Fortinet FortiOS and FortiSwitchManager, Cisco Secure Firewall Management Center, MikroTik RouterOS, ConnectWise ScreenConnect, GitLab, and JFrog Artifactory all appear with confirmed exploitation. In parallel, audit WordPress installations for The Events Calendar, Everest Forms, ThemeREX Addons, and teddy-bear-customize-addon, and restrict administrative interfaces to trusted networks where an update cannot be applied immediately. Confirm the fix status and required version for each affected product directly in the vendor's advisory before closing out remediation.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
N-able N-central is vulnerable to a pre-authentication remote code execution flaw via static code injection, allowing unauthenticated attackers to execute arbitrary code on the target system.
This vulnerability allows unauthenticated attackers to bypass authentication on Citrix NetScaler ADC and Gateway appliances via an alternate path or channel.
A heap-based buffer overflow in Fortinet FortiOS and FortiSwitchManager allows unauthenticated attackers to execute unauthorized code or commands via specially crafted packets.
An improper system process at boot time in Cisco FMC allows unauthenticated attackers to bypass authentication and execute scripts via HTTP requests to obtain root OS access.
A flaw in the RouterOS SSH login path allows attackers to bypass privilege restrictions by using a specially crafted username, leading to full administrative access.
MikroTik RouterOS contains a memory disclosure and remote denial of service vulnerability in the bandwidth-test service that allows unauthenticated attackers to trigger a kernel restart.
A missing authorization flaw in the ScreenConnect client allows unauthorized file transfer and execution during active remote sessions.
An unauthenticated path traversal vulnerability in the GitLab repository commits API allows remote attackers to read arbitrary files from the server.
A link following vulnerability in the Windows Update Stack allows a local attacker with authorized access to elevate privileges on the affected system.
A heap-based buffer overflow in the Windows ALPC subsystem allows an authenticated attacker to achieve local privilege escalation.
A memory corruption vulnerability in the Google Chrome V8 engine allows remote attackers to execute arbitrary code via a crafted HTML page.
An incorrect authorization vulnerability in JFrog Artifactory allows authenticated attackers to perform unauthorized actions, potentially leading to data compromise.
An improper authentication vulnerability in JFrog Artifactory allows unauthenticated users to obtain an internal token, potentially exposing sensitive resources even when anonymous access is disabled.
The Events Calendar plugin for WordPress is vulnerable to unauthenticated remote code execution via insecure deserialization in the is_safe_widget_instance function.
The teddy-bear-customize-addon WordPress plugin fails to validate uploaded files, allowing unauthenticated attackers to execute arbitrary PHP code on the server.
Apache OpenNLP is vulnerable to Denial of Service attacks due to inefficient regular expression patterns in the RegexNameFinder, allowing attackers to trigger CPU exhaustion or thread stack overflow.
SPIP versions before 4.4.18 are vulnerable to remote code execution via the editer_objet action, allowing attackers to inject malicious job entries into the database that execute upon cron processing.
The Events Calendar plugin for WordPress is vulnerable to unauthenticated remote code execution due to insufficient validation of widget classes, allowing attackers to trigger a callable-invocation sink.
LaciSynchroni server versions prior to 1.2.3 contain an improper authentication vulnerability allowing unauthenticated users to impersonate any target user via client-side configuration manipulation.
Mistral Vibe suffers from an arbitrary file access vulnerability due to missing path validation in commands, allowing unauthenticated attackers to escape workspace restrictions.
A logic flaw in GetSimple CMS and its Community Edition allows unauthenticated attackers to create a new administrator account by accessing the leftover setup script.
Everest Forms for WordPress contains an unauthenticated PHP object injection vulnerability in versions 3.6.0 and earlier, potentially allowing remote code execution.
ThemeREX Addons for WordPress is affected by an unauthenticated PHP object injection vulnerability, allowing remote code execution via deserialization of untrusted data.
The teddy-bear-customize-addon WordPress plugin contains an authentication bypass flaw allowing unauthenticated attackers to log in as any user, including administrators, via email address spoofing.
The Advanced Customized Prompts WordPress plugin contains an authentication bypass flaw that allows unauthenticated attackers to log in as any registered user or create new administrative accounts.
An arbitrary file write vulnerability in Mistral Vibe allows attackers to write to or overwrite files outside the intended workspace by bypassing shell redirection permission checks.
An improper access control vulnerability in Fortinet FortiMonitorOnSight allows unauthenticated attackers to potentially gain unauthorized access to sensitive information.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 10, analysis completed Sep 10.
