Cut the noise.
Know which vulnerabilities demand action.

Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.

Analytics

EPSS Trending (30d)

Threat Indicators

915
CISA KEV
266
Exploits
574
Proof-of-Concept
16.9%
Average EPSS

EPSS Hot Zone

|
Sort by:
KEV Prediction — Top%
EPSS Percentile — Top%

Emerging Vulnerabilities

01 Oct/26
CVE-2026-104286
CRITICAL

This vulnerability is a path traversal flaw caused by improper validation of pathname inputs within Fortinet FortiMail. The affected component fails to restrict access to directories, allowing crafted HTTP or HTTPS requests to manipulate file paths beyond intended boundaries. This weakness exists in FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1, specifically in the web interface handling of file operations.

CVSS 9.8
EPSS 2.2%
KEV Pred in 22d
Product Fortinet FortiMail fortinet
CVSS v3.1 KEV CWE-22 PoC RANSOMWARE
30 Sep/26
CVE-2026-102489
CRITICAL

This vulnerability is a session hijacking flaw rooted in improper session management within Zammad's authentication mechanism. The affected component fails to adequately validate or isolate session tokens, allowing unauthorized users to assume the identity of legitimate sessions. The flaw exists in the session handling logic of Zammad versions 6.3.0 through 6.5.4 and partially in versions 7.0.0 to 7.1.3 under specific environmental conditions.

CVSS 9.8
EPSS 1.3%
KEV Pred in 21d
Product Zammad GmbH Zammad zammad
CVSS v3.1 CVSS v4.0 KEV CWE-384 PoC
30 Sep/26
CVE-2026-76504
CRITICAL

This vulnerability is an authentication bypass caused by improper URI encoding handling within the HTTP request processing of Cisco Catalyst SD-WAN Manager's API session-based authentication management. The flaw resides in the API endpoint access control mechanism, where crafted HTTP requests with encoded URIs bypass authentication rules intended to restrict access. The affected component is the API authentication logic of Cisco Catalyst SD-WAN Manager.

CVSS 9.8
EPSS 1.8%
KEV Pred in 21d
Product Cisco Catalyst SD-WAN Manager cisco
CVSS v3.1 KEV CWE-177 PoC RANSOMWARE
28 Sep/26
CVE-2026-86950
HIGH

This vulnerability is an out-of-bounds write flaw caused by improper bounds checking during file processing in Apple iOS and iPadOS. The root cause lies in the failure to correctly validate input size or index values, leading to memory corruption. The affected components are the file parsing routines within the operating system's media or document handling subsystems.

CVSS 8.8
EPSS 1.2%
KEV Pred in 19d
Product Apple iOS and iPadOS apple
CVSS v3.1 KEV CWE-787 PoC
27 Sep/26
CVE-2026-88772
CRITICAL

This vulnerability is a memory corruption issue classified under CWE-119, specifically a buffer overflow within Citrix NetScaler ADC and Gateway components. The root cause lies in improper handling of input data in certain network protocol processing routines, leading to unsafe memory operations. Affected versions include multiple releases prior to 14.1-73.37 and 13.1-64.23, impacting both standard and FIPS/NDcPP builds of the ADC and Gateway.

CVSS 9.5
EPSS 1.3%
KEV Pred in 18d
Product Citrix NetScaler ADC citrix
CVSS v4.0 KEV CWE-119 PoC
27 Sep/26
CVE-2026-88771
CRITICAL

This vulnerability is an improper input validation flaw in Citrix NetScaler ADC and Gateway components. The root cause lies in insufficient sanitization of user-supplied input within specific request handling routines, allowing malicious data to bypass validation checks. Affected components include NetScaler ADC versions prior to 14.1-73.37 and 13.1-64.23, including FIPS and NDcPP variants, as well as NetScaler Gateway versions before 14.1-73.37 and 13.1-64.23.

CVSS 9.5
EPSS 1.1%
KEV Pred in 18d
Product Citrix NetScaler ADC citrix
CVSS v4.0 KEV CWE-20 PoC
22 Sep/26
CVE-2026-87902
HIGH

This vulnerability is a local file inclusion (LFI) flaw rooted in improper validation of file paths within the WordPress function get_page_template(). The function incorrectly resolves page templates by allowing inclusion of arbitrary readable .php files outside the active theme directories. This occurs due to insufficient restrictions on file path inputs used in template resolution logic, affecting the WordPress theme handling component.

