Vulnary
(what landed, by batch)

Digests

Vulnary ingests every hour. Each batch is grouped below so you can catch up on exactly the critical entries that surfaced, hour by hour.

Jul 30, 08:01 AM
batch #291
5 new · 20 summarized
(success)
01

CVE-2026-44104

A critical flaw in the firmware update process of a charging controller’s basemodule allows attackers to install tampered firmware because only a CRC32 checksum is checked, not a cryptographic signature.

Critical· 9.3
published 4h agodeletes in 45d
02

CVE-2026-7849

An unauthenticated attacker can inject a command into a system configuration file that is then executed with root privileges. The flaw comes from improper handling of special characters, allowing arbitrary code execution. This could let a remote attacker take full control of the affected system.

Critical· 9.3
published 4h agodeletes in 45d
03

CVE-2026-44108

A flaw in the shutdown process causes the firewall to stop too early, briefly exposing internal services to the outside world. This gives an attacker a chance to connect to those services and take over the system. The vulnerability is rated critical because it can lead to full compromise without any user interaction.

Critical· 9.3
published 4h agodeletes in 45d
04

CVE-2026-44101

The CHARX OCPP Agent service lacks authentication, allowing anyone on the network to reconfigure its backend connection. This can cause denial of service and expose confidential data. The vulnerability is rated critical due to its high impact and ease of exploitation.

Critical· 9.3
published 4h agodeletes in 45d
05

CVE-2026-44090

An unauthenticated attacker can connect to an MQTT broker that lacks authentication, potentially taking full control of the device. The broker is only protected by a firewall, so if the firewall is bypassed or misconfigured, the device is at risk. No vendor patch or official fix is documented.

Critical· 9.3
published 4h agodeletes in 45d
Jul 30, 07:01 AM
batch #290
104 new · 1 summarized
(success)
01

CVE-2025-38429

Linux Linux Kernel

A critical flaw in the Linux kernel’s MHI subsystem allows a race condition that can cause the host to read incomplete or uninitialized data. The issue occurs when the read pointer is updated before the buffer is written, potentially leading to data corruption. The flaw has been fixed in a kernel update.

Critical· 10<1% likelyfix available
published Jul 25, 2025deletes in 30d
02

CVE-2025-22021

Linux Linux Kernel +1 more

In the Linux kernel, the following vulnerability has been resolved: netfilter: socket: Lookup orig tuple for IPv6 SNAT nf_sk_lookup_slow_v4 does the conntrack lookup for IPv4 pac…

Critical· 10<1% likelyunprocessed
published Apr 16, 2025deletes in 45d
03

CVE-2025-21663

Linux Linux Kernel +6 more

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwmac-tegra: Read iommu stream id from device tree Nvidia's Tegra MGBE controllers require the IO…

Critical· 10<1% likelyunprocessed
published Jan 21, 2025deletes in 45d
04

CVE-2026-58046

A critical flaw in Plesk’s XML‑RPC API lets an authenticated low‑privileged user inject SQL. The attacker can read any data from the database and ultimately take full control of the panel. The issue is severe because it requires only a normal user account and no special privileges.

Critical· 9.9
published 5h agodeletes in 45d
05

CVE-2025-40212

A critical flaw in the Linux kernel’s NFS server can be triggered by a specially crafted NFSv4 filehandle, leading to a use‑after‑free and potential denial of service. The bug was fixed in a kernel update that corrected reference counting in the nfsd_set_fh_dentry function.

Critical· 9.8<1% likelyfix available
published Nov 24, 2025deletes in 30d
06

CVE-2025-39880

Linux Linux Kernel +6 more

A flaw in the Linux kernel's Ceph module allows for improper memory access when handling connection information. This occurs because the system fails to verify which version of a data structure is active before reading from or writing to it.

Critical· 9.8<1% likelyfix available
published Sep 23, 2025deletes in 30d
07

CVE-2025-40257

A race condition in the Linux kernel’s MPTCP implementation can cause a use‑after‑free error, potentially crashing the system or allowing arbitrary code execution. The flaw occurs when a timer is stopped while its data structure is freed. The issue has been fixed by adding RCU protection to the timer handling code.

Critical· 9.8<1% likelyfix available
published Dec 4, 2025deletes in 30d
08

CVE-2025-39673

Linux Linux Kernel +3 more

A critical race condition in the Linux kernel’s PPP module can cause a system crash. The flaw allows an attacker to trigger a panic by manipulating PPP channels. The issue has been fixed in recent kernel releases.

Critical· 9.8<1% likelyfix available
published Sep 5, 2025deletes in 30d
09

CVE-2025-39703

Linux Linux Kernel +8 more

A critical bug in the Linux kernel can cause a crash when it receives a corrupted HSR frame that does not have enough space for the HSR tag. The crash occurs in the networking stack and can bring the system down. The issue is triggered by a malformed packet that can be sent over the network.

