CVE-2026-76461
A critical SQL injection vulnerability in Cisco Secure Email Gateway allows unauthenticated remote attackers to execute arbitrary commands with root privileges via crafted email messages.
Critical vulnerabilities, curated daily for security professionals
Oracle and Apache enterprise platforms account for the highest-impact disclosures, with remote code execution and authentication bypass flaws in WebLogic Server, Internet Directory, Identity Manager, MyFaces, and the Airflow FAB provider. The day's total of 22 critical CVEs is down 29 percent from the prior day's 31, while 73 high-priority CVEs represent a 20 percent decrease from 91. CVE-2026-83057 and CVE-2026-83058 (both CVSS 9.9) affect Oracle Internet Directory, CVE-2026-70756 (CVSS 9.8) affects Oracle WebLogic Server, and CVE-2026-68536 (CVSS 9.8) affects Apache MyFaces. Identity and directory services are the concentration point, alongside WordPress plugin flaws in Botiga Pro and WP Recipe Maker and an Apple platform issue spanning iOS, iPadOS, macOS, visionOS, and watchOS; seven CVEs carry confirmed active exploitation, including Cisco Secure Email Gateway and Cisco Identity Services Engine. Prioritize internet-facing Oracle middleware and Cisco security appliances, restrict administrative interfaces to trusted networks, and confirm fix status for each affected product in the vendor's advisory.
Immediate action: Oracle middleware (WebLogic Server, Internet Directory, Identity Manager) and Cisco security appliances (Secure Email Gateway, Identity Services Engine) need immediate attention, followed by Apache MyFaces and Airflow deployments and Apple endpoints. Review each vendor's security advisory to confirm the fix status and affected version ranges for your specific deployment before scheduling maintenance windows.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A critical SQL injection vulnerability in Cisco Secure Email Gateway allows unauthenticated remote attackers to execute arbitrary commands with root privileges via crafted email messages.
A logic error in the Google Pixel cellular modem component allows for unauthenticated, adjacent privilege escalation without user interaction.
An authentication bypass vulnerability in the Cisco Identity Services Engine API allows unauthenticated, remote attackers to gain unauthorized access to the management interface.
Acronis Backup plugins for cPanel and Plesk contain an insecure file permissions vulnerability that allows authenticated users to perform local privilege escalation.
A race condition in the Linux kernel crypto subsystem allows local users to cause state inconsistencies via concurrent writes to an af_alg socket.
A memory corruption vulnerability in the Linux kernel netfilter bridge component allows for out of bounds writes during ARP packet processing.
A vulnerability in the Linux kernel TLS implementation allows for improper handling of zero-length records during recvmsg processing, potentially leading to unauthorized system state manipulation.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 18, analysis completed Sep 18.
Apache MyFaces Core is vulnerable to Server-Side Request Forgery and Local File Inclusion, which could allow an unauthenticated attacker to compromise system integrity.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 18, analysis completed Sep 18.
A session invalidation flaw in the Apache Airflow FAB provider prevents existing sessions from being cleared after a password reset, allowing attackers to maintain unauthorized access.
Disclosed Sep 15; held until the analysis firmed up on Sep 20.
A critical vulnerability in Oracle WebLogic Server allows unauthenticated remote attackers to achieve full system takeover via T3 or IIOP protocols.
OpenPanel js-runtime contains a sandbox escape vulnerability in the JavaScript webhook template validator, allowing authenticated attackers to execute arbitrary code.
Disclosed Sep 15; held until the analysis firmed up on Sep 20.
A critical, easily exploitable vulnerability in the Oracle Internet Directory LDAP server allows low-privileged attackers to achieve complete system takeover.
Disclosed Sep 15; held until the analysis firmed up on Sep 20.
A critical access control vulnerability in the Oracle Internet Directory LDAP server allows authenticated attackers to achieve a full system takeover.
Disclosed Sep 15; held until the analysis firmed up on Sep 20.
A critical vulnerability in Oracle Identity Manager allows unauthenticated attackers to achieve full system takeover via network-based HTTP requests.
The Botiga Pro WordPress plugin lacks authorization checks on REST API routes, enabling unauthenticated attackers to modify site settings, inject malicious scripts, and perform privilege escalation.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 18, analysis completed Sep 18.
A permissions vulnerability in multiple Apple operating systems allows an unauthenticated application to perform unauthorized user fingerprinting due to insufficient sandbox restrictions.
The WP Recipe Maker plugin for WordPress is vulnerable to arbitrary shortcode execution due to improper sanitization of recipe metadata, allowing unauthenticated attackers to disclose sensitive data.
