CVE-2026-7273
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware allows potential remote command execution.
Critical vulnerabilities, curated daily for security professionals
The most significant disclosures from Friday affect widely deployed web platforms, including Zimbra Collaboration Suite, Apache Lounge Windows builds of Apache HTTP Server, and several WordPress and WooCommerce plugins. Critical CVEs rose 4% to 29 from 28 the prior day, while high-priority CVEs fell 21% to 59 from 75, for 88 in total. Notable critical entries include CVE-2026-93643 in Zimbra Collaboration Suite (CVSS 9.8), CVE-2026-18143 in Addify Request a Quote for WooCommerce (CVSS 9.8), and CVE-2026-89282 in Apache Lounge Windows (CVSS 9.1). Internet-facing web applications carry most of the risk, with two critical Piwigo flaws, a Zammad help desk issue, and plugin vulnerabilities across e-commerce and OAuth login components; 10 CVEs are also actively exploited, affecting network and security appliances from F5, Check Point, MikroTik, and Zyxel as well as Microsoft SharePoint. Defenders should inventory exposed Zimbra, Apache on Windows, and WordPress deployments, restrict administrative interfaces on perimeter devices, and confirm fix status in each vendor advisory.
Immediate action: Prioritize internet-facing Zimbra, Apache Lounge on Windows, Piwigo, and Zammad servers, along with WordPress sites running the affected WooCommerce and OAuth plugins, and move the actively exploited F5, Check Point, MikroTik, Zyxel, and SharePoint systems up the patch queue. Confirm fix status and the fixed versions in each vendor's advisory before scheduling changes. Where a fix cannot be applied right away, restrict management interfaces to trusted networks and disable the affected plugins.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware allows potential remote command execution.
VeloCloud Orchestrator (VCO) on-prem is vulnerable to improper input validation, allowing unauthenticated remote attackers to access privileged functionality and compromise the host.
A heap-based buffer overflow in F5 BIG-IP APM, when configured as an OAuth Authorization Server, allows unauthenticated attackers to achieve remote code execution via malicious traffic.
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on the Check Point Management Server.
An improper certificate trust validation vulnerability exists in Check Point Quantum Security Gateways during VPN negotiation, allowing unauthenticated remote code execution.
The WSO2 JWT authentication mechanism incorrectly validates tokens using unsupported algorithms, potentially allowing unauthenticated attackers to bypass security controls and gain unauthorized access.
Adobe Commerce and Magento Open Source are vulnerable to an improper authorization flaw that allows unauthenticated attackers to escalate privileges and access sensitive resources.
An improper workflow enforcement vulnerability in MikroTik RouterOS allows unauthenticated attackers to initiate SSH sessions and execute arbitrary commands, leading to full device control.
A code injection vulnerability in Microsoft SharePoint allows an authenticated attacker to execute arbitrary code over the network.
A remote file inclusion vulnerability in WordPress Core allows unauthenticated attackers to execute arbitrary code by manipulating the get_page_template() function to include unauthorized PHP files.
The Request a Quote for WooCommerce plugin is vulnerable to unauthenticated arbitrary file uploads, allowing remote code execution via the popup upload handler.
Disclosed Sep 23 without a CVSS score; scored Sep 24, analysis completed Sep 26.
The YAHMAN Add-ons WordPress plugin before 0.9.31 is vulnerable to code injection, allowing unauthenticated attackers to write arbitrary PHP files and achieve remote code execution.
An unauthenticated SQL injection vulnerability exists in Piwigo 17.0.0beta1 and earlier, allowing attackers to extract sensitive database information via the filtered search functionality.
Disclosed Sep 22 without a CVSS score; tracked by CVE Brief from Sep 23; scored Sep 24, analysis completed Sep 24.
The Apache Lounge Windows distribution of Apache HTTP Server features insecure default installation directory permissions, allowing authenticated users to modify critical files.
Zammad fails to verify email ownership during SSO account linking, allowing unauthenticated attackers to hijack any local account by matching email addresses.
An unauthenticated remote attacker can exploit unsigned save fields in the OnlyOffice document editing feature to perform path traversal and execute arbitrary commands as the zimbra user.
Piwigo versions prior to 16.4.0 are vulnerable to unrestricted file uploads, allowing an authenticated administrator to achieve arbitrary command execution via a malicious logo file.
Disclosed Sep 23 without a CVSS score; scored Sep 24, analysis completed Sep 26.
A critical authentication bypass in the WP OAuth Server plugin allows authenticated users to impersonate others, including administrators, by misbinding OpenID Connect identity assertions.
X-SpringBoot versions 6.0 and earlier contain a hardcoded master authentication code, allowing unauthenticated attackers to bypass login and perform account takeover.
