CVE-2026-75650
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
Critical vulnerabilities, curated daily for security professionals
Google Chrome accounts for the largest share of the critical disclosures from Saturday, with at least eight CVSS 9.6 vulnerabilities in the browser alongside a CVSS 9.9 flaw in the Masteriyo LMS WordPress plugin and a CVSS 9.8 flaw in the DS Ad Rotator WordPress plugin. Critical CVEs fell to 19 (down 32% from 28 the prior day) while high-priority CVEs rose to 86 (up 76% from 49). Notable entries include CVE-2026-82845 (Masteriyo LMS, CVSS 9.9), CVE-2026-81402 (DS Ad Rotator, CVSS 9.8), and the Chrome cluster led by CVE-2026-87494 and CVE-2026-87504 (both CVSS 9.6). Browser memory-safety bugs and WordPress plugin access-control flaws dominate the critical set, with 14 actively exploited vulnerabilities spanning network edge appliances (Citrix NetScaler, Fortinet, Cisco FMC, MikroTik RouterOS), remote management tools (N-able N-central, ConnectWise ScreenConnect), and developer platforms (GitLab, JFrog Artifactory). Prioritize Chrome updates across managed endpoints, audit WordPress sites for the two affected plugins, and confirm fix status for each edge and remote-management product in the vendor advisory before restricting internet-facing management interfaces.
Immediate action: Update Google Chrome across all managed endpoints and audit WordPress installations for the Masteriyo LMS and DS Ad Rotator plugins, then review internet-facing Citrix NetScaler, Fortinet, Cisco FMC, MikroTik, N-able, ConnectWise, GitLab, and JFrog systems given confirmed active exploitation. Confirm fix status for each product in the vendor's advisory and restrict exposed management interfaces where an update cannot be applied immediately.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
N-able N-central is vulnerable to a pre-authentication remote code execution flaw via static code injection, allowing unauthenticated attackers to execute arbitrary code on the target system.
This vulnerability allows unauthenticated attackers to bypass authentication on Citrix NetScaler ADC and Gateway appliances via an alternate path or channel.
A heap-based buffer overflow in Fortinet FortiOS and FortiSwitchManager allows unauthenticated attackers to execute unauthorized code or commands via specially crafted packets.
An improper system process at boot time in Cisco FMC allows unauthenticated attackers to bypass authentication and execute scripts via HTTP requests to obtain root OS access.
A flaw in the RouterOS SSH login path allows attackers to bypass privilege restrictions by using a specially crafted username, leading to full administrative access.
MikroTik RouterOS contains a memory disclosure and remote denial of service vulnerability in the bandwidth-test service that allows unauthenticated attackers to trigger a kernel restart.
A missing authorization flaw in the ScreenConnect client allows unauthorized file transfer and execution during active remote sessions.
An unauthenticated path traversal vulnerability in the GitLab repository commits API allows remote attackers to read arbitrary files from the server.
A link following vulnerability in the Windows Update Stack allows a local attacker with authorized access to elevate privileges on the affected system.
A heap-based buffer overflow in the Windows ALPC subsystem allows an authenticated attacker to achieve local privilege escalation.
A memory corruption vulnerability in the Google Chrome V8 engine allows remote attackers to execute arbitrary code via a crafted HTML page.
An incorrect authorization vulnerability in JFrog Artifactory allows authenticated attackers to perform unauthorized actions, potentially leading to data compromise.
An improper authentication vulnerability in JFrog Artifactory allows unauthenticated users to obtain an internal token, potentially exposing sensitive resources even when anonymous access is disabled.
The DS Ad Rotator WordPress plugin fails to validate file types or verify user permissions during uploads, allowing unauthenticated attackers to execute arbitrary PHP code on the server.
