CVE-2026-86060
A flaw in the RouterOS SSH login path allows attackers to bypass privilege restrictions by using a specially crafted username, leading to full administrative access.
Critical vulnerabilities, curated daily for security professionals
Hewlett Packard Enterprise EdgeConnect SD-WAN Gateways account for three of the day's highest-scoring flaws (CVE-2026-76669, CVE-2026-76670 and CVE-2026-76672, all CVSS 9.9), placing network edge infrastructure at the centre of yesterday's disclosures. The set totals 64 critical CVEs (up 14% from 56 the prior day) and 59 high-priority CVEs (down 26% from 80), with 123 CVEs disclosed overall. Two perfect-score issues also stand out: CVE-2026-59971 in designcomputer mysql_mcp_server and CVE-2026-53710 in IBM mcp-context-forge, both CVSS 10, alongside CVE-2026-45579 and CVE-2026-61667 (CVSS 9.9) in DIRACGrid DIRAC and CVE-2026-89656 (CVSS 9.8) in the Linux kernel. Model Context Protocol server implementations feature repeatedly, indicating that AI agent tooling is now a recurring target class next to conventional gateway, grid computing and kernel components. Eight CVEs carry confirmed active exploitation, including Mikrotik RouterOS, ConnectWise ScreenConnect, GitLab, Cisco Secure Email Gateway, Google Chrome and JFrog Artifactory, so internet-facing management interfaces and remote access tooling warrant the first review pass.
Immediate action: Prioritise HPE EdgeConnect SD-WAN Gateways, Mikrotik RouterOS, ConnectWise ScreenConnect, Cisco Secure Email Gateway, GitLab and JFrog Artifactory, then restrict management interface exposure on any of these that is reachable from the internet. Review MCP server deployments (mysql_mcp_server, IBM mcp-context-forge) and Linux kernel builds against CVE-2026-89656. Confirm fix status and available versions in each vendor's own advisory before scheduling remediation windows.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A flaw in the RouterOS SSH login path allows attackers to bypass privilege restrictions by using a specially crafted username, leading to full administrative access.
MikroTik RouterOS contains a memory disclosure and remote denial of service vulnerability in the bandwidth-test service that allows unauthenticated attackers to trigger a kernel restart.
A missing authorization flaw in the ScreenConnect client allows unauthorized file transfer and execution during active remote sessions.
An unauthenticated path traversal vulnerability in the GitLab repository commits API allows remote attackers to read arbitrary files from the server.
A critical SQL injection vulnerability in Cisco Secure Email Gateway allows unauthenticated remote attackers to execute arbitrary commands with root privileges via crafted email messages.
A memory corruption vulnerability in the Google Chrome V8 engine allows remote attackers to execute arbitrary code via a crafted HTML page.
An incorrect authorization vulnerability in JFrog Artifactory allows authenticated attackers to perform unauthorized actions, potentially leading to data compromise.
An improper authentication vulnerability in JFrog Artifactory allows unauthenticated users to obtain an internal token, potentially exposing sensitive resources even when anonymous access is disabled.
The Cotonti Comments plugin contains an unsafe deserialization vulnerability in the ci parameter, allowing unauthenticated attackers to trigger remote code execution via PHP object injection.
A critical authentication bypass in the MySQL MCP Server allows unauthenticated remote attackers to execute arbitrary SQL queries, potentially leading to unauthorized data access or code execution.
A remote code execution vulnerability exists in DIRAC via improper neutralization of dynamically evaluated code in the RequestManagementSystem, allowing authenticated attackers to execute system commands.
DIRAC is vulnerable to SQL injection and subsequent code execution via unsafe dataset handling in FileCatalogHandler.py, allowing authenticated attackers to achieve full system compromise.
An unauthenticated code injection vulnerability in the python_sandbox_server allows attackers to execute arbitrary OS commands via the execute_code MCP tool.
A privilege escalation flaw in the HPE EdgeConnect SD-WAN Orchestrator API allows authenticated users to gain administrative control over the system.
An API privilege escalation vulnerability in HPE EdgeConnect SD-WAN Orchestrator allows low-privileged authenticated users to gain administrative control over the system.