UC Browser for Android (13.7.8.1314) contains a Universal Cross-Site Scripting (UXSS) flaw allowing unauthenticated attackers to execute arbitrary JavaScript in the context of any origin.
A critical flaw in the Chef Automate API gateway allows unauthenticated attackers to bypass identity validation and gain elevated access to protected system functions.
WAVLINK WN535M1 and WN535M3 routers contain an unauthenticated OS command injection vulnerability in the sync_server daemon, allowing remote attackers to execute arbitrary commands as root.
An arbitrary code execution vulnerability in Mistral Vibe allows unauthenticated attackers to bypass command permission checks using environment variable assignments.
Mistral Vibe contains an arbitrary code execution vulnerability involving improper inspection of ANSI-C quoted arguments, allowing unauthenticated attackers to bypass command permission checks.
Mistral Vibe contains an arbitrary code execution vulnerability where shell constructs bypass command permission checks, allowing unauthenticated attackers to execute arbitrary commands.
A deserialization vulnerability in GitLab allows authenticated users with Duo Chat access to execute arbitrary server object lookups, potentially exposing sensitive credentials and configurations.
SPIP versions before 4.4.18 contain a missing authorization vulnerability in administrative action endpoints, allowing unauthenticated attackers to reset passwords for any user, including administrators.
A privilege escalation vulnerability in Hugo allows Node tools triggered during builds to bypass security restrictions, enabling unauthorized file system access outside the working directory.
A critical authentication bypass in the Sofia IPC daemon of Xiongmai XM530 IP cameras allows remote attackers to execute privileged ONVIF actions via crafted SOAP requests.
The authorizer server fails to validate redirect URIs, allowing unauthenticated attackers to steal authentication tokens via an open redirect vulnerability on the /authorize endpoint.
A default administrative password in a bundled inventory management component allows unauthenticated access to the administrative interface if the setup routine is not correctly executed.
Disclosed Sep 6 without a CVSS score; tracked by CVE Brief from Sep 7; scored Sep 10, analysis completed Sep 12.
A use-after-free vulnerability exists in libcurl when handling HTTP/2 Server Push streams if the parent handle shares connections, potentially leading to memory corruption during cleanup.
A flaw in the RACER UAV control software allows unauthenticated attackers to trigger unsafe trajectory planning and potential collisions by manipulating the finite state machine.
The Tutor LMS plugin for WordPress is vulnerable to PHP Object Injection, allowing authenticated users with subscriber-level access or higher to achieve remote code execution.
A stored cross-site scripting (XSS) vulnerability in the AVideo donationLink profile field allows authenticated users to execute arbitrary JavaScript in the browsers of other visitors.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the Printing component of Google Chrome allows a remote attacker to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the Google Chrome Core component allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the WebPackaging component of Google Chrome allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use-after-free vulnerability in the ANGLE component of Google Chrome on Windows allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page.
NextGen Connect (Mirth Connect) versions 4.7.1 and earlier are vulnerable to SQL injection via the Database Connector API, allowing authenticated users to perform unauthorized data and system operations.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
Google Chrome contains an insufficient policy enforcement vulnerability in Extensions, allowing remote attackers to potentially execute arbitrary code via a crafted HTML page and social engineering.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
An incorrect authorization vulnerability in Google Chrome WebView for Android allows a remote attacker to escape the sandbox and execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A missing authorization flaw in the Google Chrome FileSystem allows a remote attacker to achieve sandbox escape and arbitrary code execution through a compromised renderer process and social engineering.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
Google Chrome contains a vulnerability in the FileAPI caused by improper input validation, allowing a remote attacker to achieve sandbox escape and execute arbitrary code.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A high-severity injection vulnerability in Google Chrome DevTools allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A confused deputy vulnerability exists in the DataTransfer component of Google Chrome, allowing a remote attacker to achieve sandbox escape and arbitrary code execution via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
An out of bounds read vulnerability in the ANGLE graphics component of Google Chrome allows remote attackers to potentially execute arbitrary code outside the browser sandbox.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
An incorrect authorization flaw in the Views component of Google Chrome on Windows allows a remote attacker to execute arbitrary code outside the browser sandbox via social engineering.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A missing authorization flaw in Google Chrome Extensions allows a remote attacker who has compromised the renderer process to potentially execute arbitrary code outside the sandbox.
