CVE & CISA-KEV Catalog
| Severity | Description | ||||||
|---|---|---|---|---|---|---|---|
| CVE-2026-87886 | High | 7.8 v3 | - | KEV | Fix available | 2026-09-17 | Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238. |
| CVE-2026-76460 | Critical | 10.0 v3 | - | KEV | -No fix available yet | 2026-09-16 | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. |
| CVE-2026-58704 | High | 8.8 v3 | - | KEV | -No fix available yet | 2026-09-15 | In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
| CVE-2026-76461 | Critical | 9.8 v3 | 2.2% | KEV | Fix available | 2026-09-14 | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system. |
| CVE-2026-85706 | Critical | 10.0 v3 | 12% | KEV | Fix available | 2026-09-12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. |
| CVE-2026-87491 | High | 8.8 v3 | 1.0% | KEV | Fix available | 2026-09-11 | This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2026-87491 exists in the wild. |
| CVE-2026-85046 | High | 8.8 v3 | 1.5% | KEV | Fix available | 2026-09-09 | This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2026-85046 exists in the wild. |
| CVE-2026-84869 | Critical | 9.9 v3 | 0.7% | KEV | Fix available | 2026-09-08 | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted. |
| CVE-2026-85880 | High | 7.8 v3 | 0.6% | KEV | Fix available | 2026-09-08 | Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally. |
| CVE-2026-81963 | High | 7.8 v3 | 0.6% | KEV | Fix available | 2026-09-08 | Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. |
| CVE-2026-75650 | Critical | 10.0 v3 | 2.1% | KEV | Fix available | 2026-09-07 | Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. |
| CVE-2026-86218 | Critical | 9.8 v3 | 0.7% | KEV | Fix available | 2026-09-06 | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. |
| CVE-2026-86060 | Critical | 9.8 v3 | 1.1% | KEV | Fix available | 2026-09-05 | RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) |
| CVE-2026-67277 | High | 8.2 v3 | 0.9% | KEV | Fix available | 2026-09-05 | RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) |
| CVE-2026-83549 | High | 7.8 v3 | 8.5% | KEV | Fix available | 2026-09-01 | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. |
| CVE-2026-83548 | Critical | 10.0 v3 | 4.7% | KEV | Fix available | 2026-09-01 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations. |
| CVE-2026-82329 | Critical | 9.8 v3 | 7.7% | KEV | Fix available | 2026-08-28 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. |
| CVE-2026-82078 | Critical | 9.1 v3 | 1.7% | KEV | Fix available | 2026-08-28 | An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. |
| CVE-2026-81578 | Critical | 9.8 v3 | 1.6% | KEV | Fix available | 2026-08-28 | An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations. |
| CVE-2026-60004 | Critical | 9.8 v3 | 87% | KEV | Fix available | 2026-08-26 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. |
| CVE-2026-72530 | Critical | 9.0 v3 | 1.8% | KEV | Fix available | 2026-08-19 | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. |
| CVE-2026-72529 | Critical | 9.8 v3 | 1.6% | KEV | Fix available | 2026-08-19 | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function. |
| CVE-2026-19490 | Critical | 9.8 v3 | 5.6% | KEV | Fix available | 2026-08-19 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. |
| CVE-2026-64849 | Critical | 9.3 v3 | 16% | KEV | Fix available | 2026-08-17 | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0. |
| CVE-2026-73570 | High | 8.9 v3 | 32% | KEV | Fix available | 2026-08-13 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. |
| CVE-2026-42018 | High | 7.5 v3 | 0.9% | KEV | Fix available | 2026-08-12 | JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. |
| CVE-2026-66384 | Medium | 5.3 v3 | 0.6% | KEV | Fix available | 2026-08-12 | An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. |
| CVE-2026-20349 | High | 8.6 v3 | 2.2% | KEV | -No fix available yet | 2026-08-11 | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. |
| CVE-2026-68820 | High | 7.0 v3 | 6.2% | KEV | Fix available | 2026-08-11 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
| CVE-2026-72898 | Critical | 10.0 v3 | 94% | KEV | Fix available | 2026-08-10 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance. |
| CVE-2026-65400 | Critical | 9.8 v3 | 10% | KEV | Fix available | 2026-08-06 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. |
| CVE-2026-18577 | High | 8.1 v3 | 54% | KEV | Fix available | 2026-08-02 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 |
| CVE-2026-18556 | High | 7.4 v3 | 40% | KEV | -No fix available yet | 2026-08-01 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. |