PraisonAI versions 1.4.0 through 1.7.1 contain a sandbox escape vulnerability in the codeMode tool, allowing authenticated attackers to execute arbitrary code on the host filesystem.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A heap-based out-of-bounds write vulnerability in the Linux kernel libceph component allows attackers to trigger memory corruption via malformed CRUSH maps.
An authenticated remote attacker can exploit the cache synchronization endpoint in HPE EdgeConnect SD-WAN Gateways to disclose sensitive configuration data, including API tokens and credentials.
The JetFormBuilder plugin for WordPress is vulnerable to unauthenticated privilege escalation, allowing remote attackers to create new administrator-level accounts by exploiting improper input validation.
A critical vulnerability in the Oracle Access Manager Authentication Engine allows an unauthenticated, remote attacker to achieve a full system takeover.
A critical vulnerability in Oracle Platform Security for Java allows unauthenticated attackers to achieve full system takeover via network access.
A critical vulnerability in the Oracle WebLogic Server Web Container allows unauthenticated remote attackers to achieve full system takeover via crafted HTTP requests.
An unauthenticated, easily exploitable vulnerability in the Oracle Internet Directory LDAP Server allows a remote attacker to achieve a full system takeover.
Oracle Forms Services contains a critical vulnerability allowing unauthenticated remote attackers to achieve full system compromise via HTTP, potentially impacting broader Fusion Middleware environments.
A critical security vulnerability in Oracle Hyperion Financial Management allows unauthenticated remote attackers to modify or access sensitive financial data.
A critical authentication engine vulnerability in Oracle Access Manager allows low privileged network attackers to compromise the system and impact additional products via scope change.
An authentication engine vulnerability in Oracle Access Manager allows low privileged network attackers to achieve a full system takeover.
A critical vulnerability in Oracle WebCenter Portal allows a low privileged attacker to achieve a full system takeover via the Composer component.
A critical vulnerability in the Oracle Service Delivery Platform Messaging Enabler allows low privileged, network-based attackers to achieve full system takeover via T3 or IIOP protocols.
A critical vulnerability in the Oracle Service Delivery Platform Messaging Enabler allows low privileged attackers to achieve full system takeover via network-based T3 or IIOP protocols.
A critical vulnerability in the Oracle Service Delivery Platform Messaging Enabler allows low privileged, network-based attackers to achieve full system takeover via HTTP.
A critical vulnerability in Oracle WebCenter Sites allows low privileged, network-based attackers to achieve full system takeover via HTTP.
A critical vulnerability in the Oracle WebLogic Server TopLink Integration component allows low-privileged, network-based attackers to achieve full system takeover via HTTP.
A critical vulnerability in Oracle WebCenter Portal allows a low privileged, network-based attacker to achieve a full system takeover via the Composer component.
A critical vulnerability in the Oracle Internet Directory LDAP server allows a low privileged attacker to achieve a full system takeover via network access.
A critical vulnerability in the Oracle Internet Directory LDAP server allows low-privileged, network-adjacent attackers to achieve a full system takeover and cross-product compromise.
A critical vulnerability in Oracle Business Intelligence Enterprise Edition allows a low-privileged, network-based attacker to achieve full system takeover via HTTP.
A critical security vulnerability in Oracle Hyperion Financial Management allows low privileged attackers to achieve a full system takeover via network-based HTTP requests.
The TrueBooker WordPress plugin is vulnerable to authorization bypass, allowing unauthenticated attackers to modify arbitrary user emails and reset account passwords.
A critical vulnerability in Oracle WebLogic Server allows unauthenticated remote attackers to achieve full system takeover via T3 or IIOP protocols.
A critical vulnerability in Oracle WebLogic Server allows unauthenticated remote attackers to achieve full system takeover via T3 or IIOP protocols.
Oracle Access Manager contains an easily exploitable vulnerability in the Authentication Engine allowing unauthenticated remote attackers to achieve full system takeover via T3 or IIOP protocols.
A critical vulnerability in the Oracle Access Manager Authentication Engine allows unauthenticated remote attackers to achieve full system takeover via HTTP.
A critical vulnerability in the Oracle Access Manager Authentication Engine allows an unauthenticated attacker to achieve a full system takeover via network access.
