CVE-2026-76461
A critical SQL injection vulnerability in Cisco Secure Email Gateway allows unauthenticated remote attackers to execute arbitrary commands with root privileges via crafted email messages.
Critical vulnerabilities, curated daily for security professionals
Google Chrome, Apple's operating system family, and several widely deployed open-source components led yesterday's disclosures, with sandbox-escape and remote code execution classes dominating the high-scoring entries. The day carried 31 critical CVEs (up 11% from the prior day's 28) and 91 high-priority CVEs (up 47% from 62), for 122 total. CVE-2026-93603 (CVSS 10) in patriksimek vm2 and CVE-2026-61682 (CVSS 9.9) in kcp-dev kcp sit at the top of the range, followed by CVE-2026-84609 (CVSS 9.8) across Apple iOS, iPadOS, macOS, tvOS, visionOS, and watchOS, and CVE-2026-84434 (CVSS 9.8) in the Gravity Forms WordPress plugin. Seven entries have confirmed active exploitation, spanning Cisco Secure Email Gateway, Cisco Identity Services Engine, Google Pixel, Acronis Backup, and the Linux kernel. Defenders should prioritize internet-facing Cisco security appliances and backup infrastructure, verify browser and mobile fleet update channels are current, and inventory applications embedding vm2 or pg_partman, restricting untrusted input to those components until fixes are confirmed.
Immediate action: Cisco Secure Email Gateway and Identity Services Engine, Acronis Backup, and Apple and Chrome endpoint fleets are the most exposed and should be scheduled first, with Linux kernel updates following on the standard maintenance cycle. Applications embedding vm2, pg_partman, or XWiki Rendering should be inventoried and their untrusted input paths restricted until component versions are confirmed. Confirm fix availability and the exact fixed version in each vendor's own advisory before closing out remediation.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A critical SQL injection vulnerability in Cisco Secure Email Gateway allows unauthenticated remote attackers to execute arbitrary commands with root privileges via crafted email messages.
A logic error in the Google Pixel cellular modem component allows for unauthenticated, adjacent privilege escalation without user interaction.
An authentication bypass vulnerability in the Cisco Identity Services Engine API allows unauthenticated, remote attackers to gain unauthorized access to the management interface.
Acronis Backup plugins for cPanel and Plesk contain an insecure file permissions vulnerability that allows authenticated users to perform local privilege escalation.
A race condition in the Linux kernel crypto subsystem allows local users to cause state inconsistencies via concurrent writes to an af_alg socket.
A memory corruption vulnerability in the Linux kernel netfilter bridge component allows for out of bounds writes during ARP packet processing.
A vulnerability in the Linux kernel TLS implementation allows for improper handling of zero-length records during recvmsg processing, potentially leading to unauthorized system state manipulation.
The kcp front-proxy fails to sanitize identity headers, allowing authenticated tenants to perform cross-workspace impersonation and gain elevated privileges.
An SQL injection vulnerability in the pg_partman PostgreSQL extension allows authenticated users to achieve database-wide compromise and arbitrary operating system command execution.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 17.
A use after free vulnerability in the Google Chrome Auth component allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 17.
A use after free vulnerability in the Google Chrome Core allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 17.
A vulnerability in the ANGLE graphics engine of Google Chrome allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.
The Gravity Forms plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads, allowing remote code execution via hidden file upload fields that bypass validation.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
A permissions vulnerability in multiple Apple operating systems allows an unauthorized application to modify protected system files due to inadequate path validation.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
A certificate validation flaw in multiple Apple operating systems allows an attacker with a compromised intermediate certificate authority to issue certificates with arbitrary extended key usages.
A vulnerability in XWiki Rendering allows authenticated users to achieve remote code execution by injecting script macros into HTML macro content.
A sandbox escape vulnerability in vm2 allows unauthenticated attackers to execute arbitrary code on the host system by exploiting improper handling of the `this` receiver in non-strict functions.
A heap-based buffer underflow in IBM MQ for HPE NonStop allows an authenticated attacker to trigger a denial of service or execute arbitrary code by sending specially crafted multi-segment messages.
A buffer overflow vulnerability in the Totolink A3002MU router allows remote attackers to trigger a denial of service or potential code execution via the submit-url parameter in the formWlWds function.
A buffer overflow vulnerability in the Totolink A3002MU router allows remote, unauthenticated attackers to crash the device or potentially execute arbitrary code via the submit-url parameter.