| CVE-2026-59310 | Critical | 9.8 v3 | 46% | KEV + Ransom | Fix available | 2026-07-30 | VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. |
| CVE-2026-20316 | Medium | 5.3 v3 | 11% | KEV + Ransom | -No fix available yet | 2026-07-29 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this se |
| CVE-2026-42016 | High | 8.1 v3 | 0.9% | KEV | Fix available | 2026-07-27 | JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. |
| CVE-2026-63077 | Critical | 9.8 v3 | 87% | KEV | Fix available | 2026-07-27 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol |
| CVE-2026-16812 | Critical | 10.0 v3 | 1.6% | KEV | Fix available | 2026-07-27 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited. |
| CVE-2026-16232 | Critical | 9.8 v3 | 72% | KEV | Fix available | 2026-07-22 | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers. |
| CVE-2026-63030 | Critical | 9.8 v3 | 97% | KEV | Fix available | 2026-07-17 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. |
| CVE-2026-60137 | Medium | 5.9 v3 | 78% | KEV | Fix available | 2026-07-17 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. |
| CVE-2026-9198 | Critical | 9.8 v3 | 61% | KEV | Fix available | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments |
| CVE-2026-9586 | Critical | 9.8 v3 | 12% | KEV | Fix available | 2026-07-17 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. |
| CVE-2021-27137 | High | 8.1 v3 | 4.0% | KEV | Fix available | 2026-07-16 | An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request). |
| CVE-2026-15410 | High | 7.2 v3 | 12% | KEV + Ransom | -No fix available yet | 2026-07-14 | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. |
| CVE-2026-15409 | Critical | 10.0 v3 | 85% | KEV + Ransom | -No fix available yet | 2026-07-14 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. |
| CVE-2026-58644 | Critical | 9.8 v3 | 16% | KEV | Fix available | 2026-07-14 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. |
| CVE-2026-56164 | Medium | 5.3 v3 | 27% | KEV | Fix available | 2026-07-14 | Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-56155 | High | 7.8 v3 | 0.3% | KEV | Fix available | 2026-07-14 | Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally. |
| CVE-2026-55040 | Critical | 9.1 v3 | 51% | KEV | Fix available | 2026-07-14 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. |
- HighKEVCVSS 7.8 v3·EPSS -·Fix available
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
Published 2026-09-17
- CriticalKEVCVSS 10.0 v3·EPSS -·No fix yet
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
Published 2026-09-16
- HighKEVCVSS 8.8 v3·EPSS -·No fix yet
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Published 2026-09-15
- CriticalKEVCVSS 9.8 v3·EPSS 2.2%·Fix available
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.
Published 2026-09-14
- CriticalKEVCVSS 10.0 v3·EPSS 12%·Fix available
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
Published 2026-09-12
- HighKEVCVSS 8.8 v3·EPSS 1.0%·Fix available
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2026-87491 exists in the wild.
Published 2026-09-11
- HighKEVCVSS 8.8 v3·EPSS 1.5%·Fix available
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2026-85046 exists in the wild.
Published 2026-09-09
- CriticalKEVCVSS 9.9 v3·EPSS 0.7%·Fix available
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
Published 2026-09-08
- HighKEVCVSS 7.8 v3·EPSS 0.6%·Fix available
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- HighKEVCVSS 7.8 v3·EPSS 0.6%·Fix available
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Published 2026-09-08
- CriticalKEVCVSS 10.0 v3·EPSS 2.1%·Fix available
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published 2026-09-07
- CriticalKEVCVSS 9.8 v3·EPSS 0.7%·Fix available
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Published 2026-09-06
- CriticalKEVCVSS 9.8 v3·EPSS 1.1%·Fix available
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Published 2026-09-05
- HighKEVCVSS 8.2 v3·EPSS 0.9%·Fix available
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Published 2026-09-05
- HighKEVCVSS 7.8 v3·EPSS 8.5%·Fix available
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Published 2026-09-01
- CriticalKEVCVSS 10.0 v3·EPSS 4.7%·Fix available
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Published 2026-09-01
- CriticalKEVCVSS 9.8 v3·EPSS 7.7%·Fix available
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
Published 2026-08-28
- CriticalKEVCVSS 9.1 v3·EPSS 1.7%·Fix available
An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.