An unauthenticated remote code execution vulnerability exists in the Portlet Services component of Oracle WebCenter Portal, allowing full system takeover via HTTP.
An unauthenticated remote code execution vulnerability exists in the Oracle WebCenter Portal Composer component, allowing for a full system takeover via HTTP.
The zereight gitlab-mcp server improperly handles file paths and authentication in SSE mode, allowing unauthenticated attackers to read sensitive files and perform account takeovers.
Disclosed Sep 12 without a CVSS score; scored Sep 13, analysis completed Sep 13.
The CODE MONKEYS PROPOSALS WordPress plugin fails to validate file paths and lacks capability checks, allowing authenticated users to delete arbitrary server files and achieve a site takeover.
Disclosed Sep 12 without a CVSS score; scored Sep 13, analysis completed Sep 13.
The WebTotem Backups WordPress plugin fails to validate file paths and authorization, allowing authenticated users to delete arbitrary files on the server, potentially leading to a full site takeover.
An authentication bypass vulnerability in the _account_log function allows unauthenticated remote attackers to gain administrative access to affected Pepperl+Fuchs IO-Link Master devices.
Casdoor through 4.4.0 contains an authorization bypass in the /api/mcp endpoint, allowing authenticated users with valid application credentials to perform unauthorized cross-organization administration.
An unauthenticated remote attacker can upload a malicious IODD file to execute arbitrary shell commands with root privileges, resulting in persistent compromise.
The mySCADA myPRO Manager command API fails to enforce authentication, allowing unauthenticated remote attackers to access privileged management functions.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Ceph filesystem component of the Linux kernel allows an unauthenticated attacker to trigger memory corruption via race conditions during session management.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability exists in the Linux kernel Ceph filesystem component due to a race condition during cap flushing, potentially leading to memory corruption or system instability.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel NFSD component during NFSv4.0 revoked-state cleanup allows for potential memory corruption or system instability.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel NFSD subsystem allows unauthenticated remote attackers to trigger memory corruption and potential code execution during delegation revocation.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel NFSD subsystem allows unauthenticated remote attackers to potentially achieve arbitrary code execution or cause a system crash.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel NFSD subsystem allows unauthenticated attackers to trigger a system crash or potentially execute arbitrary code via client teardown.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel nfsd subsystem allows remote, unauthenticated attackers to trigger memory corruption and potential code execution during asynchronous copy operations.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel NFS server allows unauthenticated attackers to trigger memory corruption and potential system instability during asynchronous copy operations.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A flaw in the Linux kernel NFS implementation allows for a potential use-after-free condition when composing filehandles, which may lead to system instability or arbitrary code execution.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel ksmbd module allows authenticated attackers to trigger memory corruption via race conditions in oplock break notifications.
Disclosed Sep 9 without a CVSS score; tracked by CVE Brief from Sep 10; scored Sep 12, analysis completed Sep 16.
An unauthenticated arbitrary file upload and path traversal vulnerability in LZ-litchi allows remote attackers to write files outside the intended directory via the directory parameter.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A misconfiguration in the Linux kernel IOMMU subsystem allows for improper ACS enforcement when tboot is enabled, potentially leading to security bypasses.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A memory management flaw in the Linux kernel iaa crypto driver allows data corruption when software fallback is triggered during decompression on hardware analytics errors.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
The Linux kernel SUNRPC implementation fails to properly validate RFC 4121 MIC token lengths in gss_krb5_verify_mic_v2, potentially leading to out-of-bounds memory access.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A buffer over-read vulnerability exists in the Linux kernel Ceph filesystem implementation, where insufficient bounds checking on xattr value lengths allows for potential information disclosure or denial of service.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
The Linux kernel ceph filesystem driver contains an out-of-bounds read vulnerability in the MDS map decoder, which can be triggered by unauthenticated network attackers.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A flaw in the Linux kernel NFSACL v2 SETACL implementation allows unauthenticated remote attackers to inadvertently delete directory ACLs by sending malformed requests.
An argument injection vulnerability in the video upload function of Fireshare prior to version 1.6.14 allows unauthenticated attackers to write or overwrite arbitrary system files.
Disclosed Sep 9 without a CVSS score; tracked by CVE Brief from Sep 10; scored Sep 12, analysis completed Sep 16.
