The Events Calendar ≤ 6.17.4: 2 Unauthenticated RCEs via Comments
CVE-2026-78006 and CVE-2026-78159 (CVSS 9.8): unauthenticated code execution in the WordPress plugin The Events Calendar, through a comment awaiting moderation. Immediate mitigation.
Routers: 11 Critical CVEs in September — D-Link, Totolink, Netis, WAVLINK
Eleven CVSS 9.1 to 9.9 CVEs across D-Link DIR-823G / DIR-878 / DWR-M921, Totolink A3002MU, Netis NX10 and WAVLINK WN535M. Public exploits, and a web server abandoned in 2005 behind several of them.
JFrog Artifactory: 4 CISA KEV CVEs in 16 Days — Fixed in 7.133.11 and 7.146.8
CVE-2026-66384, 82329, 42016 and 42018: four JFrog Artifactory vulnerabilities added to CISA KEV between August 27 and September 11, 2026. Three of the four are authentication failures.
CVE-2026-85706 GitLab: Fixed in 19.1.8, 19.2.6, 19.3.2 — Unauthenticated File Read
GitLab CE/EE fixes 19.1.8, 19.2.6 and 19.3.2 for CVE-2026-85706 (CVSS 10.0, CISA KEV): a path traversal in the commits API allowing arbitrary file reads without authentication.
RMM in CISA KEV: N-able N-central 2026.3.1.14 and ConnectWise ScreenConnect 26.6.5.9742
CVE-2026-86218 (9.8) in N-able N-central and CVE-2026-84869 (9.9) in ConnectWise ScreenConnect: two remote management tools KEV-listed four days apart. Fixes and detection.
Citrix NetScaler and Cisco FMC: 2 Authentication Bypasses in CISA KEV
CVE-2026-19490 (NetScaler ADC / Gateway) and CVE-2026-20079 (Cisco Secure FMC): two alternate-path authentication bypasses added to CISA KEV on September 9, 2026, with a three-day deadline.
Chrome 153.0.8010.36: 4 CVEs, 2 Exploited — V8, WebView and Extensions
Chrome fix 153.0.8010.36 for CVE-2026-87534 and 87544, plus two V8 CVEs in CISA KEV (CVE-2026-87491, CVE-2026-85046). Why the NVD scores mislead here.
Samsung SMR September 2026: CVE-2026-21095 and 21096, 9.8 RCE in Image Decoders
CVE-2026-21095 and CVE-2026-21096 (CVSS 9.8): two heap overflows in the DNG and JPEG decoders of libimagecodec.quram.so, fixed by SMR Sep-2026 Release 1. Android 14 through 17.
MikroTik RouterOS: Fixed in 6.49.21, 7.23.4 and 7.24.2 — 2 CVEs in CISA KEV
RouterOS fixes 6.49.21, 7.23.4 and 7.24.2 for CVE-2026-67277 (kernel memory leak via btest) and CVE-2026-86060 (privilege escalation), both added to CISA KEV on September 10, 2026.
Windows: CVE-2026-85880 and CVE-2026-81963 in CISA KEV — Escalation to SYSTEM
September 2026 Patch Tuesday: two Windows privilege escalations KEV-listed the same day — an ALPC heap overflow and a link following flaw in the Windows Update Stack.
Commvault: 3 CVSS 9.8 CVEs — Fixed in 11.36.123, 11.40.72, 11.44.20, 11.46.20
Commvault fixes 11.36.123, 11.40.72, 11.44.20 and 11.46.20 for CVE-2026-77089, 77092 and 77098: authentication bypass, deserialization and SQL injection across the backup platform.
CVE-2026-75650 Adobe Commerce / Magento 2.4.4-2.4.9: 10.0 RCE in CISA KEV
CVE-2026-75650 (CVSS 10.0): template engine injection in Adobe Commerce and Magento Open Source 2.4.4 through 2.4.9 — code execution with no authentication and no user interaction. Added to CISA KEV.
PaperCut CVE-2026-81578 + 82078: Fixed in 24.1.9, 25.0.12, 26.0.4 — a Chain to RCE
PaperCut NG/MF fixes 24.1.9, 25.0.12 and 26.0.4 for CVE-2026-81578 (9.8) and CVE-2026-82078 (9.1), two CISA KEV entries the agency explicitly flags as chainable.