CVSS 8.1
EPSS 40.0%
KEV Pred in 13d
Product WordPress wordpress
CVSS v3.1 KEV CWE-98 PoC
22 Sep/26
CVE-2026-94127
CRITICAL

This vulnerability is a heap-based buffer overflow (CWE-122) in the F5 BIG-IP Access Policy Manager (APM) component when configured as an OAuth Authorization Server. The flaw arises from improper handling of specific OAuth profile inputs within the virtual server's access policy, allowing crafted malicious traffic to corrupt memory. The issue affects the data plane processing path of BIG-IP APM when OAuth authorization server profiles are active, leading to uncontrolled execution flow.

CVSS 9.8
EPSS 2.2%
KEV Pred in 13d
Product F5 BIG-IP f5
CVSS v3.1 CVSS v4.0 KEV CWE-122 PoC
22 Sep/26
CVE-2026-93616
CRITICAL

This vulnerability is a directory traversal and file upload flaw in Check Point Quantum Security Management. It arises from insufficient input validation in the file upload functionality, allowing unauthorized manipulation of file paths. The affected component is the Check Point Management Server's file handling mechanism, which fails to restrict user-supplied file paths, enabling arbitrary file placement on the server.

CVSS 9.8
EPSS 19.7%
KEV Pred in 13d
Product checkpoint Quantum Security Management checkpoint
CVSS v3.1 KEV CWE-22 PoC
19 Sep/26
CVE-2026-84434
CRITICAL

This vulnerability is an arbitrary file upload flaw arising from inconsistent validation logic within the Gravity Forms WordPress plugin. Specifically, the upload_file function processes files without re-validating extensions when uploaded via hidden file upload fields, allowing bypass of the extension validation pipeline. The affected component is the File Upload field feature configured with Visibility set to 'Hidden' in Gravity Forms versions up to and including 3.1.0.4.

CVSS 9.8
EPSS 3.9%
KEV Pred in 10d
Product Gravity Forms gravity
CVSS v3.1 CWE-434 PoC
16 Sep/26
CVE-2026-76460
CRITICAL

This vulnerability is an authentication bypass caused by insufficient authentication controls on a specific API endpoint within Cisco Identity Services Engine (ISE) Software. The root cause lies in the failure to enforce proper authentication checks on the affected API, allowing unauthenticated access. The flaw specifically impacts the web-based management interface component of Cisco ISE, enabling unauthorized interactions with its API endpoints.

CVSS 10.0
EPSS 14.0%
KEV Pred in 8d
Product Cisco Identity Services Engine Software cisco
CVSS v3.1 KEV CWE-648 PoC RANSOMWARE
15 Sep/26
CVE-2026-89026
CRITICAL

This vulnerability is an authentication bypass caused by a hard-coded HS256 JWT signing key embedded in the pbxapi index.php file of the Issabel Framework. The root cause is the use of a static, identical JWT secret across all installations, which compromises token integrity verification. The affected component is the JWT authentication mechanism within the Issabel Framework's pbxapi endpoint.

CVSS 9.8
EPSS 0.7%
KEV Pred in 6d
Product Issabel Foundation Issabel Framework issabel
CVSS v3.1 CVSS v4.0 CWE-321 PoC
14 Sep/26
CVE-2026-76461
CRITICAL

This vulnerability is a command injection flaw rooted in improper input validation within the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. The affected component fails to sanitize crafted email messages containing malicious SQL statements, allowing arbitrary command execution at the operating system level. The issue specifically arises from insufficient validation in the email parsing mechanism that processes incoming email content.

CVSS 9.8
EPSS 28.3%
KEV Pred in 5d
Product Cisco Secure Email cisco
CVSS v3.1 KEV CWE-89 PoC RANSOMWARE
12 Sep/26
CVE-2026-78159
CRITICAL

This vulnerability is a remote code execution flaw caused by insufficient validation of the widget 'classes' map in the The Events Calendar WordPress plugin. The root cause lies in the parse_array function within the Element_Classes component, where a plain-array payload can bypass the is_safe_widget_instance() object check. This improper input handling in the widget classes feature enables unauthorized code execution.