The Forminator Forms WordPress plugin is vulnerable to unauthenticated arbitrary shortcode execution due to improper validation of input before calling the do_shortcode function.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 18, analysis completed Sep 18.
The Apache Airflow Keycloak provider lacks proper client validation, allowing unauthenticated attackers to use credentials from any confidential client in the realm to authenticate to Airflow.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 18, analysis completed Sep 18.
The Apache Airflow Keycloak provider fails to validate the association between session tokens and Keycloak access tokens, allowing attackers to impersonate other users' privileges.
A remote OS command injection vulnerability exists in the D-Link R95 router due to improper input validation of the NTPServer argument within the DHMAPI component.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 18, analysis completed Sep 18.
A buffer overflow vulnerability in IBM Verify Identity Access allows unauthenticated attackers to execute arbitrary code or cause a system crash.
A type confusion vulnerability in Suricata's DoH2 implementation allows unauthenticated attackers to trigger an invalid memory free, potentially leading to remote code execution.
Suricata versions prior to 8.0.7 are vulnerable to a use-after-free condition in the Http2ThreadMultiBuf component during specific HTTP response header inspection scenarios.
The DBI module for Perl incorrectly handles DBM connect attributes, allowing unauthenticated attackers to execute arbitrary code via unsafe module loading.
Disclosed Sep 16 without a CVSS score; scored Sep 18, analysis completed Sep 18.
A memory safety vulnerability exists in the Linux kernel xfrm6_input_addr function, where an off by one error allows an out of bounds write to the security path structure.
Disclosed Sep 16 without a CVSS score; scored Sep 18, analysis completed Sep 18.
A heap-based out-of-bounds read vulnerability exists in the Linux kernel NTFS3 filesystem driver, allowing local attackers to leak sensitive kernel memory via crafted Extended Attribute records.
Disclosed Sep 16 without a CVSS score; scored Sep 18, analysis completed Sep 18.
The Linux kernel ext4 filesystem contains an out-of-bounds read vulnerability in the ext4_read_inline_dir function, which can be triggered during directory iteration.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 18, analysis completed Sep 18.
The TOTOLINK X5000R router contains a hardcoded password for root access, allowing unauthenticated attackers to gain full control over the device.
A SQL injection vulnerability in the pg_partman extension allows authenticated users to achieve database-wide compromise and remote code execution as the PostgreSQL service account.
Mongoid fails to sanitize caller-supplied filter data, allowing unauthenticated attackers to influence query operations and potentially disclose sensitive database field values.
SiYuan before 3.8.3 is vulnerable to SQL injection via the getGraph endpoint, allowing unauthorized database queries and potential data exfiltration by unauthenticated or low-privileged users.
The legacy DOC renderer in flyfish-dev file-viewer fails to restrict URL schemes in hyperlinks, allowing unauthenticated attackers to execute arbitrary scripts in the application origin via crafted files.
The MgoSync WordPress plugin contains an unauthenticated information exposure vulnerability in its REST API, allowing attackers to exfiltrate sensitive WooCommerce API credentials.
A use after free vulnerability in Microsoft Edge (Chromium-based) allows an unauthorized attacker to achieve local privilege escalation.
The Viosock driver in virtio-win is vulnerable to a heap-based buffer overflow via an integer overflow, allowing local low-privilege users to trigger kernel memory corruption and privilege escalation.
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution via the wppa_image_magick function due to insufficient sanitization of multipart upload filenames.
Cotonti versions through 1.0.0 use a cryptographically weak PRNG to generate password recovery tokens, allowing unauthenticated attackers to reset arbitrary user accounts.
The DigestAuthProvider component in http4k fails to validate the URI parameter in Digest authentication responses, allowing attackers to perform replay attacks and bypass authentication protections.
Disclosed Sep 16; held until the analysis firmed up on Sep 20.
An unauthenticated vulnerability in Oracle Hyperion Financial Management allows an attacker with local network access to achieve a full system takeover.
ArcadeDB versions before 26.9.1 contain an SSRF vulnerability where insufficient validation of IPv6 transition addresses allows authenticated attackers to access internal services and cloud metadata.
An improper authorization flaw in WACRM allows authenticated viewers to perform unauthorized write operations, such as creating or deleting flows and triggering automations, by bypassing role checks.
A missing authorization vulnerability in the Unbounce Landing Pages WordPress plugin allows authenticated users to manipulate proxy configurations and serve arbitrary content from the site origin.
Disclosed Sep 15; published with a limited analysis after repeated re-checks found no further public detail.
Ekia File Manager 1.2.7 exposes an improperly configured Android ContentProvider, allowing local applications to read, create, overwrite, or delete files accessible to the application process.