SOHO Routers: 6 Critical CVEs with Public Exploits (TRENDnet, ipTIME, Comfast, UTT)
TRENDnet TEW-821DAP / 823DRU / 755AP, EFM ipTIME T16000M, Comfast CF-N1-S and UTT HiPER 1250GW: six CVSS 9.9-10.0 CVEs, every exploit is public. Audit and mitigation.
OpenShift Multi-Cluster: 3 CVSS 9.9 CVEs in Submariner, Lighthouse and ACM
CVE-2026-66785, CVE-2026-66788 and CVE-2026-70496: a compromised spoke cluster can hijack traffic and inject resources into its peers. The hub-spoke trust model questioned.
Firefox 154 / ESR 140.14: 4 Use-After-Free CVSS 9.8 — Thunderbird Too
Fixes in Firefox 154, ESR 153.1, ESR 140.14, ESR 115.39 and Thunderbird 154 / 153.1 / 140.14 for CVE-2026-74936, 74940, 74943 and 74944: four critical use-after-free flaws.
Oracle August 2026: 17 Critical CVEs in Hyperion and Reports Developer
17 CRITICAL CVEs (CVSS 9.8 to 10.0) in Oracle Hyperion 11.2.25 and Reports Developer 12.2.1.19 / 14.1.2 — unauthenticated takeover over HTTP, TCP, IIOP, UDP and CORBA.
Check Point SmartConsole CVE-2026-16232: Admin Token Obtained Without Authentication
An unauthenticated attacker can obtain a SmartConsole session token and authenticate with full administrative privileges on Quantum and Multi-Domain Security Management. Exploitation confirmed by Check Point.
Cisco FMC & Unified CM in KEV: When Cisco Rates Its Own Flaws Above CVSS
CVE-2026-20316 (hard-coded password in Secure Firewall Management Center) and CVE-2026-20230 (Unified CM SSRF to root) are in CISA KEV. Two cases where CVSS understates real risk.
Fortinet in KEV: 2 FortiSandbox RCEs and a Bypass of the FortiOS Anti-Persistence Patch
CVE-2026-39808 and CVE-2026-25089 (FortiSandbox, unauthenticated command injection) and CVE-2025-68686 (FortiOS, symlink persistence patch bypass). Three CVEs in CISA KEV.
Arista VeloCloud Orchestrator CVE-2026-16812: Exploited 10.0 RCE on SD-WAN
VeloCloud Orchestrator on-prem (formerly VMware SD-WAN) exposes internal functionality remotely: OS command injection, CVSS 10.0, active exploitation confirmed by the vendor. Versions and mitigation.
Langflow CVE-2026-0770: Unauthenticated Root RCE in LLM Tooling (CVSS 9.8)
Langflow exposes the exec_globals parameter of its validate endpoint: code execution as root without authentication. With CVE-2026-55255 (running other users' flows), two CVEs in CISA KEV.
SharePoint: 4 CVEs Added to CISA KEV in 3 Weeks — Unauthenticated RCE Chain
Microsoft SharePoint racked up 4 CISA KEV entries in July 2026: two CVSS 9.8 deserializations, an authentication bypass and an authenticated RCE. Chain analysis, detection and patching.
WordPress Core CVE-2026-60137 + 63030: Chained SQLi to Unauthenticated RCE
Two WordPress core CVEs (6.9.x < 6.9.5, 7.0.x < 7.0.2) chain into unauthenticated RCE on default installations: REST API batch route confusion + author__not_in SQL injection. In CISA KEV.
Joomla: 4 Extensions Added to KEV in 4 Days — Unauthenticated Upload to RCE
iCagenda, Balbooa Forms, Joomlack Page Builder, JoomShaper SP Page Builder: four Joomla extensions in CISA KEV in early July 2026, all arbitrary file upload leading to RCE. Audit and mitigation.
SimpleHelp CVE-2026-48558: Unverified OIDC Signature, RMM Takeover (CVSS 10.0)
SimpleHelp ≤ 5.5.15 accepts OIDC tokens without verifying their cryptographic signature. A forged token grants a full technician session, MFA bypassed. CVSS 10.0, in CISA KEV.
Ubiquiti UniFi OS: 3 CVEs Added to KEV the Same Day, Chaining to Full Takeover
CVE-2026-34908, 34909 and 34910: broken access control, path traversal and command injection on UniFi OS. Three CVEs added to CISA KEV on the same day, exploitable as a chain.
WordPress May 2026: 4 Critical Plugins with Auth Bypass / RCE (CVSS 9.8)
Burst Analytics, Career Section, InfusedWoo Pro, Form Notify — 4 WordPress plugins with auth bypass / RCE / privilege escalation disclosed in May 2026. Versions and mitigation.
SAP S/4HANA CVE-2026-34260: Authenticated SQL Injection in Enterprise Search ABAP
SAP S/4HANA Enterprise Search ABAP: SQL injection (CVSS 9.6) via user input concatenated without validation. Sensitive data exfiltration risk, audit recommended.
Microsoft Patch Tuesday May 2026 — Wave 2: Hyper-V LPE, Entra ID Spoofing, Authenticator
May 2026 Patch Tuesday follow-up: 3 new CRITICAL CVEs — Hyper-V use-after-free LPE (9.3), Entra ID spoofing (9.3), Microsoft Authenticator info disclosure (9.6). Patch now.
ArchiveBox CVE-2026-42601: RCE via /add/ — No Patch Available (CVSS 9.8)
ArchiveBox ≤ 0.8.6rc0: the /add/ endpoint merges an unvalidated config JSON into plugin environment variables. Unauthenticated RCE, no official fix. Mitigation.
Angular Expressions CVE-2026-44643: Sandbox Escape → RCE (CVSS 10.0)
angular-expressions < 1.5.2: an attacker can craft a filter expression that escapes the sandbox and executes arbitrary code. CVSS 10.0, scope changed. Patch and mitigation.
Adobe Connect: 2 Critical CVEs (Deserialization + Auth Bypass) — CVE-2026-34659 & 34660
Adobe Connect ≤ 2025.9.15: deserialization of untrusted data (CVSS 9.6) + incorrect authorization (CVSS 9.3) → RCE and script injection. Patch and hardening.
PHP 8.x: 3 CRITICAL CVEs at once (PDO Firebird SQLi + 2 SOAP UAFs)
PHP 8.2.31 / 8.3.31 / 8.4.21 / 8.5.6 fix 3 CRITICAL CVEs (CVSS 9.8): PDO Firebird NUL-byte SQL injection + 2 SOAP use-after-free flaws exploitable for RCE.
OpenClaw: 3 Critical Auth Bypass CVEs in the Browser Sandbox
OpenClaw < 2026.4.15 stacks 3 CRITICAL CVEs (CVSS 9.6-9.8): exposed noVNC, Feishu webhook without validation, CDP relay on 0.0.0.0. Patch and hardening guide.
Microsoft Patch Tuesday May 2026: 4 CRITICAL CVEs (Netlogon, DNS, Dynamics, Azure)
May 2026 Patch Tuesday — 4 CRITICAL CVEs: Windows Netlogon RCE (9.8), Windows DNS RCE (9.8), Dynamics 365 code injection (9.9), Azure Logic Apps EoP (9.9).
Gotenberg CVE-2026-40281: PDF API Takeover via ExifTool Injection (CVSS 10.0)
Gotenberg ≤ 8.30.1: a newline in PDF metadata values injects ExifTool pseudo-tags — arbitrary file overwrite/symlinks in the container. CVSS 10.0, patch 8.31.0.
GitHub Enterprise Server CVE-2026-8034: SSRF via Notebook Viewer (URL Parser Confusion)
GitHub Enterprise Server < 3.21 contains an SSRF (CVSS 9.8) in the notebook viewer — URL parser confusion between validation and HTTP request. Patch and mitigation.
Chrome CVE-2026-7910: Use-After-Free in Views (Site Isolation Bypass)
Chrome < 148.0.7778.96 contains a use-after-free in Views (CVSS 9.6) allowing site isolation bypass from a compromised renderer. Urgent browser patch.
CVE-2026-34084 PhpSpreadsheet: Fixed in 5.6.0, 3.10.4, 2.4.4, 1.30.3
PhpSpreadsheet fixes 5.6.0, 3.10.4, 2.4.4, 2.1.15 and 1.30.3 for CVE-2026-34084 (CVSS 9.8): RCE via phar:// in IOFactory::load(). Detection and mitigation.
CVE-2026-0300 Palo Alto PAN-OS 10.2: Root RCE, CISA KEV, Workaround
CVE-2026-0300 (CVSS 9.8): PAN-OS 10.2 User-ID Authentication Portal buffer overflow → unauthenticated root RCE. In CISA KEV. Patch, workaround, detection.
CVE-2026-42238 Nginx UI: Fixed in 2.3.8 — Unauthenticated Root RCE
Nginx UI fix 2.3.8 for CVE-2026-42238 (CVSS 9.8): /api/restore unauthenticated for 10 min after startup → root RCE via app.ini. Detection and mitigation.
n8n CVE-2026-42233: Oracle SQL Injection via Webhook in Database Node
n8n (before 1.123.32 / 2.17.4 / 2.18.1) contains a critical SQL injection (CVSS 9.8) on the Oracle Database node select operation. Webhook-driven data exfiltration.
LiteLLM CVE-2026-42208: AI Gateway SQL Injection Added to CISA KEV
LiteLLM AI Gateway (v1.81.16 → 1.83.7) contains a critical SQL injection (CVSS 9.8) on LLM routes. API key theft, added to CISA KEV — patch urgently.
CoreDNS CVE-2026-35579: TSIG Authentication Bypass on gRPC, QUIC, DoH and DoH3
CoreDNS < 1.14.3 fails to validate the TSIG HMAC on modern transports. AXFR, DDNS and TSIG-gated plugins bypassable without a key. Patch and workaround.
WattBox 800/820 CVE-2026-41446: Diagnostic Backdoor in Plaintext on the Label
Snap One WattBox 800 and 820 (firmware < 2.10.0.0) ship with diagnostic endpoints whose auth relies on MAC + service tag — both printed on the label. Root RCE.
CVE-2026-35051 / 39858 Traefik: Fixed in 2.11.43, 3.6.14, 3.7.0-rc.2
Traefik fix 2.11.43, 3.6.14, 3.7.0-rc.2 for CVE-2026-35051 and CVE-2026-39858 (CVSS 10.0) — unauthenticated ForwardAuth bypass. IOCs and mitigation.
Totolink A8000RU: 22 Critical Command Injection CVEs in One Week
The Totolink A8000RU router stacks 22 CRITICAL CVEs (CVSS 9.8) in /cgi-bin/cstecgi.cgi command injection. All exploits public — analysis, IOCs, mitigation.
Tenda AC18 CVE-2026-31255: Unauthenticated RCE via SetSambaCfg
Tenda AC18 router v15.03.05.05 contains a critical command injection (CVSS 9.8) on /goform/SetSambaCfg. Analysis, exploitation and mitigation.
ProjeQtor CVE-2026-41462: Unauthenticated SQL Injection on Login
ProjeQtor 7.0 to 12.4.3 contains a critical SQL injection (CVSS 9.8) on the login endpoint. Privileged account creation, data theft, possible RCE.
D-Link DI-8100 CVE-2026-7248: Critical Buffer Overflow in tgfile.htm
D-Link DI-8100 firmware 16.07.26A1 contains an unauthenticated buffer overflow (CVSS 9.8) on tgfile.htm. Public PoC, analysis and mitigation.
Patch Management Guide: How to Handle CVEs Quickly and Effectively
Learn how to build a robust CVE patch management process: SLAs by severity, key steps, tools, and common mistakes to avoid to protect your infrastructure.
How to Monitor CVE Vulnerabilities Across Your IT Assets
A complete guide to tracking and managing CVEs affecting your IT infrastructure: methods, tools, and best practices for IT teams and security managers.
How to Conduct a CVE Security Audit of Your IT Infrastructure
Complete guide to conducting a CVE security audit: asset inventory, vulnerability scanning, CVSS scoring, remediation planning, and CISO best practices.
Best CVE Monitoring Tools in 2026: Full Comparison
A complete comparison of the best CVE management and monitoring tools in 2026: open-source solutions, SaaS platforms, scanners. Which tool is right for your context?
VMware vCenter & ESXi CVEs 2026: Top 8 Critical Flaws (Patch Now)
Critical VMware vCenter and ESXi CVEs exploited by ransomware gangs. Full list with CVE-2021-21985, CVE-2024-37085 — patches, IOCs and ESXiArgs protection.
Understanding the CVSS Score: How to Assess CVE Severity
The CVSS (Common Vulnerability Scoring System) score is the global standard for measuring vulnerability severity. Learn to read it in 5 minutes.
Spring4Shell CVE-2022-22965: Critical RCE in Spring Framework
Spring4Shell is a remote code execution vulnerability in Spring Framework. Analysis of CVE-2022-22965, exploitation conditions and how to protect Java applications.
