CVE-2026-75650
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
Critical vulnerabilities, curated daily for security professionals
Consumer and small-business networking hardware dominated the day's critical disclosures, with D-Link and Totolink routers accounting for six of the 14 critical CVEs, alongside a maximum-severity flaw in a WordPress payment plugin. The brief covers 14 critical CVEs (down 26% from the prior day's 19) and 102 high-priority CVEs (up 19% from 86). CVE-2026-81648 in the CryptoPayment Gateway WordPress plugin carries a CVSS of 10, while CVE-2026-90692 and CVE-2026-90693 affect the D-Link DIR-878 at CVSS 9.9, and CVE-2026-84939 reaches 9.1 in Apache FreeMarker. Remote code execution against internet-facing router firmware and CMS extensions is the recurring pattern, which puts branch offices, remote worker sites, and self-hosted web properties in scope. Fourteen CVEs carry confirmed active exploitation, including issues in Citrix NetScaler, Cisco Secure Firewall Management Center, and ConnectWise ScreenConnect; restrict management interfaces on those platforms to trusted networks and verify remediation guidance directly with each vendor.
Immediate action: Prioritize the actively exploited issues in remote access and management platforms first: Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center, ConnectWise ScreenConnect, N-able N-central, and MikroTik RouterOS, followed by inventory of internet-exposed D-Link and Totolink routers and any sites running the CryptoPayment Gateway plugin. Consult each vendor's advisory to confirm the current fix status and the exact version that addresses the issue before scheduling maintenance windows.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
N-able N-central is vulnerable to a pre-authentication remote code execution flaw via static code injection, allowing unauthenticated attackers to execute arbitrary code on the target system.
This vulnerability allows unauthenticated attackers to bypass authentication on Citrix NetScaler ADC and Gateway appliances via an alternate path or channel.
A heap-based buffer overflow in Fortinet FortiOS and FortiSwitchManager allows unauthenticated attackers to execute unauthorized code or commands via specially crafted packets.
An improper system process at boot time in Cisco FMC allows unauthenticated attackers to bypass authentication and execute scripts via HTTP requests to obtain root OS access.
A flaw in the RouterOS SSH login path allows attackers to bypass privilege restrictions by using a specially crafted username, leading to full administrative access.
MikroTik RouterOS contains a memory disclosure and remote denial of service vulnerability in the bandwidth-test service that allows unauthenticated attackers to trigger a kernel restart.
A missing authorization flaw in the ScreenConnect client allows unauthorized file transfer and execution during active remote sessions.
An unauthenticated path traversal vulnerability in the GitLab repository commits API allows remote attackers to read arbitrary files from the server.
A link following vulnerability in the Windows Update Stack allows a local attacker with authorized access to elevate privileges on the affected system.
A heap-based buffer overflow in the Windows ALPC subsystem allows an authenticated attacker to achieve local privilege escalation.
A memory corruption vulnerability in the Google Chrome V8 engine allows remote attackers to execute arbitrary code via a crafted HTML page.
An incorrect authorization vulnerability in JFrog Artifactory allows authenticated attackers to perform unauthorized actions, potentially leading to data compromise.
An improper authentication vulnerability in JFrog Artifactory allows unauthenticated users to obtain an internal token, potentially exposing sensitive resources even when anonymous access is disabled.
A code injection vulnerability in the Conditional Content Pro extension allows authenticated, privileged users to execute arbitrary PHP code on the server via malicious article syntax.
The CryptoPayment Gateway plugin for WordPress contains an authorization bypass vulnerability allowing unauthenticated users to perform administrative actions, including file deletion and credential theft.
A stack-based buffer overflow in the D-Link DIR-878 router allows remote authenticated attackers to execute arbitrary code by manipulating the IPv6Address or Hostname arguments.
Disclosed Sep 10 without a CVSS score; scored Sep 12, analysis completed Sep 12.
A path traversal vulnerability exists in the Apache FreeMarker template loading mechanism when localized lookup is enabled, allowing unauthenticated attackers to access unauthorized files.
A stack-based buffer overflow in the SetWan3Settings function of the D-Link DIR-878 allows remote attackers to trigger memory corruption via manipulated WAN setting arguments.
A stack-based buffer overflow in the D-Link DIR-823G router allows remote attackers to execute code via the HNAP1 interface.