The VikRentItems WordPress plugin contains an unauthenticated SQL injection vulnerability due to improper sanitization of user-supplied parameters.
Disclosed Sep 15; published with a limited analysis after repeated re-checks found no further public detail.
The ThemeAtelier Domain For Sale plugin for WordPress contains a missing authorization flaw in its REST API, allowing unauthenticated attackers to access and manipulate sensitive business data.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
An out-of-bounds access vulnerability in multiple Apple operating systems allows a local application to trigger system termination or corrupt kernel memory.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
An out-of-bounds write vulnerability in macOS allows local attackers to cause kernel memory corruption by connecting to a malicious SMB server.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
A race condition vulnerability in multiple Apple operating systems allows a sandboxed application to execute arbitrary code with kernel privileges.
A heap-based buffer overflow in the IBM MQ C client for HPE NonStop allows remote attackers to trigger a denial of service or execute arbitrary code via malicious queue manager responses.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
A privacy vulnerability in Apple iOS and iPadOS allows an installed application to enumerate other applications installed on the user device.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
A path traversal vulnerability in Apple iOS and iPadOS allows an attacker with physical access to a trust-paired device to read and write arbitrary files on the system.
Disclosed Sep 14 without a CVSS score; tracked by CVE Brief from Sep 15; scored Sep 17, analysis completed Sep 17.
A memory corruption vulnerability exists in multiple Apple operating systems due to an integer overflow during the processing of maliciously crafted 3D models.
The Ultimate Member WordPress plugin fails to properly sanitize user-supplied profile names, leading to a stored Cross-Site Scripting (XSS) vulnerability that allows unauthenticated script execution.
The Master Blocks plugin for WordPress is vulnerable to Stored XSS via an unauthenticated REST API route, allowing attackers to inject malicious scripts into administrative pages.
Disclosed Sep 17; held until the analysis firmed up on Sep 20.
A vulnerability in the Core component of Oracle Identity Manager 12.2.1.4.0 and 14.1.2.1.0 allows low-privileged attackers to gain full system takeover via HTTP.
Disclosed Sep 17; held until the analysis firmed up on Sep 20.
A vulnerability in the OIM Legacy UI component of Oracle Identity Manager allows an authenticated attacker with low privileges to achieve a full system takeover via HTTP.
The ProfilePress WordPress plugin is vulnerable to arbitrary shortcode execution in versions up to 4.17.2, allowing authenticated users to inject and execute code via improper shortcode validation.
The UsersWP WordPress plugin fails to verify social login email ownership, allowing unauthenticated attackers to hijack accounts including administrator profiles.
A privilege escalation vulnerability in the pg_partman PostgreSQL extension allows authenticated users to move tables between schemas by exploiting improper authorization checks in background tasks.
The YS LeadGen plugin for WordPress is vulnerable to unauthenticated sensitive information exposure via the ysleadgen_get_captured_data AJAX action, allowing unauthorized access to user form submissions.
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 is vulnerable to an out-of-bounds read due to improper validation of message header offset values, potentially leading to information disclosure or a DoS.
An insecure direct object reference in the Mongoid object-document mapper allows authenticated users to access or modify data belonging to other users.
Mistral Vibe before 2.25.5 is vulnerable to remote code execution during worktree creation because it executes git hooks before validating repository trust.
A heap-based buffer overflow exists in the Kamailio CDP Diameter Receiver component due to insufficient validation of the Diameter message-length field, allowing remote unauthenticated code execution.
A heap-based out-of-bounds read vulnerability in the Suricata SMTP MIME quoted-printable decoder allows unauthenticated remote attackers to cause a denial of service via crafted traffic.
IBM MQ is vulnerable to a buffer overflow via malformed compressed data on configured channels, potentially allowing remote code execution or denial of service by unauthenticated attackers.
A vulnerability in Netty's HTTP/1 to HTTP/2 conversion allows remote unauthenticated attackers to perform request smuggling, potentially leading to unauthorized access or cache poisoning.
IBM Guardium Data Protection 12.2 is vulnerable to remote arbitrary code execution via improper neutralization of input during web page generation.
IBM Guardium Data Protection version 12.2 is susceptible to an improper authorization vulnerability that allows remote attackers to bypass security restrictions.
IBM Guardium Data Protection 12.2 contains a cross-site request forgery vulnerability that allows a remote attacker to bypass security restrictions.
IBM Guardium Data Protection 12.2 is susceptible to a security bypass vulnerability resulting from improper certificate validation, which may allow remote attackers to compromise system integrity.
