2d ago
2026-09-11 20:18Z
CRIT

CVE-2026-80926 — Linux: In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80926

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep. When the durable handle owning the oplock is disconnected, session_fd_check() clears opinfo->conn and drops its conn reference under ci->m_lock, and the last ksmbd_conn_put() frees the connection. A break triggered by another connect CVSSv3.1 9.8 (CRITICAL) · EPSS 6th percentile

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 20:17Z
CRIT

CVE-2026-53952 — GetSimple: A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53952

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The application features an automated security control designed to delete the sensitive `admin/setup.php` file post-installation. However, this control is neutralized by a self-exclusion bug within the delet CVSSv3.1 9.8 (CRITICAL)

CWECWE 306CWECWE 285CWECWE 489VNDGetsimpleTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 20:13Z
CRIT

CVE-2026-85706 | GitLab CE/EE Repository Commits API Path Traversal Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-85706

CVE-2026-85706 is a critical unauthenticated path traversal vulnerability in GitLab CE/EE's repository commits API (CVSS 10.0) affecting versions 18.7–19.3.1. The flaw allows remote attackers to read arbitrary files from the GitLab server, potentially exposing credentials, secrets, SSH keys, and database credentials. Patches are available in versions 19.1.8, 19.2.6, and 19.3.2.

SRFApplicationTACTA0001SRFWebTACTA0009SWGitlabVNDGitlabTYPVulnerabilitySTGInitial Access
92
Edit Score
2d ago
2026-09-11 19:17Z
CRIT

CVE-2026-79395 — An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79395

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin username with any arbitrary password when the account's stored password is empt CVSSv3.1 9.8 (CRITICAL)

CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 19:17Z
HIGH

CVE-2026-62107 — PHP: Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62107

Unauthenticated PHP Object Injection in Masteriyo - LMS <= 3.4.0 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 502TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 19:17Z
HIGH

CVE-2026-62106 — Subscriber: Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62106

Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 19:17Z
CRIT

CVE-2026-62105 — PHP: Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62105

Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2d ago
2026-09-11 19:17Z
CRIT

CVE-2026-62103 — PHP: Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62103

Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 19:17Z
HIGH

CVE-2026-62102 — Subscriber: Privilege Escalation in Gato GraphQL <= 19.2.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-62102

Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions. CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDSubscriberTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 19:17Z
CRIT

CVE-2026-54072 — Authorizer: Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54072

Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server appends `access_token`, `id_token`, and `refresh_token` as query parameters and issues a 302 redirect to the attacker-supplied URL. An unauthenticated attacker can obtain the required `client_id` from th CVSSv3.1 9.3 (CRITICAL)

CWECWE 601VNDAuthorizerTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2d ago
2026-09-11 17:18Z
CRIT

CVE-2026-72710 — SPIP: before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72710

SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing attackers with a valid nonce to inject attacker-controlled rows into the spip_jobs table. Attackers can supply arg=job/0 with crafted fonction and args values, which are later unserialized and executed when the cron job queue is drained, resulting in arbitrary PHP function execut CVSSv3.1 9.8 (CRITICAL)

CWECWE 915VNDSpipTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 17:18Z
CRIT

CVE-2026-72709 — SPIP: before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-72709

SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by supplying a valid HMAC-SHA256 nonce without any server-side permission check via autoriser(). Attackers can obtain a valid nonce, compute it for any action as the anonymous user, and invoke the editer_auteur action directly over HTTP to reset the password of any user account, includ CVSSv3.1 9.8 (CRITICAL)

CWECWE 862VNDSpipTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 16:17Z
HIGH

CVE-2026-7863 — Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7863

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection. This issue affects Pardus Software: before 1.0.5. CVSSv3.1 8.4 (HIGH)

CWECWE 78TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2d ago
2026-09-11 16:17Z
HIGH

CVE-2026-70341 — Use: after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-70341

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. CVSSv3.1 8.5 (HIGH)

CWECWE 416TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2d ago
2026-09-11 15:17Z
CRIT

CVE-2026-89010 — WAVLINK: WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89010

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136. The daemon interpolates attacker-controlled filename input containing shell metacharacters into a shell command string via sprintf() and passes it to system() without sanitization, enabling root-level CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDWavlinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 15:17Z
CRIT

CVE-2026-89009 — WAVLINK: WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89009

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136. The daemon, which runs as root and requires no authentication, accepts a 100-byte filename field in its protocol header without path canonicalization, allowing attackers to supply an absolute path and wr CVSSv3.1 9.1 (CRITICAL)

CWECWE 36VNDWavlinkTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2d ago
2026-09-11 15:17Z
HIGH

CVE-2026-87020 — An integer overflow in a specified pitch and buffer-size computation leads to a heap

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87020

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG. CVSSv3.1 8.1 (HIGH)

CWECWE 190TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2d ago
2026-09-11 15:17Z
HIGH

CVE-2026-82583 — NextGen: Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82583

NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition. CVSSv3.1 8.3 (HIGH)

CWECWE 89VNDNextgenTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2d ago
2026-09-11 15:17Z
HIGH

CVE-2026-78224 — XSLT: The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78224

The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks. CVSSv3.1 8.2 (HIGH)

CWECWE 611VNDXsltTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2d ago
2026-09-11 15:17Z
HIGH

CVE-2026-38058 — The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38058

The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware. CVSSv3.1 8.1 (HIGH)

CWECWE 497TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2d ago
2026-09-11 15:17Z
HIGH

CVE-2026-38056 — A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-38056

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians CVSSv3.1 8.8 (HIGH)

CWECWE 862TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 14:17Z
HIGH

CVE-2026-89212 — XML: A flaw resulting in XML external entity (XXE) was found in Akana API Platform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-89212

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions of Akana) and has been fixed as a security patch in the latest release of supported versions. CVSSv3.1 8.6 (HIGH)

CWECWE 611TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2d ago
2026-09-11 14:17Z
CRIT

CVE-2026-71644 — Robotics: An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71644

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the drone enters IDLE CVSSv3.1 9.8 (CRITICAL)

CWECWE 843VNDRoboticsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2d ago
2026-09-11 14:17Z
HIGH

CVE-2026-71416 — Headroom: compresses data before the data reaches a large language model.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71416

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket client executed in a traditional or headless browser such as lightpanda, if the CVSSv3.1 8.8 (HIGH)

CWECWE 287CWECWE 1385VNDHeadroomTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2d ago
2026-09-11 13:35Z
CRIT

Metasploit Wrap Up: This One Goes to Sixteen!

Metasploit 6.5.4 release adds 16 new modules including 10 exploit modules, with 5 targeting CISA KEV-listed vulnerabilities. Modules cover critical RCE chains in SonicWall SMA1000, PaperCut NG/MF, JetBrains TeamCity, and Next.js, plus novel Kerberos relay (ESC8) and Windows persistence techniques. Four bug fixes address race conditions, payload selection, DNS handling, and module regressions.

SRFApplicationTACTA0004TACTA0005TACTA0001TACTA0002SRFNetworkSRFWebTACTA0003
92
Edit Score