The Customer Reviews for WooCommerce plugin is vulnerable to authorization bypass, allowing unauthenticated attackers to permanently delete arbitrary files from the WordPress Media Library.
A session fixation vulnerability in the Apache Qpid Broker-J HTTP management interface allows unauthenticated remote attackers to hijack authenticated sessions.
Disclosed Sep 22 without a CVSS score; tracked by CVE Brief from Sep 23; scored Sep 24, analysis completed Sep 24.
pH7Builder improperly validates IP headers, allowing unauthenticated remote attackers to bypass IP-based brute force protection by spoofing the X-Forwarded-For header.
The FriendsOfFlarum OAuth plugin fails to verify Discord email addresses, allowing unauthenticated attackers to hijack user accounts, including administrative accounts, via account linking.
A vulnerability in InvoicePlane allows an administrator to upload malicious PHP files to the template directory, which are then executed by the system during public invoice rendering.
The Bookly WordPress plugin is vulnerable to an Insecure Direct Object Reference (IDOR) allowing unauthenticated attackers to access, enumerate, and delete customer appointment records.
A command injection vulnerability in the kitty terminal emulator's colour control escape code handler allows attackers to execute arbitrary commands by reflecting unneutralized input into the shell.
A path traversal vulnerability in GLPI allows an authenticated form administrator to write files to arbitrary server locations, potentially leading to remote code execution.
An OS command injection vulnerability exists in the Mediawiki ExternalData extension, allowing unauthenticated remote attackers to execute arbitrary system commands.
A memory management flaw exists in the Linux kernel RDMA/srpt component where failure in context allocation results in stale counters, potentially leading to incorrect send queue accounting.
Disclosed Sep 21 without a CVSS score; tracked by CVE Brief from Sep 22; scored Sep 23, analysis completed Sep 26.
Univer v1.0.0-alpha.2 is vulnerable to unauthenticated remote code execution via the UniscriptExecutionService.execute() function.
Disclosed Sep 21 without a CVSS score; tracked by CVE Brief from Sep 22; scored Sep 25, analysis completed Sep 25.
An incorrect access control vulnerability in the ZLMediaKit HTTP API allows unauthenticated remote attackers to achieve remote code execution via the setServerConfig endpoint.
Disclosed Sep 21 without a CVSS score; tracked by CVE Brief from Sep 22; scored Sep 25, analysis completed Sep 25.
A remote code execution vulnerability exists in the RemoteRegisterFunctionService function of Univer v1.0.0-alpha.2, allowing unauthenticated attackers to execute arbitrary code via a crafted payload.
A stored cross-site scripting vulnerability in Zimbra Collaboration Suite allows unauthenticated attackers to compromise mailbox data and impersonate users via forged share notifications.
A stored cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite allows unauthenticated attackers to execute malicious scripts via crafted calendar COUNTER messages.
An unauthenticated sender can trigger stored XSS in Zimbra Collaboration Suite (ZCS) via a forged share notification, leading to unauthorized access to recipient mailbox data.
X-SpringBoot exposes login verification codes in HTTP responses, allowing unauthenticated attackers to hijack user accounts via mobile or email login endpoints.
Disclosed Sep 23 without a CVSS score; tracked by CVE Brief from Sep 24; scored Sep 25, analysis completed Sep 25.
A critical out-of-bounds read vulnerability in Claris FileMaker Server for Linux allows unauthenticated attackers to disclose process memory via crafted image files in FileMaker WebDirect.
Disclosed Sep 23 without a CVSS score; tracked by CVE Brief from Sep 24; scored Sep 25, analysis completed Sep 25.
An authorization bypass in the FileMaker Server Web Publishing Engine permits unauthenticated access to the XML Web Publishing interface by manipulating extended privilege headers.
Lemonldap::NG::Portal fails to verify client secrets for public OAuth2 Relying Parties, allowing unauthenticated attackers to introspect tokens and deanonymize user identifiers.
OpenClaw for iOS fails to enforce TLS certificate pinning in specific WebViews, allowing attackers to intercept credentials and gain unauthorized operator access to Gateway systems.
OpenClaw is vulnerable to a DNS rebinding attack in the Chrome DevTools Protocol (CDP) transport, allowing unauthenticated attackers to bypass SSRF protections and access restricted network resources.
Disclosed Sep 24 without a CVSS score; scored Sep 25, analysis completed Sep 25.
The wpForo Forum WordPress plugin before 3.1.6 is vulnerable to insecure deserialization, which could allow authenticated users to inject PHP objects and potentially achieve remote code execution.
Disclosed Sep 24 without a CVSS score; scored Sep 25, analysis completed Sep 25.
The MasterStudy LMS WordPress Plugin fails to validate display-style settings, allowing authenticated users with Contributor roles or higher to execute arbitrary local PHP files via path traversal.
