Skip to content

This week in CVEs

A day-by-day record of the CVEs published over the last seven days.

Updated 00:28 UTC

Published per day

CriticalHighMediumLowUnscored

Tuesday, October 6

1,010 total84 critical294 high134 WordPress
CVE-2026-106102NVD10.0 Critical

Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead()

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the SSR-only getHead() serializer in ui/src/plugins/meta/Meta.js used getAttr() to interpolate values supplied through useMeta() into title, meta, link, and script markup without HTML text or quoted-attribute encoding. injectServerMeta() appended that output to the raw server-rendered response. An attacker who can influence dynamic page metadata, such as a post title, product name, excerpt, or display name, can terminate the intended HTML context and inject executable markup before hydration. The client-side apply() path is not affected because it uses DOM APIs that encode attributes. This issue is fixed in version 2.22.0.

quasarframework quasarPublished 17:07 UTCCNA GitHub_MEPSS –
CVE-2026-105857NVD10.0 Critical

Payload: RCE in Payload Form Builder

Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.

payloadcms payloadPublished 16:26 UTCCNA GitHub_MEPSS –
CVE-2026-63692NVD10.0 Critical

Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker...

Dell Container Storage ModulesPublished 14:38 UTCCNA dellEPSS –
CVE-2026-63688NVD10.0 Critical

Dell Container Storage Modules (CSM), versions prior to v1.18.0, contains a Missing Authentication for Critical Function vulnerability in the...

Dell Container Storage Modules (CSM)Published 14:32 UTCCNA dellEPSS –
CVE-2026-39773NVDWordPress10.0 Critical

WordPress Doctreat Core plugin <= 1.7.0 - Privilege Escalation vulnerability

Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions.

AmentoTech Doctreat CorePublished 08:34 UTCCNA PatchstackEPSS –
plugin:doctreat_core≤ 1.7.0fixed inNo fix listed
CVE-2026-39770NVDWordPress10.0 Critical

WordPress Doctreat theme <= 1.7.0 - Arbitrary File Upload vulnerability

Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.

AmentoTech DoctreatPublished 08:34 UTCCNA PatchstackEPSS –
theme:doctreat≤ 1.7.0fixed inNo fix listed
CVE-2026-32579NVDWordPress10.0 Critical

WordPress Kognetiks Chatbot for WordPress plugin <= 2.4.9 - Arbitrary File Upload vulnerability

Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.

Kognetiks Chatbot for WordPressPublished 08:34 UTCCNA PatchstackEPSS –
plugin:chatbot-chatgpt≤ 2.4.9fixed inNo fix listed
CVE-2026-105484NVD10.0 Critical

TOTOLINK X6000R UploadFirmwareFile cstecgi.cgi firmware_check os command injection

A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.

TOTOLINK X6000RPublished 01:00 UTCCNA VulDBEPSS –
1,002 more published Oct 6, by severityShow
  1. The list loads with JavaScript.

Monday, October 5

413 total29 critical154 high62 WordPress
CVE-2026-105285NVD10.0 Critical

Totolink A3002MU QoS Rule formIpQoS stack-based overflow

A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument addQos/comment/entry_name leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

Totolink A3002MUPublished 09:15 UTCCNA VulDBEPSS 1.10%
CVE-2026-105284NVD10.0 Critical

Totolink A3002MU Authentication Check boa sub_40FCFC improper authorization

A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

Totolink A3002MUPublished 09:00 UTCCNA VulDBEPSS 0.78%
CVE-2026-100103NVD10.0 Critical

Authentication bypass via default auth token in P4Search

Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly documented default value. An unauthenticated attacker with network access can obtain the highest application privilege, potentially leading to arbitrary code execution and compromise of the connected P4 Server.