A buffer overflow vulnerability in the Totolink A3002MU router allows a remote authenticated attacker to trigger a crash via the submit-url parameter in the formNewSchedule function.
A buffer overflow vulnerability in the Totolink A3002MU router allows remote attackers to trigger a denial of service or potentially execute arbitrary code via the service_type parameter.
A buffer overflow vulnerability in the Totolink A3002MU router allows remote attackers to cause a denial of service via a crafted static_ipv6 parameter in the formIpv6Setup function.
A buffer overflow vulnerability in the Totolink A3002MU router allows remote authenticated attackers to trigger memory corruption via the ip6addr parameter in the formFilter function.
A command injection vulnerability exists in the D-Link DWR-M920 router, specifically within the newPin parameter of the /boafrm/formPinManageSetup endpoint.
A missing authentication flaw in the Contec CPSL-08P1EN allows remote attackers to perform unauthorized operations due to a lack of critical function access controls.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 10, analysis completed Sep 14.
The mpush gateway server v0.8.1 is vulnerable to remote code execution via a crafted broadcast message.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 10, analysis completed Sep 14.
The springboot-project v1.0.0 seller-side module contains an access control flaw allowing unauthenticated users to manage products and orders.
A SQL injection vulnerability in the Feng Office Legacy API allows unauthenticated remote attackers to manipulate the auth argument in the Contacts::instance->findAll function.
Amundsen frontend versions through 4.3.0 contain a stored cross-site scripting (XSS) vulnerability due to improper HTML sanitization in ResourceListItem components.
Disclosed Sep 9 without a CVSS score; tracked by CVE Brief from Sep 10; scored Sep 11, analysis completed Sep 11.
A flaw in Apache Parquet allows an attacker to redirect KMS tokens to a malicious host by exploiting improper input validation of file-controlled KMS URLs in the crypto keytools package.
The ASE2000 V2 Communication Test Set contains an improper certificate validation flaw in its IEC 60870-5-104 TLS client, allowing network-positioned attackers to perform Man-in-the-Middle attacks.
A SQL injection vulnerability in SourceCodester School Registration and Fee System 1.0 allows unauthenticated attackers to execute arbitrary database queries via the category parameter.
A SQL injection vulnerability in SourceCodester School Registration and Fee System 1.0 allows remote, unauthenticated attackers to manipulate database queries via the period parameter.
SourceCodester School Registration and Fee System 1.0 contains a SQL injection vulnerability in the /bilal/normal/delete_stud.php file via the selector[] parameter, allowing unauthenticated remote access.
SourceCodester School Registration and Fee System 1.0 contains an unauthenticated SQL injection vulnerability in the status parameter of the save_stud.php file.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A heap buffer overflow in the Android p2p_pd.c component allows for remote code execution via a specially crafted bootstrap request without requiring user interaction.
Dromara orion-visor versions up to 2.5.7 use a hard-coded AES cryptographic key, allowing attackers to decrypt sensitive SSH private keys and host passwords stored in the database.
Disclosed Sep 9 without a CVSS score; scored Sep 12, analysis completed Sep 12.
A race condition in the FileAPI of Google Chrome allows a remote attacker who has compromised the renderer process to bypass site isolation via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 12, analysis completed Sep 12.
An incorrect authorization vulnerability in Google Chrome Site Isolation allows remote attackers to bypass security boundaries through a crafted file and social engineering.
Suprema BioStar 2 and BioStar X contain a vulnerability in the adserversetting endpoint that allows authenticated attackers to retrieve Active Directory service account credentials in cleartext.
A local privilege escalation vulnerability in the Logitech Logi Options+ updater service allows low-privileged users to execute arbitrary code with SYSTEM privileges on Windows systems.
The Tabs & Accordions extension for Joomla is vulnerable to stored Cross-site Scripting (XSS) via the data-rlta-alias parameter, allowing privileged users to execute malicious JavaScript.
Cheshire Cat AI up to 1.9.2 fails to validate user identity in default configurations, allowing unauthenticated attackers to impersonate any user via a manipulated HTTP header.
An improper authorization vulnerability in the Rizwan17 inventory-management-system allows unauthenticated attackers to manipulate user roles during registration.