CVSS 9.8
EPSS 1.4%
KEV Pred in 3d
Product stellarwp The Events Calendar stellarwp
CVSS v3.1 CWE-94 PoC
12 Sep/26
CVE-2026-78006
CRITICAL

This vulnerability is a remote code execution flaw caused by unsafe deserialization within the is_safe_widget_instance function of the The Events Calendar WordPress plugin. The root cause lies in insufficient validation allowing bypass of protection mechanisms due to PHP magic methods triggering during pre-parse combined with forged wp_hash integrity attributes before unserialize() is invoked. The affected component is the plugin's widget rendering logic, specifically in versions up to and including 6.17.4.

CVSS 9.8
EPSS 1.5%
KEV Pred in 3d
Product stellarwp The Events Calendar stellarwp
CVSS v3.1 CWE-502 PoC
12 Sep/26
CVE-2026-85706
CRITICAL

This vulnerability is a directory traversal flaw caused by improper path confinement and lack of authentication enforcement within the GitLab repository commits API. The root cause lies in the API's failure to validate and restrict file path inputs, allowing unauthorized access to files outside intended directories. The affected component is the repository commits API in GitLab Community and Enterprise Editions across multiple versions prior to specific patch releases.

CVSS 10.0
EPSS 93.0%
KEV Pred in 3d
Product GitLab gitlab
CVSS v3.1 KEV CWE-22 Exploit PoC
11 Sep/26
CVE-2026-89013
HIGH

This vulnerability is an authorization bypass affecting Dolibarr's document management components. The root cause lies in insufficient validation of the 'hashp' parameter within the document storage endpoints, specifically in htdocs/document.php and htdocs/viewimage.php. The application incorrectly allows bypassing token-based authorization checks when the 'hashp' parameter is set to a crafted value, enabling unauthorized access to protected resources.

CVSS 7.5
EPSS 1.6%
KEV Pred in 2d
Product Dolibarr dolibarr
CVSS v3.1 CVSS v4.0 CWE-863 PoC
09 Sep/26
CVE-2026-85102
CRITICAL

This vulnerability is an improper certificate trust validation flaw within the VPN negotiation process of Check Point Quantum Security Gateway. The root cause is the failure to correctly verify the authenticity of certificates presented during the VPN handshake, allowing acceptance of malicious or forged certificates. The affected component is the VPN negotiation module responsible for establishing secure tunnels between endpoints.

CVSS 9.8
EPSS 7.5%
KEV Pred N/A
Product checkpoint Quantum Security Gateway checkpoint
CVSS v3.1 KEV CWE-295 PoC
09 Sep/26
CVE-2026-80099
HIGH

This vulnerability is an authentication bypass caused by improper validation in the wp-module-data component bundled within several Newfold WordPress plugins. The root cause lies in the authenticate() method hooked to the rest_authentication_errors filter, which performs an HMAC-style Bearer token comparison that fails when HiiveConnection::get_auth_token() returns false. This results in the secret salt collapsing to a constant hash, allowing attacker-controlled inputs to pass authentication checks.

CVSS 8.8
EPSS 2.9%
KEV Pred N/A
Product Newfold WP Plugin Web newfold
CVSS v3.1 CWE-287 PoC
09 Sep/26
CVE-2026-87491
HIGH

This vulnerability is an out-of-bounds write (CWE-787) occurring within the V8 JavaScript engine component of Google Chrome. The root cause is improper bounds checking during memory operations in V8's handling of crafted JavaScript code, leading to memory corruption. The flaw specifically affects versions of Google Chrome prior to 153.0.8010.36, compromising the integrity of the V8 sandbox environment.

CVSS 8.8
EPSS 3.1%
KEV Pred 81%
Product Google Chrome google
CVSS v3.1 KEV CWE-787 PoC
07 Sep/26
CVE-2026-75650
CRITICAL

This vulnerability is an improper neutralization of special elements within the template engine of Adobe Commerce. The root cause lies in insufficient sanitization of user-controllable input embedded in templates, allowing injection of malicious code. The affected component is the template processing mechanism responsible for rendering dynamic content in Adobe Commerce versions including 2.4.4 and its patches.