IBM Guardium Data Protection 12.2 is vulnerable to remote OS command injection due to improper neutralization of special elements in commands.
IBM Guardium Data Protection 12.2 is vulnerable to OS command injection, which may allow a remote, unauthenticated attacker to execute arbitrary system commands.
An unauthenticated host header injection vulnerability in SysReptor allows attackers to hijack password reset tokens by manipulating the reset link's domain.
A flaw in the zot container registry authentication handler allows authenticated users to perform unauthorized deletions of manifests and blobs due to improper authorization checks for DELETE requests.
IBM Guardium Data Protection 12.2 is vulnerable to SQL injection, potentially allowing an authenticated remote attacker to access sensitive information.
IBM Guardium Data Protection 12.2 is vulnerable to SQL injection, allowing a remote authenticated attacker to retrieve sensitive information.
IBM Guardium Data Protection 12.2 contains an improper authorization vulnerability that allows a remote authenticated attacker to bypass security restrictions.
A path traversal vulnerability in IBM Guardium Data Protection version 12.2 allows a remote authenticated attacker to access unauthorized directories on the system.
Exim versions prior to 4.100.1 are vulnerable to an information disclosure flaw when using the Proxy-Protocol, potentially allowing attackers to read uninitialized stack memory.
IBM Guardium Data Protection 12.2 allows local privilege escalation via a SUID-root nmap_wrapper binary, enabling low-privileged users to execute arbitrary commands as root.
A flaw in the SmartLife app allows authenticated users to obtain account IDs and reset passwords by spoofing application authentication parameters during requests to the backend.
ArcadeDB before 26.9.1 contains an authorization flaw where TimeSeries types fail to enforce ACL entries, allowing authenticated users to bypass security rules and access unauthorized data.
ArcadeDB fails to enforce access control checks when querying data through LSM index files or the TimeSeries engine, allowing authenticated users to bypass read and delete restrictions.
A heap-based buffer overflow and out-of-bounds read vulnerability exists in FluidSynth due to improper validation of DLS file sample loop parameters.
A missing authorization vulnerability in Perses allows authenticated low-privilege users to exfiltrate sensitive project or global secrets by intercepting them via a user-controlled datasource proxy.
A heap-based buffer overflow in FluidSynth allows out-of-bounds memory access when the synth.midi-channels configuration is set above 16, potentially leading to system compromise.
IBM Guardium Data Protection 12.2 contains an improper privilege management vulnerability that permits a local attacker with low privileges to escalate their access to higher levels.
IBM Guardium Data Protection 12.2 contains an improper privilege management vulnerability that permits a local attacker to escalate privileges.
A heap-based buffer overflow in the rsyslog imhttp module allows an unauthenticated remote attacker to cause a process crash via an oversized HTTP Basic Authorization header.
Argo Workflows 4.1.0 through 4.1.3 contains an authorization bypass in ListArchivedWorkflows, allowing users to retrieve archived workflows from unauthorized namespaces via negated field selectors.
The mmpstrucdata plugin in rsyslog is susceptible to a stack-based buffer overflow, allowing a remote unauthenticated attacker to cause a crash via a crafted RFC5424 structured-data parameter.
A heap-based buffer overflow in OpenImageIO allows memory corruption when processing crafted 1-bit CMYK TIFF files, potentially leading to application crashes or arbitrary code execution.
Expat versions up to 2.8.4 fail to validate UTF-16 surrogates, allowing attackers to craft malformed input that hides markup characters and enables XML injection.
Disclosed Sep 16 without a CVSS score; scored Sep 17, analysis completed Sep 17.
The Linux kernel ksmbd implementation contains an out-of-bounds read vulnerability in share configuration responses due to improper validation of IPC share configuration payload sizes.
A heap out-of-bounds write vulnerability in OpenImageIO allows attackers to trigger memory corruption via a specially crafted Cineon image file.
Gopeed versions through 2.0.0-beta.3 contain a path traversal vulnerability in the archive extraction module that allows attackers to write arbitrary files outside the intended destination directory.
A path traversal vulnerability in LubeLogger allows authenticated users to move uploaded files outside the intended storage directory, potentially leading to unauthorized file placement or overwriting.
A heap out-of-bounds write vulnerability exists in OpenImageIO due to a buffer size mismatch during the processing of zbuffer-only tiled IFF image files, potentially leading to memory corruption.
A heap-based buffer overflow in OpenImageIO allows memory corruption when processing specifically crafted tiled OpenEXR image files.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 17, analysis completed Sep 17.
The C-MOR Video Surveillance web interface is susceptible to a path traversal vulnerability via the 'cam' parameter in show-movies.pml, allowing unauthorized file access.