OpenClaw contains an OS command injection vulnerability in the Google Meet node command, allowing authenticated attackers to execute arbitrary processes on paired nodes.
Laranode contains a path traversal vulnerability in the file upload endpoint that allows authenticated users to write arbitrary files outside their home directory and achieve remote code execution.
Horilla HR and CRM software versions prior to 2.0.0 are vulnerable to code injection via the export_data function, allowing authenticated users to execute arbitrary operating-system commands.
A vulnerability in the Google gVisor gofer component allows a local attacker with image deployment privileges to achieve root code execution on the host system via CUSE ioctl handling.
Disclosed Sep 23 without a CVSS score; tracked by CVE Brief from Sep 24; scored Sep 25, analysis completed Sep 25.
A heap buffer overflow in the FileMaker Server database engine allows memory corruption via a crafted .fmp12 file, potentially enabling arbitrary code execution.
AIL Framework is vulnerable to stored cross-site scripting (XSS) via unsanitized usernames in the timeline feature, allowing remote attackers to execute arbitrary JavaScript in an analyst's session.
A stored cross-site scripting (XSS) vulnerability in the AIL Framework allows authenticated attackers to inject malicious scripts into popover elements, leading to potential session compromise.
A stored cross-site scripting vulnerability in Zammad allows authenticated users to inject malicious HTML and JavaScript into ticket titles, which execute when viewed by other users.
RabbitMQ improperly exposes the OAuth2 client secret via an unauthenticated JavaScript endpoint, potentially allowing unauthorized actors to perform token theft and client impersonation.
Disclosed Sep 23 without a CVSS score; scored Sep 24, analysis completed Sep 24.
The WC Fields Factory WordPress plugin suffers from a missing authorization vulnerability allowing authenticated users to modify arbitrary post meta and manipulate product pricing.
Disclosed Sep 22 without a CVSS score; tracked by CVE Brief from Sep 23; scored Sep 24, analysis completed Sep 24.
A local cross-user code execution vulnerability exists in specific Windows builds of GNU Wget due to an insecurely writable hardcoded configuration path.
Disclosed Sep 23 without a CVSS score; tracked by CVE Brief from Sep 24; scored Sep 25, analysis completed Sep 25.
A DLL hijacking vulnerability in the Claris FileMaker Pro installer for Windows allows a local user to achieve arbitrary code execution with elevated privileges.
A stored cross-site scripting vulnerability in the Horilla HR search parameter allows unauthenticated attackers to execute malicious JavaScript in the context of an authenticated user's session.
The CliInvoke.Specializations library is vulnerable to OS command injection via improper quoting in PowerShell and Cmd wrappers, allowing arbitrary command execution with host process privileges.
Zammad session management is susceptible to a path traversal attack allowing authenticated users to delete arbitrary files on the server when using the default file-based session store.
Disclosed Sep 23 without a CVSS score; scored Sep 24, analysis completed Sep 26.
The divi-dash WordPress plugin before 1.0.7 fails to validate client IP addresses, allowing unauthenticated attackers to spoof IPs, bypass rate limits, and cause resource exhaustion.
Disclosed Sep 23 without a CVSS score; scored Sep 24, analysis completed Sep 24.
The WP Recipe Maker plugin lacks authorization checks on a REST route, allowing unauthenticated attackers to corrupt user metadata and cause denial of service for any account, including administrators.
Dell ThinOS 10 contains an improper certificate validation vulnerability that allows unauthenticated adjacent attackers to bypass protection mechanisms and gain unauthorized access.
Disclosed Sep 21 without a CVSS score; tracked by CVE Brief from Sep 22; scored Sep 23, analysis completed Sep 26.
idccms V1.70 contains a cross-site scripting (XSS) vulnerability in the /admin/makeDiy_deal.php script, which may allow attackers to execute malicious scripts in a user's browser.
OpenClaw Codex before 2026.7.1 fails to enforce owner authorization for native conversation bindings, allowing authenticated users to execute host-capable commands.
A vulnerability in the golang.org/x/playground component allows unauthenticated remote attackers to achieve arbitrary file writes and potential remote code execution on the host system.
A missing authorization flaw in the OpenClaw voice-call package allows remote callers to invoke agent tools intended only for the trusted owner.
OpenClaw before 2026.7.1 contains a vulnerability in the model-facing cron tool that allows for improper case sensitivity handling, leading to potential command execution.
A use-after-free race condition in QEMU's 9pfs subsystem allows a malicious guest user to escape the VM boundary and execute code on the host.
An unauthenticated denial of service vulnerability exists in Zammad via the OTRS import endpoint, where missing authentication checks allow attackers to exhaust server resources.
A missing authorization flaw in the Akia keyless entry service allows authenticated guests to unlock doors for which they do not have authorization by manipulating room identifiers.
OpenClaw fails to enforce administrator scope requirements on browser control via the node.invoke method, allowing authenticated users with write-scope to interact with browser applications.