CVSS 10.0
EPSS 3.9%
KEV Pred 84%
Product Adobe Commerce adobe
CVSS v3.1 KEV CWE-1336 PoC RANSOMWARE
06 Sep/26
CVE-2026-86218
CRITICAL

The vulnerability is a pre-authentication remote code execution caused by improper handling of input data within N-able N-central. The root cause lies in the unsafe processing of commands or scripts in a component responsible for handling unauthenticated requests, allowing arbitrary code execution. This flaw affects N-central versions prior to 2026.3.1.14, specifically within the core service that processes external input without sufficient validation or sanitization.

CVSS 9.8
EPSS 12.9%
KEV Pred 81%
Product N-able N-central n-able
CVSS v3.1 CVSS v4.0 KEV CWE-96 Exploit PoC
05 Sep/26
CVE-2026-86060
CRITICAL

This vulnerability is a privilege escalation flaw caused by improper argument handling in the SSH login process of Mikrotik RouterOS. Specifically, usernames beginning with a prohibited character bypass input validation, allowing unauthorized modification of the trusted RouterOS policy mask. The affected component is the RouterOS SSH login helper, which processes authentication requests without sufficient sanitization of username parameters.

CVSS 9.8
EPSS 6.4%
KEV Pred 84%
Product Mikrotik RouterOS mikrotik
CVSS v3.1 CVSS v4.0 KEV CWE-88 PoC
05 Sep/26
CVE-2026-67279
MEDIUM

This vulnerability is an authentication bypass in the SSH protocol implementation of Mikrotik RouterOS. The root cause is that after a client requests a rekey operation, the server transitions into the connection protocol phase without verifying user authentication. This flaw affects the SSH server component responsible for managing session channels and command dispatching within RouterOS.

CVSS 6.5
EPSS 1.0%
KEV Pred 81%
Product Mikrotik RouterOS mikrotik
CVSS v3.1 CVSS v4.0 KEV CWE-841 PoC
03 Sep/26
CVE-2026-85046
HIGH

This vulnerability is a type confusion flaw located within the V8 JavaScript engine component of Google Chrome. The root cause stems from improper handling of object types in memory, leading to incorrect assumptions about data structures. This flaw affects V8's internal type system prior to version 152.0.7977.82, allowing crafted input to manipulate memory layout inconsistently.

CVSS 8.8
EPSS 48.9%
KEV Pred 79%
Product Google Chrome google
CVSS v3.1 KEV CWE-843 PoC
02 Sep/26
CVE-2026-9055
CRITICAL

This is a privilege escalation flaw rooted in missing authorization checks on the customer update endpoint of the Amelia booking plugin for WordPress. The endpoint accepts an attacker-controlled 'type' parameter and uses it to assign the caller's role without verifying that the caller is entitled to that role. A second defect compounds it: passing 'externalId' as 0 makes the plugin provision a new WordPress user carrying the wpamelia-manager role instead of linking to an existing account.

CVSS 9.8
EPSS 0.5%
KEV Pred 70%
Product melograno Booking for Appointments and Events Calendar – Amelia melograno
CVSS v3.1 CWE-269 PoC
01 Sep/26
CVE-2026-83548
CRITICAL

The SMA1000 Work Place interface exposes an unintended alternate access path that reaches internal request-handling functionality before authentication is enforced. Because the appliance treats this path as trusted, the server can be induced to issue requests on the attacker's behalf, which is the classic Server-Side Request Forgery pattern. The flaw sits in the pre-auth surface of the appliance, so no session or credential material is involved in reaching the vulnerable code.

CVSS 10.0
EPSS 8.8%
KEV Pred 78%
Product SonicWall SMA1000 sonicwall
CVSS v3.1 KEV CWE-441 Exploit PoC RANSOMWARE
28 Aug/26
CVE-2026-82329
CRITICAL

JFrog Artifactory ships a default configuration in which the authentication layer accepts material that should never be trusted from the network. Public analysis of the patch describes a phantom join key: an attacker-supplied value that the server accepts when validating a URL parameter, allowing a service admin token to be forged rather than issued. The weakness is in the identity verification path itself, not in any single API handler.