A security flaw in Actions Semiconductor Media Player Utilities v.4.46 allows physically proximate attackers to execute arbitrary code via the Production.dll and RdiskUpgrade.exe components.
A use after free vulnerability in Google Chrome Internals allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
A use after free vulnerability in the Google Chrome DOM allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
A command injection vulnerability in the IO-Link Master devices allows authenticated users with low privileges to execute arbitrary commands with root privileges via the get_iodd_menu_info endpoint.
A command injection vulnerability in the Pepperl+Fuchs IO-Link Master series allows authenticated attackers to execute arbitrary code with root privileges.
A command injection flaw in the Pepperl+Fuchs device upload endpoint allows authenticated attackers with operator credentials to execute arbitrary commands with root privileges.
A command injection vulnerability in the parameter management endpoint allows authenticated, low-privileged remote attackers to execute arbitrary commands with root privileges.
A command injection vulnerability in the Pepperl+Fuchs IO-Link Master modules allows authenticated attackers to execute arbitrary commands with root privileges via the save_iodd_parameters endpoint.
A local file inclusion vulnerability in the IO-Link Master modules allows low-privileged authenticated attackers to execute arbitrary PHP code via the get_iodd_port_info endpoint.
A local file inclusion vulnerability in the Pepperl+Fuchs IO-Link Master series allows low-privileged remote attackers to execute arbitrary PHP code via the save_iodd_parameters endpoint.
A command injection vulnerability in the Pepperl+Fuchs IO-Link Master allows an authenticated low-privileged attacker to execute arbitrary commands with root privileges via the web interface.
A type confusion vulnerability in the ServiceWorker component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A type confusion vulnerability in the Google Chrome Compositing component allows a remote attacker to execute arbitrary code within the sandbox via a crafted HTML page.
A type confusion vulnerability in Google Chrome's CacheStorage component allows a remote, unauthenticated attacker to execute arbitrary code within the sandbox using a crafted HTML page.
A use after free vulnerability in Microsoft Edge allows an unauthorized attacker to potentially elevate privileges over a network.
A heap-based buffer overflow in Microsoft Edge allows an unauthenticated remote attacker to execute arbitrary code via a network-based attack vector.
Disclosed Sep 9 without a CVSS score; scored Sep 13, analysis completed Sep 13.
A flaw in Google Chrome's Network component allows a remote attacker who has compromised the renderer process to bypass site isolation using a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 13, analysis completed Sep 13.
An incorrect authorization vulnerability in the Google Chrome FileSystem component allows remote attackers to bypass site isolation using a crafted PDF file.
A security vulnerability in Oracle Hyperion Financial Management allows a low privileged, locally authenticated attacker to achieve a full system takeover.
A vulnerability in the Proxy User Delegation component of Oracle User Management allows low privileged, network-based attackers to achieve full system takeover.
Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in the ntools_tcpdump_start_set.cgi endpoint due to an unsized sprintf call, allowing potential remote code execution.
An unauthenticated remote attacker can compromise Oracle Business Intelligence Enterprise Edition via HTTP, leading to unauthorized data access, modification, or partial denial of service.
Netcore NR255-V version 1.5.130703 is vulnerable to OS command argument injection within its tcpdump utility components, allowing authenticated attackers to execute arbitrary system commands.
A critical vulnerability in Oracle Identity Manager allows low privileged attackers to achieve full system takeover via network protocols T3 and IIOP.
A vulnerability in the Portlet Services component of Oracle WebCenter Portal allows a low privileged attacker to achieve full system takeover via network access.
Oracle WebCenter Portal contains a vulnerability in the Composer component that allows a low-privileged, network-adjacent attacker to achieve a full system takeover.
A critical vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows an authenticated attacker to gain full control of the application via T3 or IIOP protocols.
A vulnerability in the Oracle WebCenter Enterprise Capture Client Bundle allows a low privileged attacker to achieve full system takeover via network access.
A vulnerability in Oracle WebCenter Sites allows a low privileged attacker with network access to achieve a full system takeover via HTTP.
A vulnerability in the Oracle WebCenter Portal Runtime Tools component allows a low-privileged, network-adjacent attacker to achieve full system takeover.