The Masteriyo LMS WordPress plugin is vulnerable to insecure deserialization, allowing authenticated users to achieve remote code execution and unauthenticated users to perform arbitrary file writes.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A use after free vulnerability in the Google Chrome browser on Windows allows remote attackers to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A use after free vulnerability in the Google Chrome Core component allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted extension.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A use after free vulnerability in Google Chrome's password management component allows remote attackers to execute arbitrary code via social engineering and specific UI interactions.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A use after free vulnerability in Google Chrome Payments allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A use-after-free vulnerability in the Sharing component of Google Chrome for iOS allows remote attackers to execute arbitrary code outside the sandbox via crafted network traffic.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
An incorrect authorization flaw in Google Chrome DevTools allows a remote attacker to achieve sandbox escape and execute arbitrary code via a malicious HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A memory safety vulnerability involving improper array index validation in the ANGLE component of Google Chrome allows for remote code execution via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
Google Chrome contains an incorrect reference resolution vulnerability in Extensions that allows a remote attacker to achieve sandbox escape and arbitrary code execution via crafted network traffic.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 10, analysis completed Sep 13.
A SQL injection vulnerability in the mfish-nocode-pro tableName parameter allows unauthenticated attackers to access sensitive database information.
The Frontegg SAML SSO WordPress plugin fails to validate SAML response signatures or issuers, enabling unauthenticated attackers to hijack sessions or create unauthorized administrator accounts.
The WP images upload on piclect WordPress plugin fails to validate file types during upload, enabling unauthenticated remote code execution.
The WP Component WordPress plugin fails to perform capability or nonce checks, allowing unauthenticated attackers to overwrite arbitrary site options and potentially achieve a full site takeover.
Disclosed Sep 9 without a CVSS score; tracked by CVE Brief from Sep 10; scored Sep 11, analysis completed Sep 11.
A failure to verify SAML2 Bearer token signatures in Apache Impala allows unauthenticated attackers to impersonate arbitrary users via the hs2-http interface.
Disclosed Sep 9 without a CVSS score; tracked by CVE Brief from Sep 10; scored Sep 11, analysis completed Sep 11.
A missing authorization and unsafe reflection vulnerability in the Apache Nutch REST API allows unauthenticated remote attackers to execute arbitrary code.
sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines, allowing unauthenticated attackers to execute arbitrary code via malicious SIP packets.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
The Bifrost vtoken-minting and slpx pallets contain an authorization bypass that allows unauthorized accounts to manipulate channel commission attribution.
Disclosed Sep 6 without a CVSS score; tracked by CVE Brief from Sep 7; scored Sep 11, analysis completed Sep 11.
The Authen::SASL::Perl::DIGEST_MD5 module fails to verify nonces during the authentication handshake, allowing unauthenticated attackers to replay captured credentials.
A memory management flaw in the Linux kernel allows local users to trigger kernel panics or invalid memory access via device-private PMDs during specific memory operations.
A buffer overflow vulnerability exists in the Linux kernel hp-bioscfg driver due to an off-by-one error during string buffer operations, potentially allowing memory corruption.
The Linux kernel AF_IUCV implementation fails to validate the ingress network device for received frames, potentially allowing unauthorized data injection or denial of service between sockets.
A buffer overflow vulnerability exists in the Linux kernel stm32 CEC driver due to missing length checks on received bytes, allowing an out of bounds memory write by a remote CEC peer.
Socket Firewall versions before 2.0.0 fail to verify upstream TLS certificates by default, enabling potential Man-in-the-Middle attacks that could lead to malicious package substitution.
A memory management flaw in the Linux kernel pagewalk implementation allows a local attacker to trigger an out of bounds write via a race condition in page table handling.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A missing authorization flaw in Google Chrome allows remote attackers to bypass system access restrictions using social engineering and a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A privilege elevation vulnerability in the Google Chrome WebUI allows a remote attacker who has compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A vulnerability in Google Chrome's SiteIsolation feature allows a remote attacker who has compromised the renderer process to escape the sandbox and execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
An improper initialization flaw in Google Chrome for Windows allows a remote attacker to achieve sandbox escape and arbitrary code execution via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A vulnerability in Google Chrome on Windows allows an attacker who has compromised the renderer process to escape the sandbox and execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
The ELEX WooCommerce Request a Quote plugin is vulnerable to unauthenticated SQL injection, allowing remote attackers to extract sensitive data from the WordPress database.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 13.