An unauthenticated privilege escalation vulnerability exists in the Tourism-Management-System user registration endpoint, allowing attackers to create administrative accounts.
A critical flaw in the Tourism-Management-System password recovery function allows unauthenticated attackers to reset the password of any account to a default value, leading to full account takeover.
Dromara orion-visor contains a hard-coded credential vulnerability in the ExposeApiAspect component, allowing unauthenticated remote attackers to bypass API authentication and manipulate host data.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A flaw in Google Chrome ServiceWorker logic allows a remote attacker who has compromised the renderer process to bypass site isolation protections using a specially crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A missing authorization flaw in Google Chrome Site Isolation allows a remote attacker to bypass security boundaries via a crafted HTML page.
The Rakuten Kobo Desktop Application installer for Windows is vulnerable to DLL hijacking, allowing local attackers to execute arbitrary code with the privileges of the installing user.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A confused deputy vulnerability exists in BiometricsSettingsBase.java within Android, allowing for local privilege escalation without user interaction.
The Regular Labs Modals extension for Joomla is vulnerable to stored cross-site scripting (XSS) via executable URL schemes, allowing privileged users to inject malicious JavaScript into visitor browsers.
A privileged stored cross-site scripting (XSS) vulnerability exists in the Modals Pro extension for Joomla, allowing lower-privileged authors to execute arbitrary JavaScript via event handlers.
The snappy-java library contains an out-of-bounds write vulnerability due to missing destination buffer capacity validation during decompression, which can lead to JVM termination.
The wasm2c compiler in WebAssembly wabt fails to check the return value of calloc, allowing a sandbox escape via memory corruption that can lead to arbitrary code execution on the host system.
HexStrike AI contains a path traversal vulnerability in the FileOperationsManager function, allowing unauthenticated remote attackers to write arbitrary files to the host system.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A logic error in ClipboardService.java causes a multi-user isolation vulnerability in Android, allowing for local escalation of privilege without user interaction.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A consent bypass vulnerability in Android's IntentForwarderActivity allows for local privilege escalation via tapjacking or overlay attacks without requiring user interaction.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A logic error in WindowState.java allows for an overlay bypass in Android, potentially resulting in local escalation of privilege without user interaction.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
An integer overflow in the rw_t3t.cc component of the Android operating system leads to an out of bounds write, enabling local privilege escalation.
Disclosed Sep 10 without a CVSS score; scored Sep 11, analysis completed Sep 11.
The Ultimate Gift Cards for WooCommerce plugin fails to validate gift card values against checkout payments, allowing unauthenticated users to gain excess store credit.
ESPnet allows arbitrary code execution via unsafe deserialization of pretrained model checkpoints when using torch.load with weights_only set to False.
Disclosed Sep 10 without a CVSS score; scored Sep 11, analysis completed Sep 11.
A privilege escalation vulnerability in the Registration Form for WooCommerce plugin allows authenticated users to register accounts with unauthorized roles, potentially leading to full site takeover.
Disclosed Sep 9 without a CVSS score; scored Sep 12, analysis completed Sep 12.
The Quentn WP WordPress plugin is vulnerable to unauthenticated SQL injection, allowing remote attackers to extract arbitrary data from the database.
The User Registration & Membership WordPress plugin contains an improper privilege management flaw that allows authenticated users to escalate their roles to administrator without completing payment.
HexStrike AI is vulnerable to remote OS command injection via unauthenticated API endpoints, allowing arbitrary code execution by manipulating tool parameters in the hexstrike_server.py script.
HexStrike AI contains an unauthenticated remote command execution vulnerability in the /api/command endpoint due to a lack of authentication and improper input sanitization in hexstrike_server.py.
HexStrike AI contains an unauthenticated OS command injection vulnerability in the /api/python/execute endpoint, allowing remote attackers to execute arbitrary code via the code or script arguments.
Unauthenticated attackers can permanently delete arbitrary posts, pages, and media attachments in specific WordPress plugins due to missing authorization checks.
The Really Simple Security plugin for WordPress contains an authentication bypass flaw allowing attackers to reset two-factor authentication and gain unauthorized administrative access.
The User Registration & Membership plugin contains a privilege escalation flaw allowing authenticated users to assign themselves administrative roles.
An HTTP request smuggling vulnerability in HAProxy allows unauthenticated remote attackers to bypass security rules and intercept concurrent client requests via desynchronized connection pooling.
