1w ago
2026-09-02 17:17Z
HIGH

CVE-2026-20277 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20277

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20277 are related to protection mechanism failure issues that are grouped under the Common Weakness Enumeration (CWE) CWE-693. CVSSv3.1 8.2 (HIGH)

CWECWE 693TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 17:17Z
HIGH

CVE-2026-20276 — The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20276

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20276 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691. CVSSv3.1 8.6 (HIGH)

CWECWE 691TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
1w ago
2026-09-02 17:17Z
HIGH

CVE-2026-20275 — The vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are grouped

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20275

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20275 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-682. CVSSv3.1 8.8 (HIGH)

CWECWE 682TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 17:17Z
CRIT

CVE-2026-20274 — As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20274

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-664. CVSSv3.1 9.8 (CRITICAL)

CWECWE 664TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 17:17Z
CRIT

CVE-2026-20212 — Silicon: A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-20212

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. T CVSSv3.1 9.8 (CRITICAL)

CWECWE 1327VNDSiliconTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 16:58Z
CRIT

Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild

Rapid7 Research·rapid7.comCVE-2026-83548CVE-2026-83549in the wild

SonicWall disclosed two critical vulnerabilities in SMA1000 appliances (CVE-2026-83548 SSRF + CVE-2026-83549 OS command injection) that chain to achieve unauthenticated RCE and are actively exploited in the wild. The SSRF has a CVSS 10.0 score and affects the Work Place interface typically exposed to the internet; exploitation requires no authentication. SonicWall has released platform hotfixes for affected versions (12.4.3 and 12.5.0 branches).

TACTA0001TACTA0002SRFNetwork ApplianceSWSonicwall Sma1000VNDSonicwallTYPVulnerabilityTYPAdvisorySTGExecution
92
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84673 — Jenkins: Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84673

Jenkins Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier allows overwriting the plugin's appearance configuration through Stapler data binding, allowing attackers to configure a custom SVG icon containing inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84672 — Jenkins: Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84672

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using both the group's unique object ID and its display name, allowing attackers who can create an Entra group with a colliding display name to gain the permissions configured for a privileged group. CVSSv3.1 8.8 (HIGH)

CWECWE 639VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84671 — Jenkins: File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84671

Jenkins File Parameter Plugin 425.v3fa_801681b_5e and earlier allows writing files to arbitrary locations on the Jenkins controller file system through Stapler data binding, which can lead to remote code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84670 — Jenkins: Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84670

Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84669 — Jenkins: A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84669

A path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish Allure report results to read arbitrary files on the Jenkins controller's file system. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84668 — Jenkins: SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84668

Jenkins SAML Plugin 4.618.v441a_27fa_46d2 and earlier allows overwriting the SAML identity provider metadata file through Stapler data binding, allowing attackers to replace it with attacker-controlled content and authenticate as any user. CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84665 — Jenkins: SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84665

Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. CVSSv3.1 8.0 (HIGH)

CWECWE 79VNDJenkinsTYPVulnerability
8.0
CVSS v3.1
90
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84650 — Jenkins: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84650

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of transient fields that will be deserialized, the impact depending on how those fields are used. CVSSv3.1 8.8 (HIGH)

CWECWE 502CWECWE 566VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84649 — Stapler: In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84649

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with control over a page hosted on the same site as Jenkins to obtain a valid crumb for th CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDStaplerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84648 — Jenkins: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84648

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers in control of agent processes. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84647 — Stapler: In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84647

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be instantiated via form data binding to those compatible with the expected field type, allowing attackers with Overall/Read permission to instantiate types related to configuration for which that field type was not intended. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDStaplerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-84645 — Jenkins: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84645

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 94CWECWE 915VNDJenkinsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-78689 — Description: A crafted prefix list causes an out-of-bounds write past the end of a heap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78689

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can trigger it when an affected NGINX configuration passes an externally controlled XML namespace prefix list to that method. Both the njs and the QuickJS (qjs) engines are affected. A crafted prefix list causes an out-of-bounds write past the end of a heap allocation. With the njs engin CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDDescriptionTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-77180 — NGINX: When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77180

When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access t CVSSv3.1 8.3 (HIGH)

CWECWE 76VNDNginxTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-66842 — BIG: Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66842

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. There is no data plane exposure; this is a control plane issue only. Note: Sof CVSSv3.1 8.8 (HIGH)

CWECWE 918VNDBigTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-66362 — Description: Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-66362

Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the clientSecret field of a Secret referenced by an Authentication Filter, are rendered directly into NGINX configuration templates without sanitization or escaping CVSSv3.1 8.1 (HIGH)

CWECWE 76VNDDescriptionTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 16:17Z
CRIT

CVE-2026-53611 — Looking: Prior to version 1.3.5, there is an OS Command Injection vulnerability resulting from an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53611

Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a lg-cli client. Prior to version 1.3.5, there is an OS Command Injection vulnerability resulting from an unanchored regular expression in the input validation layer. This issue has been patched in version 1.3.5. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLookingTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-02 16:17Z
HIGH

CVE-2026-18329 — Description: This may cause the js_access phase to fail open, allowing the request to proceed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18329

Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition in the access validation logic. This may cause the js_access phase to fail open, CVSSv3.1 8.2 (HIGH)

CWECWE 636VNDDescriptionTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-02 15:17Z
CRIT

CVE-2026-77009 — WatchMan: The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-77009

The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server. CVSSv3.1 9.9 (CRITICAL)

CWECWE 94VNDWatchmanTYPVulnerability
9.9
CVSS v3.1
100
Edit Score