A heap-based buffer overflow in IBM MQ Appliance protocol processing allows unauthenticated remote attackers to trigger a denial of service or execute arbitrary code.
A buffer overflow vulnerability in the TOTOLINK A3002MU router allows remote attackers to cause a denial of service via a crafted submit-url parameter in the formWlAc function.
A buffer overflow vulnerability in the Totolink A3002MU router allows remote attackers to cause a denial of service via a crafted webpage parameter in the formSchedule function.
IBM Guardium Data Protection 12.2 contains an authentication bypass vulnerability allowing unauthenticated attackers to circumvent IP access controls and gain unauthorized management interface access.
IBM Guardium Data Protection 12.2 contains a deserialization vulnerability that allows remote, unauthenticated attackers to execute arbitrary code on the affected system.
The vm2 library contains a sandbox escape vulnerability in its Promise handling, allowing unauthenticated attackers to achieve remote code execution on the host system.
A command injection vulnerability exists in the Totolink A3002MU router, specifically within the formWsc function, allowing remote attackers to execute arbitrary system commands via the localPin parameter.
IBM Guardium Data Protection 12.2 is vulnerable to a security bypass due to missing authentication in the ChangeTrackerServlet, allowing unauthenticated remote access.
IBM Guardium Data Protection 12.2 contains an SQL injection vulnerability that allows an authenticated attacker to execute arbitrary SQL commands.
A heap-based buffer overflow in the FluidSynth command handler allows unauthenticated remote attackers to trigger denial of service or remote code execution via a crafted pitch_bend_range command.
IBM Guardium Data Protection 12.2 is vulnerable to SQL injection, potentially allowing remote, unauthenticated attackers to execute arbitrary SQL commands.
IBM Guardium Data Protection 12.2 contains an insecure deserialization vulnerability in the CAS listener that allows unauthenticated remote code execution via crafted TCP messages.
IBM Common Licensing is vulnerable to a cross-site request forgery (CSRF) flaw, potentially allowing unauthorized actions to be performed by a trusted user.
The vm2 NodeVM sandbox fails to restrict the child_process module, allowing unauthenticated attackers to execute arbitrary system commands on the host.
IBM Guardium Data Protection 12.2 contains a missing authentication vulnerability in the LoadBalancerServlet, allowing unauthenticated access to privileged operations.
IBM Guardium Data Protection 12.2 contains an authenticated OS command injection vulnerability within the exportCertificate functionality.
Disclosed Sep 16 without a CVSS score; scored Sep 17, analysis completed Sep 17.
A use-after-free vulnerability in the Linux kernel ksmbd module allows unauthenticated remote attackers to cause memory corruption via a race condition during smb2_tree_connect operations.
ArnasDon wacrm is vulnerable to authorization bypass due to flawed row-level security and insecure SECURITY DEFINER functions, allowing authenticated users to access or modify data across tenants.
The The Welcomizer plugin for WordPress allows authenticated attackers with subscriber-level access to execute arbitrary PHP code via an insecure AJAX handler.
The Save as PDF Plugin by PDFCrowd for WordPress is vulnerable to arbitrary function invocation via the pdf_created_callback shortcode attribute, allowing authenticated users to execute PHP code.
Disclosed Sep 12 without a CVSS score; scored Sep 13, analysis completed Sep 13.
The Gpx2Graphics WordPress plugin is vulnerable to CSRF and unrestricted file uploads, potentially allowing an authenticated administrator to be tricked into executing arbitrary code.
Mongoid fails to sanitize string-typed query criteria, allowing unauthenticated attackers to inject server-side JavaScript expressions into the database engine.
A SQL injection vulnerability in pg_partman allows authenticated users with partman_user privileges to achieve database-wide compromise and potential operating-system command execution.
A SQL injection vulnerability in the pg_partman PostgreSQL extension allows authenticated users to achieve database-wide compromise and remote code execution via malicious table names.
ClipBucket v5 allows authenticated users to achieve remote code execution by uploading malicious PHP files via the photo upload endpoint due to improper file extension handling.
A buffer overflow vulnerability in the PDFium component of Google Chrome on Windows allows remote attackers to execute arbitrary code via a specially crafted PDF file.
A use after free vulnerability exists in the PDFium component of Google Chrome, allowing a remote attacker to execute arbitrary code via a crafted HTML page.