Perfoce P4 (Helix Core)Published 08:19 UTCCNA PerforceEPSS 0.42%
CVE-2026-105740NVD9.9 Critical

Langflow: Authenticated RCE via MCP Stdio transport allows any user to execute arbitrary OS commands on the server

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenticated Langflow user can achieve Remote Code Execution (RCE) on the server by adding an MCP server with the "Stdio" transport. The user-supplied command field is passed directly to bash -c "exec {command}" with zero validation, no allowlisting, and no sandboxing. The command executes immediately when the server list is fetched. Additionally, the env field allows arbitrary environment variable injection (e.g., LD_PRELOAD, PATH override). This vulnerability is fixed in 1.9.0.

langflow-ai langflowPublished 20:46 UTCCNA GitHub_MEPSS –
CVE-2026-105697NVD9.9 Critical

Langflow: OS command injection (RCE) via arbitrary command in MCP stdio server configuration

Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the MCP stdio transport launched whatever command / args a user put in an MCP server configuration, with no allowlist and (before 1.10.3) wrapped in bash -c "exec {command} ...". Any user able to reach the MCP server settings ("Settings → MCP Servers → Add MCP Server", POST/PATCH /api/v2/mcp/servers/{server_name}) or to build a flow with the MCP Tools component could add a "server" whose command is an arbitrary OS command (touch, rm -rf, a reverse shell, ...). The command runs on the Langflow host as the Langflow process user as soon as Langflow tries to connect to the server (listing servers, loading tools, running the flow) — even when the UI then reports that the stdio server failed to start. With the default LANGFLOW_AUTO_LOGIN=true, GET /api/v1/auto_login hands out a token without credentials, so on an exposed instance running the default configuration this is reachable without an account. AUTO_LOGIN is documented as a development-only setting; with it disabled, any authenticated (non-admin) user can exploit it. This issue is fixed in Langflow 1.10.3, langflow-base 0.10.3, and lfx 1.10.3.

langflow-ai langflow +2Published 20:16 UTCCNA GitHub_MEPSS –
CVE-2026-105691NVD9.9 Critical

Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color

Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's privileges. The same export can be triggered through a valid public share link to a malicious file. This vulnerability is fixed in 2.18.0.

penpotPublished 19:53 UTCCNA GitHub_MEPSS –
CVE-2026-105636NVD9.9 Critical

Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set)

Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker-controlled public endpoint that returns a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, where the attacker can retrieve it through the workspace webhook-logs API. This issue is fixed in 1.4.0.

makeplane planePublished 18:02 UTCCNA GitHub_MEPSS –
CVE-2026-82989NVD9.8 Critical

CVE-2026-82989

There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints

Viewsonic vCastPublished 23:14 UTCCNA certccEPSS –
405 more published Oct 5, by severityShow
  1. The list loads with JavaScript.

Sunday, October 4

64 total6 critical29 high1 KEV13 WordPress

Memory overflow vulnerability leading to Denial of Service

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

NetScaler ADC +1Published 02:35 UTCCNA NetScalerEPSS 0.53%KEV since Oct 4, due Oct 7
CVE-2026-105134NVD10.0 Critical

Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.

AhsayCBSPublished 05:30 UTCCNA VulDBEPSS 1.84%
CVE-2026-105135NVD10.0 Critical

InternLM MindSearch Planner Agent graph.py ExecutionAction.run code injection

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

InternLM MindSearchPublished 06:15 UTCCNA VulDBEPSS 0.77%
CVE-2026-105207NVD9.8 Critical

ZITADEL before 4.17.3 Account Takeover via External IdP Linking

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint. An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.

zitadelPublished 13:10 UTCCNA VulnCheckEPSS 0.31%
CVE-2026-105209NVD9.6 Critical

ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment

ZITADEL 3.x before 3.4.15 and 4.x before 4.17.1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization. Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.

zitadelPublished 13:10 UTCCNA VulnCheckEPSS 0.22%
CVE-2026-103355NVDWordPress9.3 Critical

WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.20 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 2.0.20.

Unlimited Elements For Elementor (Free Widgets, Addons, Templates)Published 08:00 UTCCNA PatchstackEPSS 0.25%
plugin:unlimited-elements-for-elementor≤ 2.0.20fixed in2.0.21
CVE-2026-105215NVD9.1 Critical

ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.

zitadelPublished 13:10 UTCCNA VulnCheckEPSS 0.34%
57 more published Oct 4, by severityShow
  1. The list loads with JavaScript.