Google Chrome contains a race condition in the V8 engine that allows remote attackers to achieve arbitrary code execution within the sandbox via a specially crafted HTML page.
A local privilege escalation vulnerability exists in the Tonec Internet Download Manager kernel driver (idmwfp.sys) due to improper access controls, allowing local attackers to gain elevated privileges.
A flaw in the Linux kernel HID sensor-hub driver allows an out-of-bounds write due to improper handling of HID report field sizes, potentially leading to memory corruption.
A use-after-free vulnerability in the Linux kernel svcrdma component allows potential memory corruption due to improper handling of failed ADDR_CHANGE listener replacements.
A use-after-free vulnerability in the Linux kernel NFS server (nfsd) allows authenticated remote attackers to cause system crashes or potential code execution via improper stateid reference handling.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A use after free vulnerability in Google Chrome's Cast component allows an adjacent attacker to achieve arbitrary code execution outside the browser sandbox via crafted network traffic.
A buffer overflow vulnerability in the Linux kernel platform/chrome sensorhub driver allows out-of-bounds memory access due to an unchecked sensor number index.
A memory management flaw in the Linux kernel IOMMU driver allows for potential system instability or code execution due to a dangling list entry during probe registration failures.
WWBN AVideo contains a missing authorization flaw in the scheduler email plugin, allowing unauthenticated attackers to access sensitive scheduler jobs and trigger unauthorized emails.
WWBN AVideo contains a stored cross-site scripting vulnerability in the UserGroups::setGroup_name function, allowing administrators to inject malicious scripts into the user management interface.
A use-after-free vulnerability exists in the Linux kernel tracing subsystem due to improper synchronization during sub-buffer order changes, potentially allowing local privilege escalation.
A logic error in the Linux kernel tracing subsystem's simple ring buffer reader swap mechanism can lead to memory corruption during failed link replacement operations.
The MemberPress Corporate Accounts plugin for WordPress contains a mass assignment vulnerability in the add_sub_account_user function, allowing authenticated users to escalate privileges.
The Album Cover Finder WordPress plugin contains a SQL injection vulnerability that allows unauthenticated attackers to query the database.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 10, analysis completed Sep 13.
A memory safety issue due to integer overflow in Google Android allows local attackers to achieve privilege escalation without additional execution requirements.
The BE REST Endpoints WordPress plugin allows unauthenticated users to perform unauthorized widget operations and inject stored cross-site scripting (XSS) payloads.
The Add User Autocomplete WordPress plugin fails to perform capability checks, allowing authenticated users to escalate their privileges to administrator on multisite installations.
The Yogeta WP Cloud WordPress plugin through version 1.0 allows unauthenticated attackers to read arbitrary files from the server due to insufficient input validation on a public endpoint.
The YayPricing WordPress plugin is vulnerable to stored Cross-Site Scripting (XSS) due to a missing authorization check on a REST API endpoint, allowing authenticated subscribers to inject malicious scripts.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 13.
The Loops & Logic WordPress plugin contains an information exposure vulnerability that allows unauthenticated users to access sensitive user records and site configuration data.
A race condition in the Linux kernel lockd and nfsd modules allows for potential use-after-free or NULL pointer dereference, impacting system stability and security.
A remote code execution vulnerability in the vLLM LlavaOnevision2 processor loader allows arbitrary code execution by ignoring the trust_remote_code security parameter.
A use-after-free vulnerability exists in the Linux kernel USB gadget UVC driver due to improper handling of dangling pointers in the bind and unbind error paths.
A use after free vulnerability exists in the Linux kernel USB gadget audio driver, where premature cleanup of sound card structures can lead to memory corruption when accessed from userspace.