CVSS 9.8
EPSS 14.1%
KEV Pred 81%
Product jfrog artifactory jfrog
CVSS v3.1 KEV CWE-287 PoC
28 Aug/26
CVE-2026-82078
CRITICAL

This vulnerability is a dynamic class loading flaw in PaperCut MF and NG's database connection utilities. The root cause is the application's instantiation of database driver classes based on configurable driver names without validating these against an allowlist of approved drivers. This unsafe dynamic loading occurs within the database connection component, enabling untrusted class loading from the application classpath.

CVSS 9.1
EPSS 63.5%
KEV Pred 77%
Product PaperCut MF/NG papercut
CVSS v3.1 CVSS v4.0 KEV CWE-470 Exploit RANSOMWARE
28 Aug/26
CVE-2026-81578
CRITICAL

This vulnerability is an improper access control flaw in the web management interface of PaperCut MF and PaperCut NG. The root cause is the premature execution of backend administrative functions before completing access validation checks. This affects the administrative web interface component responsible for enforcing authentication and authorization controls on remote requests.

CVSS 9.8
EPSS 85.6%
KEV Pred 83%
Product PaperCut MF/NG papercut
CVSS v3.1 CVSS v4.0 KEV CWE-305 Exploit PoC RANSOMWARE
28 Aug/26
CVE-2026-76581
CRITICAL

The WPMU DEV Dashboard plugin builds its HMAC message by concatenating token, state, redirect and domain values without a separator, and the two sides of the SSO handshake disagree on which fields belong in that string. The unauthenticated wdpsso_step1 action signs and returns a concatenation of all four values, while wdpsso_step2 verifies a concatenation that omits the domain field. Because no delimiter separates the fields, the boundary between redirect and domain is ambiguous to the verifier.

CVSS 9.8
EPSS 0.4%
KEV Pred 81%
Product wpmudev WPMU DEV Dashboard wpmudev
CVSS v3.1 CWE-347 PoC
26 Aug/26
CVE-2026-60004
CRITICAL

This vulnerability is a code injection flaw rooted in improper validation of input passed to the diffpatch API within Gitea's Git hook installation process. The affected component is the diffpatch API endpoint, which processes patch data without sufficient sanitization, enabling execution of arbitrary code via crafted input. The issue arises from the unsafe handling of patch content that is integrated into Git hooks, leading to command execution capability embedded in the repository management workflow.

CVSS 9.8
EPSS 24.0%
KEV Pred 80%
Product Gitea gitea
CVSS v3.1 KEV CWE-94 PoC
21 Aug/26
CVE-2026-76904
CRITICAL

This vulnerability is a SQL Injection flaw caused by improper sanitization of input parameters within the GeoTools Java library. Specifically, the PostGIS DataStore implementation's `jsonArrayContains` function constructs SQL queries by directly embedding the `<value>` parameter without escaping, affecting versions 30.5 and earlier up to 33.6 and 34.5. The root cause lies in unsafe query generation when handling String or JSON fields in PostGIS 12 or greater environments.

CVSS 9.8
EPSS 4.0%
KEV Pred 83%
Product geotools geotools
CVSS v3.1 CWE-89 PoC
21 Aug/26
CVE-2026-77806
CRITICAL

This vulnerability is a code injection flaw rooted in improper handling of user-supplied input within the SPIP content management system. Specifically, the analyse_resultat_skel function fails to sanitize the X-Spip-Filtre HTTP request header, allowing arbitrary code to be injected and executed. The flaw affects SPIP versions prior to 4.4.21 and involves the HTTP header processing mechanism.

CVSS 9.8
EPSS 4.5%
KEV Pred 83%
Product SPIP spip
CVSS v3.1 CWE-94 PoC
20 Aug/26
CVE-2026-77647
CRITICAL

This vulnerability is a remote code execution flaw caused by improper handling of PHP code blocks within SPIP versions prior to 4.4.20. The root cause lies in incorrect parsing and identification of '<?php' tags combined with var_export's faulty processing of strings containing the '<' character. This parsing error occurs in the code serialization component responsible for exporting PHP variables, leading to unsafe code injection opportunities.

CVSS 9.8
EPSS 2.3%
KEV Pred 84%
Product SPIP spip
CVSS v3.1 CWE-94 Exploit
20 Aug/26
CVE-2026-69836
CRITICAL

This vulnerability is a deserialization flaw in Microsoft Entra ID, where untrusted serialized data is processed insecurely. The root cause lies in improper validation and handling of serialized objects during deserialization, allowing malicious input to be interpreted as executable code. The affected component is the deserialization mechanism within Microsoft Entra ID's authentication or identity management services.