Saturday, October 3

114 total5 critical42 high76 WordPress
CVE-2026-105080NVD9.9 Critical

In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects...

C4illin ConvertXPublished 00:39 UTCCNA mitreEPSS 0.33%
CVE-2026-105105NVD9.8 Critical

Unauthenticated ZeroMQ command/telemetry bus in AIT-Core allows remote spacecraft command injection and telemetry exfiltration

CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data, exfiltrate command and telemetry traffic, inject forged telemetry, or disrupt the command and telemetry bus. The ait-server ZeroMQ broker binds its XSUB and XPUB sockets to all network interfaces by default without authentication or transport security. An attacker able to reach TCP port 5559 can publish messages onto internal topics, including the __commands__ command topic. With the shipped default configuration, command messages are forwarded through command_stream and emitted on the command-uplink UDP path. An attacker able to reach TCP port 5560 can subscribe to command and telemetry traffic on the ground bus. AIT-Core 3.1.2 changes the default ZeroMQ bind addresses to loopback.

NASA-AMMOS AIT-CorePublished 11:55 UTCCNA TuranSecEPSS 0.78%
CVE-2026-71885NVD9.2 Critical

MLS X.509 credential not bound to the LeafNode signature key

In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the credential's X.509 certificate chain was stored but never parsed or validated, so the end-entity certificate's public key was never required to match signature_key as RFC 9420 sec. 5.3 requires. A party could therefore present another party's certificate as its credential while signing the leaf, and the enclosing KeyPackage, with an unrelated key, and be accepted under that other party's identity through KeyPackage.verify() and the Group leaf-validation path. In a deployment that admits external commits without an independent credential-admission check, an unauthenticated attacker could be admitted under a victim's X.509 identity, evict the victim (resynchronization compares whole credentials rather than signing keys), derive the current epoch, decrypt subsequent group messages, and send messages accepted as the victim. TreeKEM.LeafNode now requires the end-entity certificate's subject public key, in the cipher suite's signature encoding, to equal signature_key for an X.509 credential and rejects the leaf otherwise, including an empty chain or a certificate whose key type does not match the cipher suite; certificate-chain and identity validation to a trust anchor remain the application's responsibility per RFC 9420 sec. 5.3.1. Deployments using only basic credentials are unaffected.

Legion of the Bouncy Castle Inc. BC-JAVAPublished 08:51 UTCCNA bcorgEPSS 0.19%
CVE-2026-87115NVDWordPress9.1 Critical

VikAppointments Services Booking Calendar <= 1.2.21 - Unauthenticated Arbitrary File Deletion via 'old_vapcfN' Parameter

The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires at least one File-type custom field to be published on the confirmation page shortcode, as this field is not created by default during plugin installation.

e4jvikwp VikAppointments Services Booking CalendarPublished 06:38 UTCCNA WordfenceEPSS 0.88%
plugin:vikappointments≤ 1.2.21fixed inNo fix listed
CVE-2026-92084NVDWordPress9.1 Critical

Beaver Builder Page Builder <= 2.11.0.5 - Unauthenticated Arbitrary Shortcode Execution via Sidebar Module Widget Output

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. Exploitation requires the target site to have a Beaver Builder page containing the Sidebar module populated with a widget that displays attacker-controllable text, such as the core Recent Comments widget, with comment moderation disabled or the attacker's comment approved.

beaverbuilder Beaver Builder Page Builder – Drag and Drop Website BuilderPublished 07:39 UTCCNA WordfenceEPSS 0.53%
plugin:beaver-builder-lite-version≤ 2.11.0.5fixed inNo fix listed
109 more published Oct 3, by severityShow
  1. The list loads with JavaScript.

Friday, October 2

398 total40 critical181 high70 WordPress
CVE-2026-104610NVD10.0 Critical

Tenda HG7/HG9/HG10 Boa Web Server formLoopBack boaGetVar stack-based overflow

A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

Tenda HG7 +2Published 12:00 UTCCNA VulDBEPSS 0.64%
CVE-2026-103956NVD10.0 Critical

Missing authentication for critical function in Loom for AWS

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured. To remediate this issue, users should upgrade to version 1.6.1 or later.

