2w ago
2026-09-01 15:32Z
CRIT

CVE-2026-9586 | Sangoma Switchvox Unauthenticated SQL Injection Remote Code Execution Vulnerability

Horizon3.ai·horizon3.aiCVE-2026-9586in the wild

CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition affecting versions prior to 8.4.0.2. The flaw exists in the /pa endpoint's PhoneAppsHandler.pm component, which concatenates user-controlled PhoneIP values directly into PostgreSQL queries without sanitization, allowing remote attackers to execute arbitrary SQL and achieve RCE. Horizon3 and Defused Cyber have observed active exploitation attempts in the wild since late August 2026.

SRFApplicationTACTA0001SWSwitchvoxVNDSangomaTYPVulnerabilitySTGExecutionSTGInitial AccessTECT1190
92
Edit Score
2w ago
2026-09-01 15:31Z
CRIT

CVE-2026-81578 + CVE-2026-82078 | PaperCut NG/MF Authentication Bypass and Unsafe Dynamic Class Loading Vulnerabilities

Horizon3.ai·horizon3.aiCVE-2026-81578CVE-2026-82078in the wild

PaperCut NG/MF contains two chained vulnerabilities enabling pre-authentication remote code execution: CVE-2026-81578 (improper access control, CVSS 8.8) allows unauthenticated modification of system configuration, and CVE-2026-82078 (unsafe dynamic class loading, CVSS 9.4) permits arbitrary Java bytecode execution via manipulated configuration. Active exploitation in customer environments has been confirmed; Emergency Patch Release 2 is available for versions 24–26.

SRFApplicationTACTA0001TACTA0002SRFWebSWPapercut MfSWPapercut NgVNDPapercutTYPVulnerability
92
Edit Score
2w ago
2026-09-01 15:17Z
HIGH

CVE-2026-84115 — Cleo: Performing a manipulation of the argument Bearer results in improper privilege management.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84115

A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 is sufficient to fix this issue. It is recommended to upgrade the affected compon CVSSv3.1 8.3 (HIGH)

CWECWE 269CWECWE 266VNDCleoTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-09-01 15:17Z
HIGH

CVE-2026-79686 — Dell: An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79686

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 693VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 15:17Z
CRIT

CVE-2026-78012 — NetStaX: An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78012

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDNetstaxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 15:17Z
HIGH

CVE-2026-58569 — Dell: An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58569

Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.. CVSSv3.1 8.8 (HIGH)

CWECWE 829VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 15:17Z
HIGH

CVE-2026-18630 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18630

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection. This issue affects Talassoft Industrial Management Software: from V.4 before V.16. CVSSv3.1 8.8 (HIGH)

CWECWE 89TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-09-01 14:26Z
HIGH

Linux Detection Engineering - Fileless Execution

Elastic Security Labs·elastic.co

Elastic Security Labs published a comprehensive detection engineering guide on Linux fileless execution patterns, reproducing five attack techniques (memfd_create staging, interpreter one-liners, deleted binaries, kernel module loads, and script execution) using their FENIX lab framework. The research maps each pattern to observable telemetry in Elastic Defend 9.4.0+, which now records memfd_create syscalls and kernel module loading activity to improve visibility into memory-only payload execution.

SRFOsTACTA0005OSLinuxSWElastic DefendVNDElasticTYPResearchSTGDefense EvasionSTGExecution
82
Edit Score
2w ago
2026-09-01 14:17Z
HIGH

CVE-2026-84218 — A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84218

A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only rejects URLs matching `service:jmx:rmi:///jndi/ldap:.*`, which can be bypassed using CVSSv3.1 8.1 (HIGH)

CWECWE 184TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 14:17Z
HIGH

CVE-2026-79684 — Dell: An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79684

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 693VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 14:17Z
HIGH

CVE-2026-58572 — Dell: PowerStore contains a Code Injection vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58572

Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 14:17Z
HIGH

CVE-2026-58571 — Dell: PowerStore contains an OS Command Injection vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58571

Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51765 — Incorrect: access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51765

Incorrect access control in the recvIndirectMeshInfo function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to insert or replace mesh neighbor records via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51764 — Incorrect: access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51764

Incorrect access control in the recvSlaveCloudCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite cloud-result tracking files via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51763 — Incorrect: access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51763

Incorrect access control in the freeStaClient function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forcibly disconnect wireless clients via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51762 — Incorrect: access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51762

Incorrect access control in the meshInfoKick function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to kick or clean stale mesh information/state and trigger regeneration of mesh metadata via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51760 — Incorrect: access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51760

Incorrect access control in the informSyncUpgfw function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to mass-trigger firmware update activity across mesh slaves via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51757 — Incorrect: access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51757

Incorrect access control in the meshSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to start a firmware download or flash workflow on the slave device via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51754 — Incorrect: access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51754

Incorrect access control in the updateSlaveIpList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to overwrite the slave IP inventory state via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51751 — Incorrect: access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51751

Incorrect access control in the delSlaveDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove a specified slave device from local mesh management data and reboot the system via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-51750 — Incorrect: access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51750

Incorrect access control in the updatePriChannel function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to rescan and switch the primary mesh channel via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
HIGH

CVE-2026-19513 — Gravity: The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19513

The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be reused as chunk continuation hashes and attacker-controlled temporary filenames are accepted before sanitization. This makes it possible for unauthenticated attackers, when a public form contains a Fi CVSSv3.1 8.1 (HIGH)

CWECWE 434VNDGravityTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-18808 — Control: Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18808

Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 14:17Z
CRIT

CVE-2026-18210 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18210

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before 030631b2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84143 — Mozilla Firefox: Some of these bugs showed evidence of memory corruption or another security-relevant defect and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84143

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 119VNDMozillaVNDInternallyTYPVulnerability
9.8
CVSS v3.1
99
Edit Score