A use-after-free vulnerability exists in the Linux kernel at91_udc gadget driver due to improper teardown of the polled-VBUS timer and work queue, potentially allowing local privilege escalation.
A logic error in the Linux kernel Thunderbolt networking driver fails to clear connection states during setup failures, potentially leading to kernel panics or resource mismanagement.
A memory initialization flaw in the Linux kernel MPTCP implementation allows an off-path peer to corrupt subflow bookkeeping via crafted MP_JOIN SYNs during SYN cookie reconstruction.
A memory allocation failure in the Linux kernel SUNRPC component can lead to silent memory corruption and potential system instability when RPC services are initialized under extreme memory pressure.
A logic error in the Linux kernel Bluetooth subsystem leads to an out-of-bounds read vulnerability within the eir_get_service_data function when processing malformed advertising data.
A double-free vulnerability exists in the Linux kernel V4L2 subsystem due to improper error handling in the video_register_device function.
A use-after-free vulnerability in the Linux kernel RapidIO mport character device interface allows local users to trigger memory corruption and potentially achieve arbitrary code execution.
Freeciv versions before 3.2.6 are susceptible to a heap buffer overflow in the worklist_load function, allowing memory corruption via maliciously crafted savegame files.
An out-of-bounds write vulnerability in the Linux kernel mt76 mt7996 Wi-Fi driver allows a malicious device to trigger memory corruption via a crafted MCU response.
A buffer overflow vulnerability exists in the Linux kernel mt7915 wifi driver, allowing a malicious device to perform out-of-bounds writes via a crafted EEPROM address.
A use-after-free (UAF) vulnerability in the Linux kernel iommufd subsystem allows local attackers to trigger memory corruption via concurrent I/O page fault reporting and device domain detachment.
A boundary validation flaw in the Linux kernel tegra241-cmdqv driver allows a guest-controlled virtual Stream ID to alias an incorrect physical Stream ID, potentially leading to unauthorized access.
A buffer handling flaw in the OCFS2 filesystem allows for out-of-bounds memory access via crafted refcount blocks, potentially leading to system instability or arbitrary code execution.
A heap-based out-of-bounds read and write vulnerability exists in the Linux kernel RISC-V KVM subsystem due to an integer overflow when processing PMU event information.
A race condition in the Linux kernel Bluetooth RFCOMM subsystem allows local attackers to trigger a use-after-free vulnerability, potentially leading to system instability or arbitrary code execution.
The Linux kernel ext2 file system driver is vulnerable to lost inode updates for IS_SYNC inodes, which may lead to data corruption or integrity loss.
A resource management flaw in the Linux kernel HID sensor driver allows for improper cleanup of sysfs groups during failure, potentially leading to memory corruption or undefined behavior.
An infinite loop vulnerability exists in the Linux kernel device property handling, which can be triggered during fwnode child node iteration when secondary fwnodes are present.
A use-after-free vulnerability in the Linux kernel vsock virtio driver allows local attackers to cause memory corruption or system crashes due to improper work item flushing order during removal.
A race condition in the Linux kernel i3c driver allows uninitialized lock access during probe, potentially leading to system instability or unauthorized memory state manipulation.
A race condition in the Linux kernel ALSA pcxhr driver allows local attackers to trigger uninitialized mutex state during probe, potentially leading to privilege escalation or system instability.
A race condition or improper cleanup in the Linux kernel IPMI message handler allows for potential memory corruption when an interface startup error occurs.
A race condition in the Linux kernel rt9455 power supply driver allows a use-after-free vulnerability due to improper work-queue cancellation during teardown or probe failure.
A use-after-free vulnerability exists in the Linux kernel power supply driver lp8727, caused by improper IRQ release sequencing that allows delayed work to execute after memory is freed.
A memory corruption vulnerability in the Linux kernel cros_usbpd-charger driver allows a malicious embedded controller to trigger an out of bounds write via an inaccurate port count.