IBM Platform RTM is vulnerable to SQL injection, allowing a remote unauthenticated attacker to manipulate backend database contents via crafted SQL statements.
Acode for Android contains an improperly exported service, allowing local applications to execute arbitrary commands with the privileges of the Acode application.
SiYuan versions 3.8.4 and earlier contain a stored cross-site scripting vulnerability in the Daily Note picker, allowing attackers to execute arbitrary code via malicious notebook names.
A type confusion vulnerability in the V8 JavaScript engine of Google Chrome allows a remote attacker to execute arbitrary code via a crafted HTML page.
A use-after-free vulnerability in the Linux kernel HID core allows local attackers to potentially execute arbitrary code or cause system crashes through improper input delivery during driver probing.
Google protobuf-javascript contains an uncontrolled recursion flaw when parsing unknown protobuf group fields, allowing unauthenticated attackers to cause a denial of service.
The vm2 sandbox library fails to handle rejected Promises originating from the host, allowing sandboxed code to cause a denial of service by terminating the host process.
A set of WordPress plugins from WP Cloud Plugins is vulnerable to arbitrary file upload, which can lead to remote code execution due to improper validation of uploaded file extensions and contents.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
A buffer overflow vulnerability in macOS allows attackers to cause system termination or kernel memory corruption via a maliciously crafted disk image.
IBM Guardium Data Protection 12.2 contains hardcoded credentials in the hardware_assess and obstore binaries, allowing authenticated users to extract master secrets and access internal databases.
A logic error in the Linux kernel mt76 WiFi driver causes improper handling of channel contexts during rapid channel switching, potentially leading to memory corruption or system instability.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 16, analysis completed Sep 16.
A use-after-free vulnerability in Apple operating systems allows kernel memory corruption when a user connects to a malicious NFS server.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 16, analysis completed Sep 16.
An integer overflow vulnerability in multiple Apple platforms allows for memory corruption when processing maliciously crafted web content.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
A memory corruption vulnerability in macOS allows unauthenticated attackers to achieve remote code execution by enticing a user to connect to a malicious WebDAV server.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 17.
A logic error in the Android kernel function enable_segment allows for a local privilege escalation. This vulnerability does not require user interaction or additional execution privileges.
Stacklok ToolHive containers lack network isolation and permit unauthenticated access to sensitive endpoints, allowing compromised MCP servers to interact with host services and the control plane.
The wp shortcut link and advertisement baner plugin is vulnerable to unauthenticated SQL injection via an AJAX action, potentially allowing attackers to extract sensitive database information.
The Price Drop Alert for Woo Commerce WordPress plugin is vulnerable to unauthenticated SQL injection via an AJAX action, allowing remote attackers to extract sensitive database information.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 16, analysis completed Sep 16.
A use-after-free vulnerability in Apple iOS, iPadOS, and macOS allows a local application to corrupt kernel memory or trigger unexpected system termination.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
A memory corruption vulnerability in Apple iOS, iPadOS, and macOS allows for potential application termination when processing maliciously crafted files.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
A path validation vulnerability in Apple macOS allows locally installed applications to gain unauthorized elevated privileges on the host system.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
An out-of-bounds write vulnerability in various Apple operating systems allows for application termination or potential code execution when processing a maliciously crafted video file.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 16, analysis completed Sep 16.
A privacy vulnerability allows unauthorized applications to track and identify users across reinstalls due to improper handling of identifiers in various Apple operating systems.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 16, analysis completed Sep 16.
A local application may be able to read a persistent account identifier due to an information disclosure flaw involving improper state management.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 16, analysis completed Sep 16.
A privacy vulnerability allows unauthorized cross-app and cross-site user tracking due to improper state management.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 16, analysis completed Sep 16.
A memory corruption vulnerability in Apple operating systems allows local attackers to achieve arbitrary code execution by processing a malicious image file.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 16, analysis completed Sep 16.
An out-of-bounds access vulnerability in multiple Apple operating systems allows a local application to cause system termination or kernel memory corruption.
The NUUO Network Video Recorder 2.0.0 is vulnerable to command injection via the handle_import_privilege.php file, potentially allowing unauthorized command execution on the host system.
The Easy Form Builder WordPress plugin before 4.2.0 contains a Stored Cross-Site Scripting (XSS) vulnerability allowing unauthenticated users to inject malicious scripts into administrative pages.