Disclosed Sep 10 without a CVSS score; scored Sep 11, analysis completed Sep 11.
An authorization bypass in Apache Camel K allows authenticated tenants to reference and potentially expose sensitive secrets from the operator namespace, leading to unauthorized information disclosure.
A buffer overflow vulnerability in the Contec RP-WAH-SR series web service allows a remote authenticated attacker to execute arbitrary code via a specially crafted request.
A buffer overflow vulnerability in the web service of Contec ECE1000 series devices allows a remote authenticated attacker to execute arbitrary code.
A stack-based buffer overflow in the Tenda W20E router allows remote attackers to execute code or cause a crash via the formDelWebAuthWhiteUser function.
Extreme Networks IQ Engine contains a stack-based buffer overflow in the Bonjour Gateway, which can be triggered via the ah_event_send function to potentially execute arbitrary code.
Spug versions up to 3.4.0 are vulnerable to OS command injection via the ping_check function, allowing authenticated users to execute arbitrary commands on the host system.
A directory traversal vulnerability in Paessler PRTG Network Monitor allows unauthenticated attackers to read arbitrary local files on the host system.
CrewAI uses an insufficient Python blocklist approach for sandboxing, allowing attackers to bypass security controls by leveraging the full Python runtime environment and object graph.
CyberPanel versions prior to 2.4.4 contain an ORM query filter flaw when detecting alias domains, potentially allowing unauthorized modifications.
SIPp through 3.7.7 contains a buffer overflow in the get_peer_tag function, allowing unauthenticated remote attackers to trigger a process crash by sending crafted SIP messages.
SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function that allows unauthenticated remote attackers to crash the process via crafted SIP messages.
A symlink following vulnerability in Flatpak allows a malicious sandboxed application to gain arbitrary read and write access to host files, potentially leading to host-level code execution.
A command injection vulnerability in Contec CONPROSYS M2M devices allows authenticated attackers to execute arbitrary OS commands.
An unrestricted file upload vulnerability in the Contec CONPROSYS TM Series allows authenticated remote attackers to execute arbitrary commands via specially crafted files.
Strapi contains a stored cross-site scripting (XSS) vulnerability in the content manager WYSIWYG preview component that allows authenticated users to achieve account takeover.
LangBot versions before 4.10.11 contain a password reset vulnerability due to insufficient entropy in recovery keys and a lack of rate limiting on the reset-password endpoint.
CAPEv2 contains an authorization vulnerability in REST API endpoints that allows authenticated users to access and delete analysis tasks submitted by other users.
Open Notebook before 1.11.0 contains a Server-Side Request Forgery vulnerability in the POST /api/sources endpoint, allowing authenticated users to access internal network resources.
The Quick Index extension for Joomla is vulnerable to privileged stored cross-site scripting due to improper input sanitization of class attribute values, allowing for potential malicious script injection.
A null pointer dereference in the Zephyr RTOS MQTT-SN client can be triggered by a malicious gateway, leading to kernel panics or memory corruption.
A resource exhaustion vulnerability in the UnrealIRCd webserver allows unauthenticated remote attackers to cause a denial of service by sending HTTP requests containing an excessive number of headers.
An unauthenticated OS command injection vulnerability exists in the PentestAgent MCP HTTP server via the run_task function, allowing remote attackers to execute arbitrary shell commands on the host.
GH05TCREW PentestAgent allows remote OS command injection via the LocalRuntime.execute_command function, which executes unvalidated shell commands generated by an LLM.
Anil-matcha Open-Generative-AI contains an unrestricted file upload vulnerability in the S3 Upload component due to improper handling of the x-proxy-target-url argument in /api/upload-binary.
The embedded-graphics library contains an integer overflow vulnerability in the ImageRaw::draw_sub_image function, which can be triggered remotely via a manipulated width argument.
The Tourism-Management-System contains multiple unauthenticated update endpoints that allow remote attackers to modify arbitrary records, including forum content, chat messages, and user data.
The WARP-Clash-API authorized function fails to enforce authentication when the SECRET_KEY environment variable is unset, allowing unauthenticated access to sensitive account management endpoints.
The lenve vhr application contains a vulnerability where default credentials are set during installation, allowing unauthenticated attackers to gain administrative access.