AWS loomPublished 19:06 UTCCNA AMZNEPSS 0.47%
CVE-2026-90970NVD9.9 Critical

Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

GitLab AI GatewayPublished 14:34 UTCCNA GitLabEPSS 0.94%
CVE-2026-93698NVD9.9 Critical

Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.

Webpros cPanel +1Published 06:20 UTCCNA hackeroneEPSS 0.46%
CVE-2026-82041NVD9.9 Critical

UTMStack < 11.2.16 Missing Authorization via Command WebSocket

UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any authenticated user, regardless of role, can send arbitrary operating-system commands over gRPC to any connected agent, resulting in command execution on monitored endpoints where agent processes commonly run as root or SYSTEM.

UTMStackPublished 20:13 UTCCNA VulnCheckEPSS 0.44%
CVE-2026-84411NVD9.8 Critical

MikroTik RouterOS Integer Underflow

The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.

MikroTik RouterOSPublished 22:09 UTCCNA icscertEPSS 0.95%
CVE-2026-97637NVDWordPress9.8 Critical

JSON API Auth <= 3.1.2 - Unauthenticated Authentication Bypass via Cached 'generate_auth_cookie' Response

The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in transients keyed solely by URI and query string, ignoring HTTP method and POST body; this causes the `generate_auth_cookie()` endpoint — which embeds a live WordPress `logged_in` cookie produced by `wp_generate_auth_cookie()` directly in its JSON response body — to serve that cached authenticated response to any subsequent unauthenticated GET request to the same URI. This makes it possible for unauthenticated attackers to retrieve a valid Administrator `logged_in` session cookie from the cached response and use it to fully authenticate as the site Administrator, including via the same plugin's `get_currentuserinfo` endpoint and any cookie-authenticated controller action. Exploitation requires the PI-Media/json-api parent plugin to be installed and active with the Auth controller enabled, and a legitimate Administrator must have POSTed to `/api/auth/generate_auth_cookie/` within the preceding 24-hour cache TTL; the nominal HTTPS enforcement gate present in `Auth.php` is trivially bypassed by supplying `insecure=cool` as a request parameter.

parorrey JSON API AuthPublished 07:39 UTCCNA WordfenceEPSS 0.64%
plugin:json-api-auth≤ 3.1.2fixed inNo fix listed
CVE-2023-54405NVD9.8 Critical

H3C CVM Unauthenticated File Upload via fileUpload/upload Token

H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token parameter to upload a malicious JSP file into a web-accessible directory and then request it to achieve remote code execution as the web-server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.

H3C CVMPublished 18:36 UTCCNA VulnCheckEPSS 0.59%
390 more published Oct 2, by severityShow
  1. The list loads with JavaScript.

Thursday, October 1

395 total54 critical161 high1 KEV86 WordPress
CVE-2026-104286NVDKEV9.8 Critical

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0...

Fortinet FortiMailPublished 19:17 UTCCNA fortinetEPSS 2.20%KEV since Oct 1, due Oct 4
CVE-2026-55393NVD10.0 Critical

Local File Inclusion in Teledyne FLIR Robots running Aware2

Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.

Teledyne FLIR Aware2Published 19:59 UTCCNA MandiantEPSS 0.43%
CVE-2026-101148NVD10.0 Critical

BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via Empty Integration Key

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user password hashes, and to delete arbitrary files on the server, leading to sensitive data disclosure and site takeover. The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 has been closed on WordPress.org since July 2024 and no fixed version is available. Remove it from any site where it is installed.

BackupSheep WordPress Backup PluginPublished 06:00 UTCCNA WPScanEPSS 0.31%
CVE-2026-96658NVD9.9 Critical

Foreman: safemode bypass leading to rce

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.

Red Hat Satellite 6.16 for RHEL 8 +4Published 16:23 UTCCNA redhatEPSS 0.70%
CVE-2026-79901NVD9.9 Critical

Predictable Active Directory service-account passwords in BoKS Manager

In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.