The VikBooking Hotel Booking Engine & PMS plugin allows unauthenticated users to upload malicious files via live chat, leading to stored Cross-Site Scripting (XSS) when viewed by an administrator.
The iGMS Direct Booking WordPress plugin before 2.0 lacks authorization and input sanitization, allowing unauthenticated attackers to perform stored Cross-Site Scripting (XSS) attacks.
A heap-based buffer overflow in IBM MQ for HPE NonStop allows authenticated users to trigger a denial of service or execute arbitrary code through improper validation of message distribution lists.
A memory management flaw in the Linux kernel Bluetooth subsystem allows for potential memory corruption or system instability through improper handling of SCO setup context lifetimes.
A SQL injection vulnerability in the undo_partition function of the pg_partman PostgreSQL extension allows authenticated users to execute arbitrary SQL commands with the privileges of the caller.
Disclosed Sep 12 without a CVSS score; scored Sep 13, analysis completed Sep 17.
The Temporary Login Without Password WordPress plugin before 1.9.9 fails to perform capability checks, allowing standard administrators to escalate themselves to network super admin.
Disclosed Sep 12 without a CVSS score; scored Sep 15, analysis completed Sep 19.
An authorization bypass in the Amelia WordPress plugin allows users with management permissions to modify account credentials of other users, leading to full account takeover.
Disclosed Sep 12 without a CVSS score; scored Sep 13, analysis completed Sep 13.
The Export & Import WPBakery Page Builder plugin is vulnerable to CSRF and Stored XSS, allowing attackers to execute malicious scripts in an administrator's session via a forged request.
Authenticated users of SysReptor Professional can achieve remote code execution by uploading malicious image files that exploit Ghostscript and a race condition to inject Python code.
A buffer overflow in the Moxa TN-4500B series web authentication process allows unauthenticated remote attackers to cause a denial of service via overly long username inputs.
A command injection vulnerability in btrbk's ssh_filter_btrbk.sh script allows authenticated users to execute arbitrary commands by bypassing the command allowlist via trailing pipe characters.
IBM Guardium Data Protection 12.2 contains a vulnerability allowing remote authenticated attackers to execute arbitrary code via improper input neutralization during web page generation.
IBM Guardium Data Protection 12.2 contains a vulnerability involving improper input neutralization that could allow an authenticated remote attacker to execute arbitrary code.
IBM Guardium Data Protection 12.2 is vulnerable to arbitrary code execution due to improper neutralization of input during web page generation, facilitating cross-site scripting attacks.
IBM Guardium Data Protection 12.2 is susceptible to a cross-site request forgery (CSRF) vulnerability, potentially allowing a remote attacker to bypass security restrictions.
IBM Guardium Data Protection 12.2 contains a missing authorization vulnerability in its REST API that allows a remote authenticated attacker to gain elevated privileges.
IBM Guardium Data Protection version 12.2 is vulnerable to OS command injection, which could allow a remote authenticated attacker to execute arbitrary commands on the system.
PLANET IGS-5225-8P2T4S switches contain an OS command injection vulnerability in the web server, allowing authenticated attackers to execute arbitrary system commands and escalate privileges to root.
A race condition in the Linux kernel mt7996 wifi driver allows for potential memory corruption due to improper mutex locking during SER operations.
A race condition in the Linux kernel mt76 wifi driver during RXDMAD_C buffer recycling allows for potential memory corruption or system instability.
A use-after-free vulnerability in the Linux kernel mt76 wifi driver allows for potential memory corruption due to a race condition during station removal.
A flaw in the Linux kernel dmaengine dw-edma driver allows for potential use-after-free conditions and memory leaks due to improper termination of DMA descriptors without correct callback handling.
Concrete CMS Community Store before 2.7.8 fails to sanitize customer-supplied order fields, enabling stored Cross-site Scripting (XSS) attacks that execute in authenticated manager sessions.
IBM Guardium Data Protection version 12.2 is susceptible to a SQL injection vulnerability within the New Query Builder REST processor, allowing low-privileged users to execute arbitrary SQL commands.
IBM Guardium Data Protection 12.2 contains a SQL injection vulnerability in the Analytic Grid Service Handler, allowing authenticated users to execute arbitrary SQL commands.
