1w ago
2026-09-07 11:17Z
HIGH

CVE-2026-86297 — Such manipulation of the argument peer_hostname leads to off-by-one.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86297

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname  leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used. CVSSv3.1 8.1 (HIGH)

CWECWE 189CWECWE 193TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-07 11:17Z
CRIT

CVE-2026-86296 — This manipulation causes stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86296

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 10.0 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-09-07 11:17Z
HIGH

CVE-2026-86295 — The manipulation of the argument Hostname results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86295

A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. CVSSv3.1 8.3 (HIGH)

CWECWE 74CWECWE 77TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1w ago
2026-09-07 07:16Z
CRIT

CVE-2026-79698 — Advantech: Such manipulation of the argument act leads to command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79698

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This vulnerability affects the function nodered_lib_apply of the component Node-RED Library. Such manipulation of the argument act leads to command injection. The attack can be launched remotely. The exploit is publ CVSSv3.1 9.9 (CRITICAL)

CWECWE 74CWECWE 77VNDAdvantechTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1w ago
2026-09-07 07:16Z
CRIT

CVE-2026-79697 — Advantech: This manipulation of the argument act causes command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79697

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exp CVSSv3.1 9.9 (CRITICAL)

CWECWE 74CWECWE 77VNDAdvantechTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1w ago
2026-09-07 02:17Z
HIGH

CVE-2026-20502 — In vdec, there is a possible out of bounds write due to a missing

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20502

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196. CVSSv3.1 8.4 (HIGH)

CWECWE 122TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
1w ago
2026-09-07 02:17Z
HIGH

CVE-2026-20501 — In vdec, there is a possible out of bounds write due to a heap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20501

In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197. CVSSv3.1 8.4 (HIGH)

CWECWE 122TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-07 00:00Z
CRIT

Dissecting a PHP web server rootkit

Sophos X-Ops·news.sophos.comCVE-2025-53521in the wild

Sophos X-Ops analyzed a sophisticated Linux rootkit deployed against BIG-IP APM environments exploiting CVE-2025-53521. The malware uses custom ELF loading, __libc_start_main hooking, APR function interception, and runtime mmap manipulation to inject a fileless PHP web shell into Apache worker processes while evading traditional file-based detection. The implant also establishes a local UNIX domain socket backdoor for interactive shell access without exposing a listening TCP port.

SRFApplicationTACTA0005SRFWebTACTA0003OSLinuxSWApacheVNDF5TYPResearch
92
Edit Score
1w ago
2026-09-06 23:17Z
CRIT

CVE-2026-86304 — MojoX: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86304

MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes the returned XML to Net::SAML2::Protocol::Assertion->new_from_xml with the IdP signing certificate as cacert. In Net::SAML2 before 0.86 that certificate guards o CVSSv3.1 9.8 (CRITICAL)

CWECWE 347VNDMojoxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-06 18:17Z
CRIT

CVE-2026-86219 — Authen: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86219

Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing later compares that value against the nonce the client returns. server_step derives the expected digest from the client's own parameters, so a response verifies whenever its digest matches the nonce it carries. The count table it also checks is keyed on the CVSSv3.1 9.8 (CRITICAL)

CWECWE 294VNDAuthenTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-06 18:17Z
HIGH

CVE-2026-82209 — When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82209

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`). Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP r CVSSv3.1 8.2 (HIGH)

CWECWE 201TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-06 18:17Z
CRIT

CVE-2026-19931 — A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19931

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection. CVSSv3.1 9.8 (CRITICAL)

CWECWE 488TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-06 18:17Z
CRIT

CVE-2026-18924 — A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18924

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process. CVSSv3.1 9.1 (CRITICAL)

CWECWE 416TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-06 16:16Z
HIGH

CVE-2026-19633 — PostgreSQL: Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19633

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the context of the extension’s masking mechanisms, the malicious code can run with elevated privileges. The issue is fixed in PostgreSQL Anonymizer 3.1.4 and later versions CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDPostgresqlTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-06 12:17Z
HIGH

CVE-2026-86242 — Bifrost: On documented dynamically linked builds (DYNAMIC=1 / no static-link flags), which the vendor requires

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86242

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefixed path as a download URL, writes the body to a temporary .so, and passes it to Go's plugin.Open. After a successful open, optional Init runs immediately with the supplied config as the Bifrost proc CVSSv3.1 8.1 (HIGH)

CWECWE 94CWECWE 306CWECWE 284VNDBifrostTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-06 07:16Z
HIGH

CVE-2026-18480 — SureCart: It further allows an attacker-controlled customer record to be associated with an arbitrary user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18480

The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with a subscriber-level account to change another user's email address, including an administrator's, and take over that account via a password reset. It further allows an attacker-controlled customer record to be associated with an arbitrary user, and discloses customer identifiers and email addresses t CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDSurecartTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-06 05:16Z
CRIT

CVE-2026-86167 — Tenda: The manipulation of the argument fmgpon_loid leads to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86167

A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. CVSSv3.1 9.9 (CRITICAL)

CWECWE 77CWECWE 78VNDTendaTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
1w ago
2026-09-06 04:18Z
HIGH

CVE-2026-86166 — Tenda: Executing a manipulation of the argument if can lead to buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86166

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. CVSSv3.1 8.8 (HIGH)

CWECWE 120CWECWE 119VNDTendaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-06 04:18Z
CRIT

CVE-2026-86165 — Tenda: Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86165

A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120CWECWE 119VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-06 03:17Z
CRIT

CVE-2026-86218 — N-able N-central: is vulnerable to a pre-auth remote code execution This issue affects N-central: before

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86218

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. CVSSv3.1 9.8 (CRITICAL) · EPSS 34th percentile

CWECWE 96VNDN AbleTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-06 03:17Z
CRIT

CVE-2026-75816 — Frontend: The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75816

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and ActionPost::conditions_logic() short-circuiting its current_user_can('edit_post') authorization gate whenever the post ID is non-numeric — such as the string user_1 — allowing unauthenticated form submissions to be routed to arb CVSSv3.1 9.8 (CRITICAL)

CWECWE 287VNDFrontendTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-06 03:17Z
CRIT

CVE-2026-16310 — MemberDash: The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-16310

The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration, and take over their account without any notification sent to the victim. CVSSv3.1 9.8 (CRITICAL)

CWECWE 639VNDMemberdashTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-06 02:17Z
CRIT

CVE-2026-86153 — The manipulation leads to improper privilege management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86153

A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible. CVSSv3.1 9.1 (CRITICAL)

CWECWE 269CWECWE 266TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-06 02:17Z
CRIT

CVE-2026-86152 — Executing a manipulation can lead to os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86152

A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely. CVSSv3.1 10.0 (CRITICAL)

CWECWE 77CWECWE 78TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-09-06 00:16Z
CRIT

CVE-2026-86151 — Tenda: Performing a manipulation results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86151

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely. CVSSv3.1 9.1 (CRITICAL)

CWECWE 77CWECWE 78VNDTendaTYPVulnerability
9.1
CVSS v3.1
96
Edit Score