Fortra BoKS Manager boks-serverPublished 13:52 UTCCNA FortraEPSS 0.27%
CVE-2026-103764NVD9.8 Critical

Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport

Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with arbitrary addr and size values using READ or WRITE opcodes to disclose KV cache contents, prompts and secrets or corrupt memory toward code execution.

kvcache-ai MooncakePublished 23:19 UTCCNA VulnCheckEPSS 0.64%
CVE-2025-41753NVD9.8 Critical

Path traversal in dynamically created BACnet File Objects

The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite arbitrary files on the device, which may lead to full system compromise.

WAGO 0751-9x01 +10Published 06:42 UTCCNA CERTVDEEPSS 0.59%
CVE-2026-75957NVDWordPress9.8 Critical

Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter

The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the publicly accessible `wu_ajax_nopriv_wu_validate_form` AJAX handler accepting a freely obtainable checkout nonce, and the `checkout_form=wu-finish-checkout` parameter causing `get_validation_rules()` to discard all validation rules while `finish_checkout_form_fields()` returns an empty step list — forcing `is_last_step()` to return true and routing the request directly into full order processing — after which `maybe_create_customer()` resolves the attacker-supplied `email_address` to an existing WordPress user ID without any authentication or ownership verification, and `login_customer_after_checkout()` calls `wp_set_auth_cookie()` for that user ID via a passwordless code path. This makes it possible for unauthenticated attackers to log in as any existing WordPress user — including a Network Super Admin — simply by knowing their email address. Exploitation requires that the targeted user account has no pre-existing Ultimate Multisite customer record; accounts such as a Network Super Admin on a fresh Multisite install, or any administrator or editor added before Ultimate Multisite was configured, satisfy this condition and are therefore exploitable.

superdav42 Ultimate Multisite – WordPress Multisite SaaS & WaaS PlatformPublished 07:40 UTCCNA WordfenceEPSS 0.58%
plugin:ultimate-multisite≤ 2.15.0fixed inNo fix listed
387 more published Oct 1, by severityShow
  1. The list loads with JavaScript.

Wednesday, September 30

636 total64 critical308 high3 KEV188 WordPress
CVE-2026-76504NVDKEV9.8 Critical

Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

Cisco Catalyst SD-WAN ManagerPublished 13:04 UTCCNA ciscoEPSS 1.57%KEV since Sep 30, due Oct 3

Undisclosed RCE in Zammad v6.3 and higher

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

Zammad GmbH ZammadPublished 16:21 UTCCNA DIVDEPSS 1.40%KEV since Oct 2, due Oct 5

Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

Zammad GmbH ZammadPublished 16:21 UTCCNA DIVDEPSS 0.63%KEV since Oct 2, due Oct 5
CVE-2026-55107NVD10.0 Critical

Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)

Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.

elct9620 kobakoPublished 17:06 UTCCNA GitHub_MEPSS 0.80%
CVE-2026-102427NVD10.0 Critical

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.

ordasoft.com OrdaSoft Joomla CCKPublished 15:14 UTCCNA JoomlaEPSS 0.79%
CVE-2026-96349NVDWordPress10.0 Critical

WordPress SiteSkite plugin <= 2.1.8 - Remote Code Execution (RCE) vulnerability

Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.

SiteSkitePublished 12:27 UTCCNA PatchstackEPSS 0.60%
plugin:siteskite≤ 2.1.8fixed in2.2.0
CVE-2026-76570NVD10.0 Critical

Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables < 1.21.1

Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request parameters and concatenated into SQL queries, allowing SQLi for reading and writing queries.

joomcode.com JCTables extension for JoomlaPublished 14:47 UTCCNA JoomlaEPSS 0.46%
CVE-2026-102911NVD9.9 Critical

zosmaai pi-llm-wiki wiki_capture_source MCP tool index.ts os command injection

A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. Upgrading to version 0.11.8 is able to address this issue. This patch is called 360867034e79175b45c8e04a98e4ca712bbaca35. Upgrading the affected component is advised.

zosmaai pi-llm-wikiPublished 03:45 UTCCNA VulDBEPSS 1.78%
628 more published Sep 30, by severityShow
  1. The list loads with JavaScript.