IBM MQ is vulnerable to a stack buffer overflow when processing XA transaction identifiers, which may allow an authenticated attacker to trigger a denial of service or execute arbitrary code.
IBM MQ contains a heap-based buffer overflow vulnerability in the MQPUT operation that allows authenticated attackers to cause a denial of service or escalate privileges.
Disclosed Sep 14; published with a limited analysis after repeated re-checks found no further public detail.
A cross-site scripting (XSS) vulnerability exists in the bodyclass component of Paessler PRTG Network Monitor, allowing for potential script injection.
IBM Guardium Data Protection 12.2 contains a SQL injection vulnerability in the Load Balancer Groups component, allowing unauthenticated attackers to execute arbitrary SQL commands.
LMDeploy versions 0.12.1 through 0.12.2 contain a code injection vulnerability via an unvalidated quantization_config parameter, allowing arbitrary Python code execution when loading malicious models.
SiYuan versions through 3.8.4 are vulnerable to stored cross-site scripting via unescaped heading style attributes in the outline and bookmark dock, allowing malicious script execution.
IBM MQ contains an integer overflow vulnerability in MQINQ request processing, which may allow an authenticated attacker to trigger a denial of service or execute arbitrary code.
IBM MQ contains an integer overflow vulnerability in distribution list processing that may allow an authenticated attacker to execute arbitrary code or cause a denial of service.
IBM Cloud Pak for Data 5.1.2 is vulnerable to OS command injection, allowing an authenticated user to execute arbitrary commands with elevated privileges.
An authenticated, low-privileged user can exploit an argument injection vulnerability in the NetBackup Flex OS management shell to execute arbitrary code with root-level privileges.
A cryptographic signature bypass in the Cohesity NetBackup Flex OS management shell allows authenticated, low-privileged users to execute privileged commands and gain root access to the appliance.
The TECHIN2B Application is affected by an authorization bypass vulnerability involving a user-controlled key, allowing authenticated users to escalate privileges.
A use-after-free and double-free vulnerability exists in the Linux kernel ksmbd implementation due to improper locking request handling during batch operations.
A flaw in the Linux kernel IOMMU driver fails to properly invalidate context caches for DMA aliases, potentially leading to unauthorized memory access via use-after-free conditions.
A use-after-free vulnerability in the Linux kernel Bluetooth L2CAP subsystem allows unauthenticated adjacent attackers to trigger memory corruption and potential code execution.
A logic error in the Linux kernel amdgpu driver for GFX6 hardware allows for improper pipeline synchronization, potentially leading to privilege escalation or system instability.
A use-after-free vulnerability in the Linux kernel HID subsystem allows unauthenticated local or adjacent attackers to potentially trigger memory corruption or system crashes.
A memory corruption vulnerability exists in the mt76 wifi driver of the Linux kernel due to improper handling of TWT flow agreements when rejected by the firmware.
A PCIe AER handler flaw in the Linux kernel mt76 driver causes memory corruption and system crashes when bus errors occur, potentially allowing for system-wide instability.
A memory management flaw in the Linux kernel tegra241-cmdqv driver allows out of bounds memory access due to improper validation of Stream IDs for vSIDs.
Disclosed Sep 14; published with a limited analysis after repeated re-checks found no further public detail.
An improper authentication vulnerability in the getzep graphiti REST API allows remote attackers to bypass security controls via the server/graph_service/main.py component.
The pure-Perl implementation of Mojo::JSON in Mojolicious fails to limit nesting depth, allowing unauthenticated attackers to cause memory exhaustion and process crashes via deeply nested JSON input.
NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand receive path due to improper Security Association validation.
A stored cross-site scripting (XSS) vulnerability exists in SemanticMediaWiki due to improper sanitization of data attributes, allowing arbitrary HTML injection via wikitext.
The vm2 CLI tool contains a sandbox escape vulnerability that allows unauthenticated attackers to execute arbitrary code on the host system.
SGLang versions up to 0.5.19 contain an unauthenticated PUT endpoint that allows attackers to poison the KV transfer routing table, leading to potential denial of service or data disclosure.
Icinga 2 is vulnerable to stack exhaustion via uncontrolled recursion when parsing deeply nested JSON, allowing unauthenticated remote attackers to crash the service on TCP port 5665.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 17.
A privilege escalation vulnerability in Webkul Bagisto 2.4.9 allows an authenticated backend user to elevate their account to full administrator via the user-update endpoint.