A use after free vulnerability in Microsoft Edge (Chromium-based) allows an authorized attacker to execute arbitrary code over a network.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use-after-free vulnerability in the Views component of Google Chrome allows a local attacker to achieve arbitrary code execution outside the browser sandbox via UI interaction.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use-after-free vulnerability in the Google Chrome Receiver component allows an adjacent attacker to achieve arbitrary code execution outside the sandbox using crafted network traffic.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the Views component of Google Chrome allows a local attacker to achieve arbitrary code execution outside the sandbox.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in Google Chrome DevTools allows a local attacker to achieve arbitrary code execution outside of the browser sandbox.
The Masteriyo LMS plugin for WordPress is vulnerable to unauthenticated PHP object injection, allowing attackers to execute arbitrary code.
The YPTWallet plugin for AVideo contains a stored cross-site scripting vulnerability that allows authenticated users to execute malicious scripts in an administrator's session.
The CustomizeUser plugin for AVideo contains a stored cross-site scripting vulnerability via the field_name parameter, allowing authenticated administrators to inject malicious scripts.
The LoginControl plugin for AVideo fails to HTML-encode PGP public keys, allowing authenticated attackers to perform stored cross-site scripting (XSS) attacks.
Puppet Enterprise is affected by a command injection vulnerability in the java_keystore_passwd parameter, allowing authenticated administrative users to execute arbitrary commands with root privileges.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A race condition in the Google Chrome Updater for Windows allows a local attacker to execute arbitrary code outside the sandbox.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A race condition in the Google Chrome Updater for Windows allows a local attacker to execute arbitrary code outside the sandbox.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A vulnerability in the Google Chrome Updater for Windows allows a local attacker to execute arbitrary code outside the sandbox via a local program due to incorrect authorization.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A local uncontrolled search path element vulnerability in the Google Chrome CredentialProvider on Windows allows attackers to execute arbitrary code outside the browser sandbox.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A race condition in the Chromoting component of Google Chrome on Windows allows a local attacker to execute arbitrary code outside of the browser sandbox.
The Gutenverse News plugin for WordPress fails to properly sanitize HTML in comment inputs, allowing unauthenticated users to execute Stored Cross-Site Scripting attacks.
A local privilege escalation vulnerability in ST Engineering iDirect terminals allows low-privilege users to gain full administrative control due to improper authorization handling.
A configuration exposure vulnerability in iDirect VSAT terminals allows authenticated users to retrieve sensitive MD5 password hashes via a JSON API endpoint.
OpenMRS legacyui-api contains an authorization bypass vulnerability allowing authenticated users to execute administrative DWR services, specifically the startHl7ArchiveMigration method.
A critical XML external entity (XXE) vulnerability in the Akana API Platform allows unauthenticated attackers to perform unauthorized data extraction via improper XML-to-JSON processing.
Gato GraphQL plugin for WordPress contains a privilege escalation vulnerability allowing authenticated subscribers to gain elevated privileges.
A privilege escalation vulnerability in the SMS Alert Order Notifications plugin allows authenticated subscribers to gain unauthorized administrative access.
A heap buffer overflow in stb_vorbis through 1.22 in start_decoder() allows attackers to cause process crashes or heap corruption via a crafted Ogg Vorbis file with large entries.
An authenticated OS command injection vulnerability in CISA Malcolm allows attackers to execute arbitrary system commands via crafted filenames in the file-transfer interface.
A stored cross-site scripting vulnerability in the AVideo Bookmark plugin allows authenticated video owners to inject malicious scripts that execute in the context of any visitor viewing the video.
Pardus Software contains an OS command injection vulnerability that allows an attacker to execute arbitrary commands on the underlying operating system.
The Headroom WebSocket server fails to validate the Origin header, allowing unauthenticated attackers to perform arbitrary LLM requests via a malicious browser client.
An authorization bypass vulnerability in Knowns versions 0 through 0.33.0 allows read-only users to perform unauthorized administrative operations by incorrectly exempting the project.set action.
CISA Malcolm contains a vulnerability where a hardcoded default secret allows attackers to forge authentication cookies if the setup routine is bypassed during deployment.
NextGen Mirth Connect contains an XML External Entity (XXE) injection vulnerability in the XSLT Transformer Step, potentially allowing data exfiltration and denial of service.
The nl-portal-backend-libraries package fails to verify ownership in the submitTaakV2 GraphQL mutation, allowing authenticated users to access and modify other users' task data.
Melange and Apko fail to verify the data section hash of APK packages, allowing attackers to substitute malicious file contents while bypassing signature checks.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 10, analysis completed Sep 10.
A memory corruption vulnerability in the FFmpeg RTP encoding process allows for potential remote code execution via a crafted input file.