Published 2026-08-28
- CriticalKEVCVSS 9.8 v3·EPSS 1.6%·Fix available
An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.
Published 2026-08-28
- CriticalKEVCVSS 9.8 v3·EPSS 87%·Fix available
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
Published 2026-08-26
- CriticalKEVCVSS 9.0 v3·EPSS 1.8%·Fix available
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Published 2026-08-19
- CriticalKEVCVSS 9.8 v3·EPSS 1.6%·Fix available
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Published 2026-08-19
- CriticalKEVCVSS 9.8 v3·EPSS 5.6%·Fix available
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Published 2026-08-19
- CriticalKEVCVSS 9.3 v3·EPSS 16%·Fix available
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.
Published 2026-08-17
- HighKEVCVSS 8.9 v3·EPSS 32%·Fix available
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
Published 2026-08-13
- HighKEVCVSS 7.5 v3·EPSS 0.9%·Fix available
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Published 2026-08-12
- MediumKEVCVSS 5.3 v3·EPSS 0.6%·Fix available
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Published 2026-08-12
- HighKEVCVSS 8.6 v3·EPSS 2.2%·No fix yet
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Published 2026-08-11
- HighKEVCVSS 7.0 v3·EPSS 6.2%·Fix available
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Published 2026-08-11
- CriticalKEVCVSS 10.0 v3·EPSS 94%·Fix available
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
Published 2026-08-10
- CriticalKEVCVSS 9.8 v3·EPSS 10%·Fix available
An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Published 2026-08-06
- HighKEVCVSS 8.1 v3·EPSS 54%·Fix available
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Published 2026-08-02
- HighKEVCVSS 7.4 v3·EPSS 40%·No fix yet
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Published 2026-08-01
- CriticalKEV + RansomCVSS 9.8 v3·EPSS 46%·Fix available
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
Published 2026-07-30
- MediumKEV + RansomCVSS 5.3 v3·EPSS 11%·No fix yet
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this se
Published 2026-07-29
- HighKEVCVSS 8.1 v3·EPSS 0.9%·Fix available
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Published 2026-07-27
- CriticalKEVCVSS 9.8 v3·EPSS 87%·Fix available
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
Published 2026-07-27
- CriticalKEVCVSS 10.0 v3·EPSS 1.6%·Fix available
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.
Published 2026-07-27
- CriticalKEVCVSS 9.8 v3·EPSS 72%·Fix available
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Published 2026-07-22
- CriticalKEVCVSS 9.8 v3·EPSS 97%·Fix available
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
Published 2026-07-17
- MediumKEVCVSS 5.9 v3·EPSS 78%·Fix available
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
Published 2026-07-17
- CriticalKEVCVSS 9.8 v3·EPSS 61%·Fix available
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Published 2026-07-17
- CriticalKEVCVSS 9.8 v3·EPSS 12%·Fix available
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
Published 2026-07-17
- HighKEVCVSS 8.1 v3·EPSS 4.0%·Fix available
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
Published 2026-07-16
- HighKEV + RansomCVSS 7.2 v3·EPSS 12%·No fix yet
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Published 2026-07-14
- CriticalKEV + RansomCVSS 10.0 v3·EPSS 85%·No fix yet
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
Published 2026-07-14
- CriticalKEVCVSS 9.8 v3·EPSS 16%·Fix available
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Published 2026-07-14
- MediumKEVCVSS 5.3 v3·EPSS 27%·Fix available
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Published 2026-07-14
- HighKEVCVSS 7.8 v3·EPSS 0.3%·Fix available
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Published 2026-07-14
- CriticalKEVCVSS 9.1 v3·EPSS 51%·Fix available
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Published 2026-07-14
Free CVE lookup by TridentStack Control, automated patching for Windows, macOS, and Linux fleets. Learn more·Uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog.