Cut the noise.
Know which vulnerabilities demand action.

Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.

Analytics

EPSS Trending (30d)

Threat Indicators

915
CISA KEV
266
Exploits
574
Proof-of-Concept
10.5%
Average EPSS

EPSS Hot Zone

|
Sort by:
KEV Prediction — Top%
EPSS Percentile — Top%

Emerging Vulnerabilities

08 Oct/26
CVE-2026-85097
CRITICAL

This vulnerability is an unauthenticated arbitrary file upload flaw in the Bricksforge WordPress plugin, caused by improper validation of the 'temporaryFileUploads' parameter during form submission. The root cause lies in the insufficient verification of the attacker-controlled URL field, allowing bypass of MIME type checks. The affected component is the temporary upload directory handling mechanism in Bricksforge versions up to and including 3.1.8.9.

CVSS 9.8
EPSS 0.3%
KEV Pred in 29d
Product Bricksforge bricksforge
CVSS v3.1 CWE-434
04 Oct/26
CVE-2026-88779
HIGH

This vulnerability is a stack-based buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway components. The root cause lies in improper bounds checking of input data processed by certain internal functions, leading to memory corruption. Affected versions include NetScaler ADC before 14.1-73.41, 13.1-64.28, and corresponding FIPS releases, as well as NetScaler Gateway before 14.1-73.41 and 13.1-64.28.

CVSS 8.7
EPSS 0.6%
KEV Pred in 25d
Product NetScaler ADC netscaler
CVSS v4.0 KEV CWE-119
01 Oct/26
CVE-2026-104286
CRITICAL

This vulnerability is a path traversal flaw caused by improper validation of pathname inputs within Fortinet FortiMail. The affected component fails to restrict access to directories, allowing crafted HTTP or HTTPS requests to manipulate file paths beyond intended boundaries. This weakness exists in FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1, specifically in the web interface handling of file operations.

CVSS 9.8
EPSS 2.2%
KEV Pred in 23d
Product Fortinet FortiMail fortinet
CVSS v3.1 KEV CWE-22 PoC RANSOMWARE
30 Sep/26
CVE-2026-102490
CRITICAL

The vulnerability is a privilege escalation flaw rooted in improper permission handling within Zammad's local user management. Specifically, the local 'zammad' user account is able to escalate privileges to root due to insufficient access control enforcement in the underlying privilege separation mechanism. This affects all versions of the Zammad application, including the latest alpha releases, impacting the system's user privilege boundary.

CVSS 9.8
EPSS 0.6%
KEV Pred in 21d
Product Zammad GmbH Zammad zammad
CVSS v3.1 CVSS v4.0 KEV CWE-269
30 Sep/26
CVE-2026-102489
CRITICAL

This vulnerability is a session hijacking flaw rooted in improper session management within Zammad's authentication mechanism. The affected component fails to adequately validate or isolate session tokens, allowing unauthorized users to assume the identity of legitimate sessions. The flaw exists in the session handling logic of Zammad versions 6.3.0 through 6.5.4 and partially in versions 7.0.0 to 7.1.3 under specific environmental conditions.

CVSS 9.8
EPSS 1.3%
KEV Pred in 21d
Product Zammad GmbH Zammad zammad
CVSS v3.1 CVSS v4.0 KEV CWE-384 PoC
30 Sep/26
CVE-2026-76504
CRITICAL

This vulnerability is an authentication bypass caused by improper URI encoding handling within the HTTP request processing of Cisco Catalyst SD-WAN Manager's API session-based authentication management. The flaw resides in the API endpoint access control mechanism, where crafted HTTP requests with encoded URIs bypass authentication rules intended to restrict access. The affected component is the API authentication logic of Cisco Catalyst SD-WAN Manager.

CVSS 9.8
EPSS 1.8%
KEV Pred in 21d
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-177 PoC RANSOMWARE
28 Sep/26
CVE-2026-86950
HIGH

This vulnerability is an out-of-bounds write flaw caused by improper bounds checking during file processing in Apple iOS and iPadOS. The root cause lies in the failure to correctly validate input size or index values, leading to memory corruption. The affected components are the file parsing routines within the operating system's media or document handling subsystems.

CVSS 8.8
EPSS 1.2%
KEV Pred in 20d
Product Apple iOS and iPadOS apple
CVSS v3.1 KEV CWE-787 PoC
27 Sep/26
CVE-2026-88772
CRITICAL

This vulnerability is a memory corruption issue classified under CWE-119, specifically a buffer overflow within Citrix NetScaler ADC and Gateway components. The root cause lies in improper handling of input data in certain network protocol processing routines, leading to unsafe memory operations. Affected versions include multiple releases prior to 14.1-73.37 and 13.1-64.23, impacting both standard and FIPS/NDcPP builds of the ADC and Gateway.

CVSS 9.5
EPSS 1.3%
KEV Pred in 18d
Product Citrix NetScaler ADC citrix
CVSS v4.0 KEV CWE-119 PoC
27 Sep/26
CVE-2026-88771
CRITICAL

This vulnerability is an improper input validation flaw in Citrix NetScaler ADC and Gateway components. The root cause lies in insufficient sanitization of user-supplied input within specific request handling routines, allowing malicious data to bypass validation checks. Affected components include NetScaler ADC versions prior to 14.1-73.37 and 13.1-64.23, including FIPS and NDcPP variants, as well as NetScaler Gateway versions before 14.1-73.37 and 13.1-64.23.

CVSS 9.5
EPSS 1.1%
KEV Pred in 18d
Product Citrix NetScaler ADC citrix
CVSS v4.0 KEV CWE-20 PoC
22 Sep/26
CVE-2026-87902
HIGH

This vulnerability is a local file inclusion (LFI) flaw rooted in improper validation of file paths within the WordPress function get_page_template(). The function incorrectly resolves page templates by allowing inclusion of arbitrary readable .php files outside the active theme directories. This occurs due to insufficient restrictions on file path inputs used in template resolution logic, affecting the WordPress theme handling component.

CVSS 8.1
EPSS 40.0%
KEV Pred in 13d
Product WordPress wordpress
CVSS v3.1 KEV CWE-98 PoC
22 Sep/26
CVE-2026-94127
CRITICAL

This vulnerability is a heap-based buffer overflow (CWE-122) in the F5 BIG-IP Access Policy Manager (APM) component when configured as an OAuth Authorization Server. The flaw arises from improper handling of specific OAuth profile inputs within the virtual server's access policy, allowing crafted malicious traffic to corrupt memory. The issue affects the data plane processing path of BIG-IP APM when OAuth authorization server profiles are active, leading to uncontrolled execution flow.

CVSS 9.8
EPSS 2.2%
KEV Pred in 13d
Product F5 BIG-IP f5
CVSS v3.1 CVSS v4.0 KEV CWE-122 PoC
22 Sep/26
CVE-2026-93616
CRITICAL

This vulnerability is a directory traversal and file upload flaw in Check Point Quantum Security Management. It arises from insufficient input validation in the file upload functionality, allowing unauthorized manipulation of file paths. The affected component is the Check Point Management Server's file handling mechanism, which fails to restrict user-supplied file paths, enabling arbitrary file placement on the server.

CVSS 9.8
EPSS 19.7%
KEV Pred in 13d
Product checkpoint Quantum Security Management checkpoint
CVSS v3.1 KEV CWE-22 PoC
22 Sep/26
CVE-2026-93952
CRITICAL

This vulnerability in Arista Networks VeloCloud Orchestrator (VCO) On-Prem is a logic validation flaw classified under CWE-20 (Improper Input Validation). The root cause is inadequate validation of remote requests targeting privileged internal functions within the orchestrator's management interface. The affected component is the VCO on-premises orchestration platform, which processes unauthenticated network requests allowing unauthorized access to sensitive functionality.

CVSS 10.0
EPSS 1.1%
KEV Pred in 13d
Product Arista Networks VeloCloud Orchestrator (VCO) On-Prem arista
CVSS v3.1 CVSS v4.0 KEV CWE-20
19 Sep/26
CVE-2026-84434
CRITICAL

This vulnerability is an arbitrary file upload flaw arising from inconsistent validation logic within the Gravity Forms WordPress plugin. Specifically, the upload_file function processes files without re-validating extensions when uploaded via hidden file upload fields, allowing bypass of the extension validation pipeline. The affected component is the File Upload field feature configured with Visibility set to 'Hidden' in Gravity Forms versions up to and including 3.1.0.4.

CVSS 9.8
EPSS 3.9%
KEV Pred in 10d
Product Gravity Forms gravity
CVSS v3.1 CWE-434 PoC
16 Sep/26
CVE-2026-76460
CRITICAL

This vulnerability is an authentication bypass caused by insufficient authentication controls on a specific API endpoint within Cisco Identity Services Engine (ISE) Software. The root cause lies in the failure to enforce proper authentication checks on the affected API, allowing unauthenticated access. The flaw specifically impacts the web-based management interface component of Cisco ISE, enabling unauthorized interactions with its API endpoints.

CVSS 10.0
EPSS 14.0%
KEV Pred in 8d
Product Cisco Identity Services Engine Software cisco
CVSS v3.1 KEV CWE-648 PoC RANSOMWARE
15 Sep/26
CVE-2026-58704
HIGH

This vulnerability is a permission bypass caused by a logic error within the Cellular Modem component of Google Android. The flaw arises from improper enforcement of access control checks, allowing unauthorized operations to proceed. The affected code fails to correctly validate permissions, leading to an escalation of privilege without requiring additional execution rights.

CVSS 8.8
EPSS 0.6%
KEV Pred in 7d
Product Google Android google
CVSS v3.1 KEV CWE-285
15 Sep/26
CVE-2026-89026
CRITICAL

This vulnerability is an authentication bypass caused by a hard-coded HS256 JWT signing key embedded in the pbxapi index.php file of the Issabel Framework. The root cause is the use of a static, identical JWT secret across all installations, which compromises token integrity verification. The affected component is the JWT authentication mechanism within the Issabel Framework's pbxapi endpoint.

CVSS 9.8
EPSS 0.7%
KEV Pred in 6d
Product Issabel Foundation Issabel Framework issabel
CVSS v3.1 CVSS v4.0 CWE-321 PoC
14 Sep/26
CVE-2026-76461
CRITICAL

This vulnerability is a command injection flaw rooted in improper input validation within the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. The affected component fails to sanitize crafted email messages containing malicious SQL statements, allowing arbitrary command execution at the operating system level. The issue specifically arises from insufficient validation in the email parsing mechanism that processes incoming email content.

CVSS 9.8
EPSS 28.3%
KEV Pred in 5d
Product Cisco Secure Email cisco
CVSS v3.1 KEV CWE-89 PoC RANSOMWARE
12 Sep/26
CVE-2026-78159
CRITICAL

This vulnerability is a remote code execution flaw caused by insufficient validation of the widget 'classes' map in the The Events Calendar WordPress plugin. The root cause lies in the parse_array function within the Element_Classes component, where a plain-array payload can bypass the is_safe_widget_instance() object check. This improper input handling in the widget classes feature enables unauthorized code execution.

CVSS 9.8
EPSS 1.4%
KEV Pred in 3d
Product stellarwp The Events Calendar stellarwp
CVSS v3.1 CWE-94 PoC
12 Sep/26
CVE-2026-78006
CRITICAL

This vulnerability is a remote code execution flaw caused by unsafe deserialization within the is_safe_widget_instance function of the The Events Calendar WordPress plugin. The root cause lies in insufficient validation allowing bypass of protection mechanisms due to PHP magic methods triggering during pre-parse combined with forged wp_hash integrity attributes before unserialize() is invoked. The affected component is the plugin's widget rendering logic, specifically in versions up to and including 6.17.4.

CVSS 9.8
EPSS 1.5%
KEV Pred in 3d
Product stellarwp The Events Calendar stellarwp
CVSS v3.1 CWE-502 PoC
12 Sep/26
CVE-2026-85706
CRITICAL

This vulnerability is a directory traversal flaw caused by improper path confinement and lack of authentication enforcement within the GitLab repository commits API. The root cause lies in the API's failure to validate and restrict file path inputs, allowing unauthorized access to files outside intended directories. The affected component is the repository commits API in GitLab Community and Enterprise Editions across multiple versions prior to specific patch releases.

CVSS 10.0
EPSS 93.0%
KEV Pred in 3d
Product GitLab gitlab
CVSS v3.1 KEV CWE-22 Exploit PoC
11 Sep/26
CVE-2026-89013
HIGH

This vulnerability is an authorization bypass affecting Dolibarr's document management components. The root cause lies in insufficient validation of the 'hashp' parameter within the document storage endpoints, specifically in htdocs/document.php and htdocs/viewimage.php. The application incorrectly allows bypassing token-based authorization checks when the 'hashp' parameter is set to a crafted value, enabling unauthorized access to protected resources.

CVSS 7.5
EPSS 1.6%
KEV Pred in 2d
Product Dolibarr dolibarr
CVSS v3.1 CVSS v4.0 CWE-863 PoC
09 Sep/26
CVE-2026-85102
CRITICAL

This vulnerability is an improper certificate trust validation flaw within the VPN negotiation process of Check Point Quantum Security Gateway. The root cause is the failure to correctly verify the authenticity of certificates presented during the VPN handshake, allowing acceptance of malicious or forged certificates. The affected component is the VPN negotiation module responsible for establishing secure tunnels between endpoints.

CVSS 9.8
EPSS 7.5%
KEV Pred N/A
Product checkpoint Quantum Security Gateway checkpoint
CVSS v3.1 KEV CWE-295 PoC
09 Sep/26
CVE-2026-87827
CRITICAL

The vulnerability is a remote unauthenticated system command execution flaw caused by a service in KGUARD DVR firmware that exposes a command execution interface on all network interfaces (0.0.0.0) without authentication. The root cause lies in the firmware's failure to restrict access to this service, allowing network access to execute arbitrary system commands. The affected component is the system command execution service embedded in the vulnerable KGUARD DVR firmware versions prior to 2017.

CVSS 10.0
EPSS 1.1%
KEV Pred N/A
Product KGUARD_firmware kguard_firmware
CVSS v4.0 CWE-1188
09 Sep/26
CVE-2026-80099
HIGH

This vulnerability is an authentication bypass caused by improper validation in the wp-module-data component bundled within several Newfold WordPress plugins. The root cause lies in the authenticate() method hooked to the rest_authentication_errors filter, which performs an HMAC-style Bearer token comparison that fails when HiiveConnection::get_auth_token() returns false. This results in the secret salt collapsing to a constant hash, allowing attacker-controlled inputs to pass authentication checks.

CVSS 8.8
EPSS 2.9%
KEV Pred N/A
Product Newfold WP Plugin Web newfold
CVSS v3.1 CWE-287 PoC
09 Sep/26
CVE-2026-87491
HIGH

This vulnerability is an out-of-bounds write (CWE-787) occurring within the V8 JavaScript engine component of Google Chrome. The root cause is improper bounds checking during memory operations in V8's handling of crafted JavaScript code, leading to memory corruption. The flaw specifically affects versions of Google Chrome prior to 153.0.8010.36, compromising the integrity of the V8 sandbox environment.

CVSS 8.8
EPSS 3.1%
KEV Pred 81%
Product Google Chrome google
CVSS v3.1 KEV CWE-787 PoC
08 Sep/26
CVE-2026-84869
CRITICAL

The vulnerability is an authorization bypass in the ConnectWise ScreenConnect client component that improperly controls file transfer and execution permissions during active remote sessions. The root cause lies in insufficient validation of user privileges and session state, allowing unauthorized file operations without host confirmation. This flaw specifically affects the client-side session management feature responsible for handling remote file transfers and execution commands.

CVSS 9.9
EPSS 0.9%
KEV Pred 73%
Product ConnectWise ScreenConnect connectwise
CVSS v3.1 KEV CWE-269 RANSOMWARE
07 Sep/26
CVE-2026-86538
HIGH

This vulnerability is a path traversal flaw rooted in insufficient validation of user-supplied input within the knowns-dev knowns application. Specifically, the POST /api/templates/preview endpoint fails to properly sanitize the templateFile parameter, allowing directory traversal sequences to bypass intended path restrictions. The affected component is the template preview API handler responsible for processing file paths used in template rendering.

CVSS 7.5
EPSS 1.0%
KEV Pred 84%
Product knowns-dev knowns knowns-dev
CVSS v3.1 CVSS v4.0 CWE-22
07 Sep/26
CVE-2026-75650
CRITICAL

This vulnerability is an improper neutralization of special elements within the template engine of Adobe Commerce. The root cause lies in insufficient sanitization of user-controllable input embedded in templates, allowing injection of malicious code. The affected component is the template processing mechanism responsible for rendering dynamic content in Adobe Commerce versions including 2.4.4 and its patches.

CVSS 10.0
EPSS 3.9%
KEV Pred 84%
Product Adobe Commerce adobe
CVSS v3.1 KEV CWE-1336 PoC RANSOMWARE
06 Sep/26
CVE-2026-86218
CRITICAL

The vulnerability is a pre-authentication remote code execution caused by improper handling of input data within N-able N-central. The root cause lies in the unsafe processing of commands or scripts in a component responsible for handling unauthenticated requests, allowing arbitrary code execution. This flaw affects N-central versions prior to 2026.3.1.14, specifically within the core service that processes external input without sufficient validation or sanitization.

CVSS 9.8
EPSS 12.9%
KEV Pred 81%
Product N-able N-central n-able
CVSS v3.1 CVSS v4.0 KEV CWE-96 Exploit PoC
05 Sep/26
CVE-2026-86060
CRITICAL

This vulnerability is a privilege escalation flaw caused by improper argument handling in the SSH login process of Mikrotik RouterOS. Specifically, usernames beginning with a prohibited character bypass input validation, allowing unauthorized modification of the trusted RouterOS policy mask. The affected component is the RouterOS SSH login helper, which processes authentication requests without sufficient sanitization of username parameters.

CVSS 9.8
EPSS 6.4%
KEV Pred 84%
Product Mikrotik RouterOS mikrotik
CVSS v3.1 CVSS v4.0 KEV CWE-88 PoC
05 Sep/26
CVE-2026-67279
MEDIUM

This vulnerability is an authentication bypass in the SSH protocol implementation of Mikrotik RouterOS. The root cause is that after a client requests a rekey operation, the server transitions into the connection protocol phase without verifying user authentication. This flaw affects the SSH server component responsible for managing session channels and command dispatching within RouterOS.

CVSS 6.5
EPSS 1.0%
KEV Pred 81%
Product Mikrotik RouterOS mikrotik
CVSS v3.1 CVSS v4.0 KEV CWE-841 PoC
05 Sep/26
CVE-2026-67277
HIGH

This vulnerability is an authentication bypass in Mikrotik RouterOS's IPv4 UDP testing feature. The root cause lies in the acceptance of a "related" btest connection before the primary session completes authentication, allowing unauthenticated clients to initiate tests. Additionally, improper handling of packet size intervals leads to unsigned integer underflow and kernel packet buffer misuse, affecting the RouterOS kernel's network packet processing component.

CVSS 8.2
EPSS 1.6%
KEV Pred 81%
Product Mikrotik RouterOS mikrotik
CVSS v3.1 CVSS v4.0 KEV CWE-306
05 Sep/26
CVE-2026-86124
CRITICAL

The vulnerability is an unauthenticated remote code execution flaw rooted in the TCP server component of HKUDS AutoAgent. The TCP server binds to all network interfaces and improperly handles incoming connections without authentication, allowing execution of attacker-supplied commands. This occurs due to insufficient access control in the command execution logic within the containerized environment.

CVSS 9.8
EPSS 1.0%
KEV Pred 82%
Product HKUDS AutoAgent hkuds
CVSS v3.1 CVSS v4.0 CWE-306
03 Sep/26
CVE-2026-85046
HIGH

This vulnerability is a type confusion flaw located within the V8 JavaScript engine component of Google Chrome. The root cause stems from improper handling of object types in memory, leading to incorrect assumptions about data structures. This flaw affects V8's internal type system prior to version 152.0.7977.82, allowing crafted input to manipulate memory layout inconsistently.

CVSS 8.8
EPSS 48.9%
KEV Pred 79%
Product Google Chrome google
CVSS v3.1 KEV CWE-843 PoC
02 Sep/26
CVE-2026-9055
CRITICAL

This is a privilege escalation flaw rooted in missing authorization checks on the customer update endpoint of the Amelia booking plugin for WordPress. The endpoint accepts an attacker-controlled 'type' parameter and uses it to assign the caller's role without verifying that the caller is entitled to that role. A second defect compounds it: passing 'externalId' as 0 makes the plugin provision a new WordPress user carrying the wpamelia-manager role instead of linking to an existing account.

CVSS 9.8
EPSS 0.5%
KEV Pred 70%
Product melograno Booking for Appointments and Events Calendar – Amelia melograno
CVSS v3.1 CWE-269 PoC
01 Sep/26
CVE-2026-83548
CRITICAL

The SMA1000 Work Place interface exposes an unintended alternate access path that reaches internal request-handling functionality before authentication is enforced. Because the appliance treats this path as trusted, the server can be induced to issue requests on the attacker's behalf, which is the classic Server-Side Request Forgery pattern. The flaw sits in the pre-auth surface of the appliance, so no session or credential material is involved in reaching the vulnerable code.

CVSS 10.0
EPSS 8.8%
KEV Pred 78%
Product SonicWall SMA1000 sonicwall
CVSS v3.1 KEV CWE-441 Exploit PoC RANSOMWARE
31 Aug/26
CVE-2026-82970
CRITICAL

The WP Cookie Notice for GDPR, CCPA and ePrivacy Consent plugin accepts file uploads without restricting the file type to a safe allowlist. Uploaded content lands in a location served by the web server, so a file carrying a PHP extension is interpreted rather than stored inert. The defect is in the upload handler itself, which validates neither the extension nor the resulting MIME type before writing the file to disk.

CVSS 10.0
EPSS 0.5%
KEV Pred 92%
Product WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent wp
CVSS v3.1 CWE-434
28 Aug/26
CVE-2026-82329
CRITICAL

JFrog Artifactory ships a default configuration in which the authentication layer accepts material that should never be trusted from the network. Public analysis of the patch describes a phantom join key: an attacker-supplied value that the server accepts when validating a URL parameter, allowing a service admin token to be forged rather than issued. The weakness is in the identity verification path itself, not in any single API handler.

CVSS 9.8
EPSS 14.1%
KEV Pred 81%
Product jfrog artifactory jfrog
CVSS v3.1 KEV CWE-287 PoC
28 Aug/26
CVE-2026-82078
CRITICAL

This vulnerability is a dynamic class loading flaw in PaperCut MF and NG's database connection utilities. The root cause is the application's instantiation of database driver classes based on configurable driver names without validating these against an allowlist of approved drivers. This unsafe dynamic loading occurs within the database connection component, enabling untrusted class loading from the application classpath.

CVSS 9.1
EPSS 63.5%
KEV Pred 77%
Product PaperCut MF/NG papercut
CVSS v3.1 CVSS v4.0 KEV CWE-470 Exploit RANSOMWARE
28 Aug/26
CVE-2026-81578
CRITICAL

This vulnerability is an improper access control flaw in the web management interface of PaperCut MF and PaperCut NG. The root cause is the premature execution of backend administrative functions before completing access validation checks. This affects the administrative web interface component responsible for enforcing authentication and authorization controls on remote requests.

CVSS 9.8
EPSS 85.6%
KEV Pred 83%
Product PaperCut MF/NG papercut
CVSS v3.1 CVSS v4.0 KEV CWE-305 Exploit PoC RANSOMWARE
28 Aug/26
CVE-2026-76581
CRITICAL

The WPMU DEV Dashboard plugin builds its HMAC message by concatenating token, state, redirect and domain values without a separator, and the two sides of the SSO handshake disagree on which fields belong in that string. The unauthenticated wdpsso_step1 action signs and returns a concatenation of all four values, while wdpsso_step2 verifies a concatenation that omits the domain field. Because no delimiter separates the fields, the boundary between redirect and domain is ambiguous to the verifier.

CVSS 9.8
EPSS 0.4%
KEV Pred 81%
Product wpmudev WPMU DEV Dashboard wpmudev
CVSS v3.1 CWE-347 PoC
27 Aug/26
CVE-2026-74233
CRITICAL

The infosrvd service on Zbtlink routers listens on UDP/9992 and passes attacker-supplied data into a shell context without sanitization, yielding command injection. The service does implement an authentication step, but it is ineffective by construction: the scheme relies on a hardcoded salt shipped in the firmware, and an all-zero MAC address is accepted as a wildcard that matches any device. The two defects combine so that the authentication check can be satisfied by anyone who has read the firmware.

CVSS 9.8
EPSS 3.4%
KEV Pred 80%
Product Zbtlink WE1326 zbtlink
CVSS v3.1 CVSS v4.0 CWE-78
26 Aug/26
CVE-2026-60004
CRITICAL

This vulnerability is a code injection flaw rooted in improper validation of input passed to the diffpatch API within Gitea's Git hook installation process. The affected component is the diffpatch API endpoint, which processes patch data without sufficient sanitization, enabling execution of arbitrary code via crafted input. The issue arises from the unsafe handling of patch content that is integrated into Git hooks, leading to command execution capability embedded in the repository management workflow.

CVSS 9.8
EPSS 24.0%
KEV Pred 80%
Product Gitea gitea
CVSS v3.1 KEV CWE-94 PoC
25 Aug/26
CVE-2026-77136
CRITICAL

The TYPO3 powermail extension takes the raw value of the form field designated as sender_name and hands it to a Fluid View as template source, then renders it. Because the value is treated as template code rather than as data, submitted Fluid syntax is parsed and its ViewHelpers are invoked. This is server-side template injection: the boundary between user input and template is absent, and no sanitization runs before rendering.

CVSS 9.5
EPSS 1.0%
KEV Pred 71%
Product TYPO3 Extension "powermail" typo3
CVSS v4.0 CWE-1336
21 Aug/26
CVE-2026-76904
CRITICAL

This vulnerability is a SQL Injection flaw caused by improper sanitization of input parameters within the GeoTools Java library. Specifically, the PostGIS DataStore implementation's `jsonArrayContains` function constructs SQL queries by directly embedding the `<value>` parameter without escaping, affecting versions 30.5 and earlier up to 33.6 and 34.5. The root cause lies in unsafe query generation when handling String or JSON fields in PostGIS 12 or greater environments.

CVSS 9.8
EPSS 4.0%
KEV Pred 83%
Product geotools geotools
CVSS v3.1 CWE-89 PoC
21 Aug/26
CVE-2026-77806
CRITICAL

This vulnerability is a code injection flaw rooted in improper handling of user-supplied input within the SPIP content management system. Specifically, the analyse_resultat_skel function fails to sanitize the X-Spip-Filtre HTTP request header, allowing arbitrary code to be injected and executed. The flaw affects SPIP versions prior to 4.4.21 and involves the HTTP header processing mechanism.

CVSS 9.8
EPSS 4.5%
KEV Pred 83%
Product SPIP spip
CVSS v3.1 CWE-94 PoC
20 Aug/26
CVE-2026-77647
CRITICAL

This vulnerability is a remote code execution flaw caused by improper handling of PHP code blocks within SPIP versions prior to 4.4.20. The root cause lies in incorrect parsing and identification of '<?php' tags combined with var_export's faulty processing of strings containing the '<' character. This parsing error occurs in the code serialization component responsible for exporting PHP variables, leading to unsafe code injection opportunities.

CVSS 9.8
EPSS 2.3%
KEV Pred 84%
Product SPIP spip
CVSS v3.1 CWE-94 Exploit
20 Aug/26
CVE-2026-69836
CRITICAL

This vulnerability is a deserialization flaw in Microsoft Entra ID, where untrusted serialized data is processed insecurely. The root cause lies in improper validation and handling of serialized objects during deserialization, allowing malicious input to be interpreted as executable code. The affected component is the deserialization mechanism within Microsoft Entra ID's authentication or identity management services.

CVSS 10.0
EPSS 1.5%
KEV Pred 81%
Product Microsoft Entra microsoft
CVSS v3.1 CWE-502 PoC RANSOMWARE
19 Aug/26
CVE-2026-72530
CRITICAL

This vulnerability is a code injection flaw classified under CWE-94, caused by improper handling of user-supplied scripts within the TrueConf Server isolated environment. The root cause lies in insufficient validation and sanitization of input scripts processed on port 4307/TCP, allowing crafted payloads to escape sandbox restrictions. The affected component is the script execution environment in TrueConf Server versions 5.3.x through 5.5.5 on Windows and Linux platforms.

CVSS 9.0
EPSS 1.7%
KEV Pred 83%
Product TrueConf Server trueconf
CVSS v3.1 CVSS v4.0 KEV CWE-94 PoC
Page 1 of 19 (947 total)