An unrestricted file upload vulnerability in Contec CAN-2-WF and CAN-2-USB converters allows remote authenticated attackers to execute arbitrary code.
OpenStack Glance contains a Server-Side Request Forgery (SSRF) vulnerability in the location API, allowing authenticated users to access internal network endpoints and metadata services.
MKVToolNix contains a heap buffer overflow in the bundled avilib library, which can be triggered by parsing a malicious AVI file with mkvmerge.
A stack-based buffer overflow in the Samsung Exynos mobile processor camera driver allows a local attacker to cause a denial of service via a malformed message.
SIPp through 3.7.7 contains a stack buffer overflow in createAuthHeader() when processing SIP authentication challenges, allowing an attacker to corrupt the stack and crash the client process.
A command injection vulnerability in Contec FX series industrial devices allows authenticated attackers to execute arbitrary OS commands.
A command injection vulnerability in Contec SGA1000 allows authenticated attackers to execute arbitrary OS commands.
A command injection vulnerability in the Contec CONPROSYS PAC Series allows an authenticated attacker to execute arbitrary OS commands on the device.
A command injection vulnerability in the Contec CONPROSYS TM Series allows authenticated attackers to execute arbitrary OS commands.
A critical eval injection vulnerability exists in the Contec CONPROSYS HMI System, allowing authenticated attackers to execute arbitrary code on the system.
An OS command injection vulnerability in Contec CAN-2-WF and CAN-2-USB devices allows authenticated attackers to execute arbitrary OS commands.
Contec SolarView Compact devices are vulnerable to OS command injection within the Schedule Settings, allowing authenticated attackers to execute arbitrary system commands.
The Direct Mail extension for TYPO3 contains an authorization flaw in its configuration module, allowing authenticated users to perform configuration injection or arbitrary code execution.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A Use After Free vulnerability in Arm GPU kernel drivers allows a local non-privileged user to access freed memory during GPU processing operations.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A Use After Free vulnerability in Arm GPU kernel drivers allows a local, non-privileged user to perform improper memory operations, potentially resulting in unauthorized memory access.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A Use After Free vulnerability in various Arm GPU kernel drivers allows a local, non-privileged user to access freed memory via valid GPU memory operations.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A Use After Free vulnerability in Arm GPU drivers allows a local, non-privileged user to access freed memory via GPU operations like WebGL or WebGPU, potentially leading to arbitrary code execution.
A path traversal vulnerability in Contec FX series industrial gateways allows authenticated attackers to read or modify arbitrary files on the server via the FTP interface.
A path traversal vulnerability in the Contec SGA1000 allows authenticated attackers to read or modify arbitrary files on the server via FTP.
A double-free vulnerability in the Samsung Exynos MFC encoder driver allows local attackers to trigger kernel memory corruption and potentially achieve arbitrary code execution.
The Snippets extension for Joomla is vulnerable to privileged stored cross-site scripting due to improper input sanitization, allowing lower-privileged users to inject malicious values into snippets.
A privileged stored cross-site scripting (XSS) vulnerability in the Articles Anywhere extension allows high-privileged users to inject malicious HTML event attributes into article links.
The ca-certificates package for Amazon Linux 2 fails to properly remove TrustCor root certificates, resulting from an incomplete fix for a previous vulnerability.
Nodemailer's addressparser component is vulnerable to a quadratic time complexity flaw when parsing RFC 5322 email comments, allowing attackers to trigger a denial of service via CPU exhaustion.
A path traversal vulnerability in rustypaste before 0.18.1 allows unauthenticated attackers to write files to arbitrary locations by bypassing directory-escape checks via the custom filename header.
Rhymix versions before 2.1.31 are susceptible to an insecure direct object reference vulnerability that allows authenticated users to access arbitrary files via extra variables.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A race condition in Arm GPU kernel drivers allows a local, non-privileged user to cause a denial of service or disclose sensitive information via improper GPU memory processing.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A local information disclosure vulnerability in Arm GPU kernel drivers allows non-privileged users to access sensitive kernel memory via improper GPU memory processing operations.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 11.
A vulnerability in the BES2300 Bluetooth Audio SoC firmware allows unauthenticated attackers to cause a Denial of Service via a crafted L2CAP packet.