CVSS 10.0
EPSS 1.5%
KEV Pred 81%
Product Microsoft Entra microsoft
CVSS v3.1 CWE-502 PoC RANSOMWARE
19 Aug/26
CVE-2026-72530
CRITICAL

This vulnerability is a code injection flaw classified under CWE-94, caused by improper handling of user-supplied scripts within the TrueConf Server isolated environment. The root cause lies in insufficient validation and sanitization of input scripts processed on port 4307/TCP, allowing crafted payloads to escape sandbox restrictions. The affected component is the script execution environment in TrueConf Server versions 5.3.x through 5.5.5 on Windows and Linux platforms.

CVSS 9.0
EPSS 1.7%
KEV Pred 83%
Product TrueConf Server trueconf
CVSS v3.1 CVSS v4.0 KEV CWE-94 PoC
19 Aug/26
CVE-2026-19490
CRITICAL

This vulnerability is an authentication bypass flaw rooted in improper validation of user credentials within the NetScaler ADC and Gateway authentication modules. The issue arises from the failure to correctly verify authentication tokens or session parameters, allowing unauthorized access to protected components. The affected components include NetScaler ADC and NetScaler Gateway versions ranging from 13.1 through 63.21 and 14.1 through 73.32, impacting both FIPS and non-FIPS deployments.

CVSS 9.8
EPSS 23.2%
KEV Pred 83%
Product NetScaler ADC netscaler
CVSS v3.1 CVSS v4.0 KEV CWE-288 PoC
17 Aug/26
CVE-2026-64849
CRITICAL

This vulnerability is an SSRF (Server-Side Request Forgery) flaw rooted in improper validation of webhook URLs within the MLflow platform. Specifically, the _validate_webhook_url() function only validates the original URL without accounting for HTTP redirects. The mlflow/webhooks/delivery.py component follows redirects and re-resolves hostnames, enabling attackers to bypass URL validation and interact with unintended internal or cloud metadata endpoints.

CVSS 9.3
EPSS 9.8%
KEV Pred 60%
Product mlflow mlflow
CVSS v3.1 KEV CWE-918 PoC
13 Aug/26
CVE-2026-73570
HIGH

This vulnerability is a command injection flaw rooted in improper sanitization of untrusted input within the SNMP notification processing component of Zimbra Collaboration Suite (ZCS). Specifically, when the optional zimbra-snmp package is installed and SNMP notifications are enabled, maliciously crafted SMTP requests can inject operating system commands. The flaw arises from inadequate input validation during the handling of SNMP notifications in affected ZCS versions prior to 10.1.20.

CVSS 8.9
EPSS 71.7%
KEV Pred 79%
Product Zimbra Collaboration zimbra
CVSS v3.1 KEV CWE-78 PoC RANSOMWARE
12 Aug/26
CVE-2026-66384
MEDIUM

Artifactory does not properly constrain the pathname it derives when writing Docker layer data into the cache directory for remote repositories. Under specific remote-repository conditions the resolved path escapes the intended cache root, which is the classic path traversal pattern applied to a caching write rather than to a read.

CVSS 5.3
EPSS 0.7%
KEV Pred 77%
Product jfrog artifactory jfrog
CVSS v3.1 KEV CWE-22 PoC
11 Aug/26
CVE-2026-71362
CRITICAL

The vulnerability in Adobe Commerce is an Incorrect Authorization flaw rooted in improper access control checks within the application. This issue arises from the failure to correctly enforce privilege restrictions on certain administrative functions, allowing unauthorized users to escalate privileges. The affected component is the authorization mechanism governing access to sensitive resources and administrative features in Adobe Commerce versions including 2.4.4 and its patches.

CVSS 9.1
EPSS 87.5%
KEV Pred 93%
Product Adobe Commerce adobe
CVSS v3.1 KEV CWE-863 PoC RANSOMWARE
11 Aug/26
CVE-2026-65660
HIGH

This vulnerability is a code injection flaw arising from improper control over code generation within Microsoft Office SharePoint Server 2016. The root cause lies in insufficient validation and sanitization of user-supplied input that is processed in SharePoint's code generation mechanisms. The affected component is the SharePoint Enterprise Server 2016 platform, specifically in its handling of input that influences dynamic code execution.