ProxyLogon CVE-2021-26855: The Critical Microsoft Exchange Vulnerability
ProxyLogon is one of the most exploited Exchange vulnerabilities in history. Analysis of CVE-2021-26855, the full exploit chain and remediation steps.
PHP: Critical CVEs and Securing Your Web Applications
PHP, powering 80% of the web, concentrates critical vulnerabilities in the engine and its extensions. Analysis of major CVEs and security best practices.
Palo Alto PAN-OS: Critical CVEs and NGFW Firewall Security
PAN-OS, the operating system powering Palo Alto firewalls, is regularly hit by critical vulnerabilities. Overview of major CVEs and security best practices.
Nginx: Critical CVEs and Web Server Security
Nginx, the world's second most popular web server, is not without critical vulnerabilities. Analysis of major Nginx CVEs and a secure configuration guide.
MOVEit CVE-2023-34362: The SQL Injection That Compromised Thousands of Companies
CVE-2023-34362 is a critical SQL injection in MOVEit Transfer exploited by the Cl0p gang. Analysis of the attack, victims and security hardening measures.
Jenkins: Critical CVEs and Securing Your CI/CD Pipeline
Jenkins, the most widely used CI/CD tool, concentrates critical vulnerabilities enabling code execution and secrets access. Analysis of major CVEs and best practices.
Ivanti CVE-2024-21887: Auth Bypass + RCE Exploited by APT (Full Guide)
Complete guide to Ivanti's worst 2024 CVEs (CVE-2024-21887, CVE-2023-46805, CVE-2024-21893). Detection, IOCs, patching steps and APT exploitation timeline.
Heartbleed CVE-2014-0160: The OpenSSL Vulnerability That Shook the Internet
Heartbleed is the most famous OpenSSL vulnerability in history. Analysis of CVE-2014-0160, its impact on global HTTPS security and why it still matters today.
GitLab: Critical CVEs and Securing Your Self-Hosted Instance
Self-hosted GitLab concentrates critical vulnerabilities including RCE and account takeovers. Analysis of major CVEs and security best practices for your instance.
ProxyShell CVE-2021-34473: The Exchange RCE Chain of Summer 2021
ProxyShell is a chain of three CVEs in Microsoft Exchange enabling unauthenticated RCE. Analysis of CVE-2021-34473, CVE-2021-34523, CVE-2021-31207 and protection.
EternalBlue and MS17-010: The Vulnerability Behind WannaCry
MS17-010, the SMB vulnerability exploited by EternalBlue, is behind WannaCry and NotPetya. Technical analysis, global impact and protection measures.
Docker and Kubernetes: Critical CVEs and Container Security
Docker and Kubernetes concentrate vulnerabilities enabling container escape and cluster compromise. Analysis of major CVEs and hardening your containerized infrastructure.
Citrix Bleed (CVE-2023-4966): MFA Bypass on NetScaler — Detection & Patch
Citrix Bleed lets attackers hijack NetScaler sessions and bypass MFA. CVE-2023-4966 exploitation, IOCs, mitigation steps and patch guide for Citrix ADC/Gateway.
Atlassian Confluence: Critical CVEs and Securing Your Wiki
Confluence concentrates critical RCE vulnerabilities that are regularly exploited. Analysis of major Atlassian Confluence CVEs and protection measures for your instance.
Apache HTTP Server: Critical CVEs and Web Server Security
Apache HTTP Server concentrates critical vulnerabilities regularly exploited. Analysis of major CVEs including CVE-2021-41773, CVE-2021-42013 and security best practices.
Top 10 Critical CVEs of 2024: Vulnerabilities That Defined the Year
A look back at the 10 most critical CVEs of 2024: RCE, privilege escalations, zero-days. What security teams need to remember.
Log4Shell (CVE-2021-44228): Anatomy of the Vulnerability That Shook the Internet
CVE-2021-44228, CVSS score 10.0. Log4Shell remains one of the most exploited vulnerabilities in history. Full analysis, impact and lessons learned.
WordPress CVE: How to Monitor and Secure Your Site
WordPress concentrates thousands of CVEs every year. A complete guide to identifying vulnerabilities that affect you and setting up effective security monitoring.
FortiOS and Fortinet: Major Vulnerabilities and Security Best Practices
Fortinet appliances are ubiquitous in enterprise networks. An overview of critical FortiOS CVEs and measures to secure your infrastructure.