MediaFlow Proxy versions 2.4.9 and earlier are vulnerable to server-side request forgery (SSRF) in the /proxy endpoint, allowing unauthenticated attackers to query internal network resources.
The Linux kernel hinic network driver contains a heap buffer overflow vulnerability in the mailbox segment validation logic, potentially allowing local privilege escalation.
OpenClaw fails to enforce per-chat tool policies, allowing authenticated users to bypass allowlists and access restricted native command and file tools via the Codex app-server runtime.
OpenClaw Slack versions before 2026.8.1 fail to enforce sender allowlists in group messages, allowing unauthorized participants to access Slack agent tools and data.
OpenClaw versions before 2026.7.1 contain an authorization bypass vulnerability allowing non-owner channel senders to install malicious plugins and execute processes with application privileges.
OpenClaw versions before 2026.7.1 contain a missing authorization vulnerability allowing authenticated users to persist arbitrary MCP commands, leading to full process privilege execution.
IBM Guardium Data Protection 12.2 contains a command injection vulnerability in the GIM bundle import feature, allowing authenticated attackers to execute arbitrary commands with elevated privileges.
A flaw in the Linux kernel ksmbd implementation fails to safely drain sessions during logoff, potentially allowing improper handling of SMB3 multichannel requests.
A race condition in the Linux kernel qla2xxx driver allows for potential list corruption due to improper locking of the NVMe unsolicited context list during concurrent operations.
A use-after-free vulnerability in the Linux kernel SCSI qla2xxx driver allows for potential memory corruption or system panics due to improper list management during error handling.
A heap-based buffer overflow exists in the Linux kernel SMB client when rewriting DACLs, potentially allowing for memory corruption during SID expansion.
Disclosed Sep 22 without a CVSS score; tracked by CVE Brief from Sep 23; scored Sep 24, analysis completed Sep 24.
A horizontal privilege escalation vulnerability in x-ui 0.3.2 allows authenticated users to modify the inbound proxy configurations of other users by manipulating resource identifiers.
A privilege management flaw in Zammad allows authenticated users with restricted tokens to bypass authorization checks and create new administrator accounts, leading to full system compromise.
A security filter bypass in Zammad's AI Agent configuration allows authenticated administrators to execute arbitrary commands on the host server.
Disclosed Sep 21 without a CVSS score; scored Sep 24, analysis completed Sep 22.
A stack-based buffer overflow in fetchmail's NTLM authentication allows a malicious mail server to potentially trigger remote code execution via a crafted Type 2 challenge.
An authenticated path traversal vulnerability in GLPI allows logged-in users to delete arbitrary files on the server via the profile-picture update flow.
An authenticated technician can inject stored cross-site scripting (XSS) payloads into supplier website fields in GLPI, which execute when other users view the supplier list.
The Rattadan Cosmowarp smart contract contains a logic flaw where current_admin comparison operations use incorrect factors, potentially leading to unauthorized administrative actions.
OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in the skill tool dispatch component, allowing non-owner users to access owner-only tools and server credentials.
OpenClaw versions before 2026.8.1 contain a vulnerability allowing authenticated users to read and execute arbitrary operator command cron jobs, potentially exposing sensitive environment variables.
OpenClaw versions before 2026.7.1 contain a sandbox bypass vulnerability that permits unauthorized access to host browser operations via paired nodes.
A flaw in the RabbitMQ JWKS fetching mechanism fails to validate HTTP response codes, allowing non-200 responses to trigger the destruction of cached signing keys, resulting in authentication denial.
Disclosed Sep 23 without a CVSS score; tracked by CVE Brief from Sep 24; scored Sep 25, analysis completed Sep 25.
Imprivata Enterprise Access Management fails to rotate RSA key pairs after deployment, resulting in the indefinite use of static cryptographic keys for X.509 certificate generation.
Disclosed Sep 22; held until the analysis firmed up on Sep 26.
A memory leak in the SmallRye Fault Tolerance library allows unauthenticated remote attackers to trigger a denial of service by exhausting application heap memory.
D-Link DAP-2610 devices contain an authenticated command injection vulnerability in the web interface that allows arbitrary system command execution.
Catalyst::Seal versions before 0.03 for Perl contain a dispatch memoization flaw that allows an attacker to bypass authorization checks or disable specific application paths.
The .NET library CliInvoke contains an argument-injection vulnerability in its process factory components, potentially allowing arbitrary command execution when using shell runners.
Disclosed Sep 22 without a CVSS score; tracked by CVE Brief from Sep 23; scored Sep 24, analysis completed Sep 24.
MCMS versions 6.1.1 through 6.2.1 contain a stored Cross-Site Scripting (XSS) vulnerability within the article content field, which bypasses the global XSS filter.