CVSS 8.8
EPSS 2.1%
KEV Pred 76%
Product Microsoft SharePoint Enterprise Server 2016 microsoft
CVSS v3.1 KEV CWE-94 PoC RANSOMWARE
10 Aug/26
CVE-2026-72898
CRITICAL

Metabase concatenates user-supplied input directly into SQL statements at the reset_password database endpoint, without parameterization. The endpoint is reachable before authentication, so the injection point sits on the unauthenticated attack surface of the analytics server. This is a textbook SQL injection: the query structure is built from data the caller controls.

CVSS 10.0
EPSS 19.0%
KEV Pred 81%
Product Metabase metabase
CVSS v3.1 CVSS v4.0 KEV CWE-89 PoC
06 Aug/26
CVE-2026-65400
CRITICAL

This vulnerability is an authentication bypass issue rooted in improper state management within the Screen Sharing service of Apple macOS. The flaw allows network-based attackers to circumvent authentication controls by exploiting how session state is handled during the authentication process. The affected component is the Screen Sharing feature across multiple macOS versions, where authentication validation does not adequately verify credential legitimacy.

CVSS 9.8
EPSS 1.7%
KEV Pred 84%
Product Apple macOS apple
CVSS v3.1 KEV CWE-287 PoC
06 Aug/26
CVE-2026-5430
CRITICAL

This vulnerability is an authentication bypass caused by improper validation of JSON Web Tokens (JWT) in the WSO2 Universal Gateway's JWT authentication mechanism. The root cause lies in the acceptance of JWT tokens signed with algorithms that are not explicitly configured or supported by the system. This flaw affects the JWT authentication component responsible for verifying token signatures before granting access.

CVSS 10.0
EPSS 0.6%
KEV Pred 83%
Product WSO2 Universal Gateway wso2
CVSS v3.1 KEV CWE-347 PoC
02 Aug/26
CVE-2026-18577
HIGH

This vulnerability is an authentication bypass stemming from an incomplete patch applied to N-able N-central versions through 2026.3.1. The root cause lies in improper validation of authentication tokens within the access control mechanism, specifically affecting the authentication workflow component. The flaw allows bypassing normal authentication checks due to insufficient verification logic in the session validation process.

CVSS 8.1
EPSS 14.6%
KEV Pred 81%
Product N-able N-central n-able
CVSS v3.1 CVSS v4.0 KEV CWE-288 PoC
01 Aug/26
CVE-2026-18556
HIGH

This vulnerability is an authentication bypass in N-able N-central caused by improper validation of authentication mechanisms, allowing an attacker to circumvent normal authentication controls. The root cause lies in an alternate path or channel within the authentication process that fails to enforce required credentials. This flaw affects the authentication component of N-central versions through 2026.1, enabling unauthorized access through this bypass vector.

CVSS 7.4
EPSS 7.9%
KEV Pred 81%
Product N-able N-central n-able
CVSS v3.1 CVSS v4.0 KEV CWE-288 PoC
30 Jul/26
CVE-2026-59310
CRITICAL

This vulnerability is a directory traversal flaw within the VMware vCenter Syslog server component of VMware Cloud Foundation. The root cause lies in insufficient validation of file path inputs, allowing crafted requests to access arbitrary filesystem locations. This improper sanitization enables manipulation of file paths processed by the Syslog server, exposing underlying system directories.

CVSS 9.8
EPSS 2.6%
KEV Pred 93%
Product VMware Cloud Foundation vmware
CVSS v3.1 KEV CWE-22 PoC RANSOMWARE
27 Jul/26
CVE-2026-63077
CRITICAL

This vulnerability is an unsafe deserialization flaw (CWE-502) in the JetBrains TeamCity agent polling protocol. The root cause lies in improper validation and handling of serialized data received from unauthenticated remote sources during agent-server communication. The affected component is the TeamCity server's agent polling mechanism, which processes incoming serialized objects without adequate integrity or authenticity checks.

CVSS 9.8
EPSS 89.6%
KEV Pred 81%
Product JetBrains TeamCity jetbrains
CVSS v3.1 KEV CWE-502 Exploit PoC RANSOMWARE
Page 1 of 13 (601 total)