A heap-based buffer overflow exists in the Linux kernel cros_usbpd-charger driver due to insufficient validation of EC-reported port counts, potentially allowing arbitrary memory corruption.
A memory management flaw in the Linux kernel regulator driver causes a dangling pointer, potentially leading to system instability or arbitrary code execution.
The Linux kernel Landlock LSM fails to properly restrict whiteout object creation in OverlayFS, allowing local users to bypass filesystem access controls.
A memory management flaw in the Linux kernel APEI GHES driver allows for out-of-bounds reads during ARM hardware error processing due to incorrect length accounting.
A race condition in the Linux kernel omapfb display driver allows local attackers to trigger a mutex initialization error, potentially leading to system instability or unauthorized memory access.
A race condition in the Linux kernel entry code allows unprivileged local users to bypass seccomp filters by leveraging ptrace and TSYNC, potentially executing prohibited system calls.
A buffer overflow vulnerability exists in the Linux kernel NTFS3 file system driver, potentially allowing local attackers to cause memory corruption or system crashes via a crafted log record.
A vulnerability in the zstd-jni ZstdDictDecompress constructor allows for an out-of-bounds read due to a lack of input validation, potentially leading to JVM termination.
A NULL pointer dereference vulnerability in the Linux kernel NFSD subsystem allows unauthenticated remote attackers to trigger a denial of service via specifically crafted NFS lookup requests.
A buffer handling flaw in the Linux kernel SMC-Rv2 implementation allows oversized messages to cause memory corruption, potentially leading to unauthorized rtoken deletion or installation.
A flaw in the Linux kernel libata-scsi subsystem causes TRIM commands to fail on devices with logical sector sizes exceeding 2048 bytes, resulting in potential system instability.
A memory safety vulnerability exists in the Linux kernel SMB client where an out-of-bounds read occurs during reparse data buffer processing, potentially leading to a system crash.
A vulnerability in the Linux kernel NFSv2 decoder allows for memory corruption due to improper handling of out of range useconds values, potentially leading to unauthorized data modification.
A memory underflow vulnerability in the Linux kernel ath6kl Wi-Fi driver allows adjacent slab memory disclosure due to improper length validation during association events.
A race condition in the Linux kernel svcrdma component allows potential use-after-free scenarios due to improper ordering of teardown operations during RDMA transport destruction.
A race condition in the Linux kernel NFS server file cache management can lead to memory leaks and potential system instability by preventing the proper disposal of file objects.
A use-after-free vulnerability in the Linux kernel NFS server (nfsd) allows for potential memory corruption due to improper management of the fcache_disposal structure during network namespace teardown.
A heap out-of-bounds write vulnerability in Orthanc DICOM Server allows an authenticated attacker to trigger memory corruption via a malicious PNG file.
A slab-out-of-bounds vulnerability exists in the Linux kernel nilfs2 file system driver, triggered during file truncation, which can lead to memory corruption or system instability.
An out-of-bounds write vulnerability in the Linux kernel vicodec driver allows local attackers with low privileges to corrupt kernel heap memory via malicious FWHT encoder operations.
A use-after-free vulnerability in the Linux kernel tracing subsystem allows local attackers to trigger a kernel panic by registering hist triggers with identical names.
A use-after-free vulnerability in the Linux kernel tracing/user_events subsystem allows local attackers to cause system instability or potential code execution via a race condition during fork.
A memory management flaw in the Linux kernel allows local users to trigger a folio reference count BUG by failing to clear stale mappings after freeing swapcache during device migration.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 10, analysis completed Sep 13.
A code execution vulnerability in the CMSimple CoAuthors plugin allows authenticated low-privileged users to trigger server-side execution via crafted content imports.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 10, analysis completed Sep 13.
A high-severity XML External Entity (XXE) vulnerability in the level-rule module of Distribution Management v1.0.0 allows unauthenticated attackers to read sensitive files or probe internal networks.