A vulnerability in the Siebel Cloud Manager component of Oracle Siebel CRM allows an authenticated attacker with low privileges to achieve full application takeover via network access.
A vulnerability in the Oracle Spares Management component of Oracle E-Business Suite allows a low privileged attacker to achieve full system takeover via network-based HTTP requests.
A vulnerability in the Oracle User Management component of E-Business Suite allows a low privileged attacker to compromise and take over the system via HTTP.
A vulnerability in the Oracle Sales Online component of Oracle E-Business Suite allows a low privileged attacker to achieve a full system takeover via network access.
A vulnerability in Oracle Application Testing Suite version 13.3.0.1 allows low privileged users to achieve full system takeover via network access.
A vulnerability in the RDBMS component of Oracle Database Server allows a low privileged attacker to achieve a full system takeover via Oracle Net.
A vulnerability in the Oracle Customer Interaction History component allows a low privileged attacker to compromise the application via an HTTP request.
A vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite allows a low privileged, network-based attacker to achieve a full system takeover.
A vulnerability in the Oracle Diagnostics Interfaces component of Oracle Applications Manager allows a low privileged attacker to achieve full system takeover via network access.
A vulnerability in Oracle Siebel CRM Server Infrastructure allows authenticated attackers with low privileges to achieve full system takeover via network access.
A high-severity vulnerability in the Oracle Siebel CRM Deployment server infrastructure allows authenticated attackers with network access to achieve a full system takeover.
A vulnerability in the Oracle Database Server RDBMS component allows low-privileged users to achieve a full system takeover via the DBMS_REDEFINITION package.
A vulnerability in the Oracle Business Intelligence Enterprise Edition Service Administration UI allows low-privileged network attackers to achieve a full system takeover.
A security vulnerability in Oracle BI Publisher allows a low privileged attacker with network access to achieve a full system takeover via the SOAP interface.
A vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite allows a low privileged attacker to achieve a full system takeover via HTTP.
A vulnerability in the Oracle Database Server RDBMS component allows a low privileged attacker with Create DB Link privileges to compromise the database.
A high-severity vulnerability in the Oracle Coherence Core component allows an authenticated attacker with low privileges to achieve a full system takeover via network access.
A high-severity vulnerability in the Oracle Contracts component of Oracle E-Business Suite allows a low-privileged, network-based attacker to achieve a full system compromise.
A vulnerability in the Oracle Product Hub component of Oracle E-Business Suite allows a low privileged attacker to achieve full system takeover via network-based HTTP exploitation.
A high severity vulnerability in Oracle Purchasing allows a low privileged attacker to achieve a full system takeover via HTTP network access.
A security vulnerability in Oracle Hyperion Financial Management allows a low privileged, network-based attacker to gain full control of the application via HTTP.
A security vulnerability in Oracle Hyperion Financial Management allows a low privileged, network-based attacker to achieve a complete system takeover via HTTP.
A security vulnerability in Oracle Hyperion Financial Management allows a low privileged attacker to achieve full system takeover via network-based HTTP exploitation.
A command injection vulnerability in the Field_Shadow_Password class allows authenticated low-privileged remote attackers to execute arbitrary system commands with root privileges.
A command injection vulnerability in the /api/status/data endpoint allows authenticated, low-privileged remote attackers to execute arbitrary commands with root privileges.
Digital Watchdog VMAX series recorders contain hard-coded credentials that allow unauthenticated attackers to gain root access to the ftpd service and access the underlying file system.
A vulnerability in Arista EOS with gNMI enabled allows an authenticated client to execute arbitrary code with root privileges on the switch via a specially crafted request.
Digital Watchdog VMAX series recorders are vulnerable to unauthenticated remote command execution due to a missing authentication check in a critical system function.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A memory management flaw in the Linux kernel swap subsystem allows local, authenticated users to trigger silent memory corruption and system instability via improper hibernation slot handling.
Disclosed Sep 9 without a CVSS score; tracked by CVE Brief from Sep 10; scored Sep 12, analysis completed Sep 16.
A buffer overflow vulnerability in the GPAC j2kdec_process() function allows an unauthenticated attacker to execute arbitrary code via a malicious file.