Critical· 9.8<1% likelyfix available
published Sep 5, 2025deletes in 30d
10

CVE-2025-38724

Linux Linux Kernel +1 more

A use-after-free vulnerability exists in the Linux kernel's NFS server implementation. The nfsd4_setclientid_confirm() function fails to check the return value from get_client_locked(), allowing a race condition where a confirmed client can expire and later be accessed after being freed. This flaw can be exploited to execute arbitrary code with high impact, as reflected by a CVSS v3.1 base score of 9.8 (Critical).

Critical· 9.8<1% likelyfix available
published Sep 4, 2025deletes in 30d
11

CVE-2025-38566

Linux Linux Kernel +1 more

A critical flaw in the Linux kernel’s NFS over TLS implementation allows attackers to trigger a crash or denial of service by sending malformed TLS alerts. The vulnerability arises from improper handling of control messages in the kTLS layer. It has been fixed in kernel 6.17.

Critical· 9.8<1% likelyfix available
published Aug 19, 2025deletes in 30d
12

CVE-2025-39682

Linux Linux Kernel +3 more

A flaw in the Linux kernel’s TLS handling can cause problems when a zero‑length record is processed. The bug can lead to improper record type handling, potentially allowing an attacker to disrupt the TLS connection. The issue has been fixed in newer kernel releases.

Critical· 9.8<1% likelyfix available
published Sep 5, 2025deletes in 30d
Jul 30, 06:01 AM
batch #289
14 new · 0 summarized
(success)
01

CVE-2026-65887

A Joomla extension called Gridbox, used in many websites, has a flaw that lets anyone reset any user’s password without authentication. The flaw exists in all versions older than 2.20.2. If exploited, an attacker could take over normal user accounts.

Critical· 10fix available
published 20h agodeletes in 30d
02

CVE-2026-65884

A flaw in the Gridbox extension for Joomla lets anyone create an administrator account without logging in. The issue exists in versions before 2.20.2 and can be fixed by updating the extension.

Critical· 10fix available
published 22h agodeletes in 30d
03

CVE-2026-65888

A Joomla extension called Gridbox has a flaw that lets attackers log in as any user. The problem is in the socialLogin method and affects all versions older than 2.20.2. Updating the extension fixes the issue.

Critical· 10fix available
published 20h agodeletes in 30d
04

CVE-2026-60429

Oracle Unified Directory +1 more

A critical flaw in Oracle Unified Directory lets attackers with LDAP network access take over the directory service. The vulnerability can be exploited by low‑privileged users and can affect other Oracle products. It is rated CVSS 9.9.

Critical· 9.9<1% likely
published 9d agodeletes in 37d
05

CVE-2026-14446

IBM WebSphere Application Server versions 9.0 and 8.5 contain a broken access control vulnerability in the administrative console that could allow privilege escalation. The flaw is rated critical with a CVSS base score of 9.8. No known exploitation or public exploit is reported, and the provided sources do not document an official fix.

Critical· 9.8<1% likely
published 2d agodeletes in 44d
06

CVE-2026-14512

IBM WebSphere Application Server versions 9.0 and 8.5 traditional are vulnerable to unsafe deserialization before authentication. An attacker can bypass login or run arbitrary code on the server. The flaw is exploitable remotely without any user interaction.

Critical· 9.8<1% likely
published 2d agodeletes in 44d
07

CVE-2026-16610

The Admin and Site Enhancements (ASE) Pro plugin for WordPress contains a critical flaw that lets anyone run arbitrary code on the server. The vulnerability lies in the recursive_html function, which is triggered by the [post_cf_form] shortcode. Attackers can exploit it without needing to log in or provide any user interaction.

Critical· 9.8
published 6h agodeletes in 45d
08

CVE-2026-14529

A critical flaw in IBM WebSphere Application Server allows attackers to trick the server into making arbitrary requests to internal or external resources. The vulnerability exists when the SIP container feature is enabled and can be exploited without authentication or user interaction.

Critical· 9.4
published 16h agodeletes in 45d
09

CVE-2026-65885

A Joomla extension called Gridbox from balbooa.com allows authenticated users to upload any file. If an attacker can create an account, they can use this flaw together with another vulnerability (CVE-2026-65884) to run code on the server. The flaw is serious because it requires only an authenticated user and can lead to full control of the site.

Critical· 9.4
published 22h agodeletes in 45d
10

CVE-2026-58179

A stack overflow in Apache Traffic Server’s regex_remap plugin can be triggered by malformed substitution input, allowing attackers to run arbitrary code. The flaw exists in several major releases and can be fixed by upgrading to the latest patched versions.

Critical· 9.2<1% likelyfix available
published 1d agodeletes in 30d
11

CVE-2026-14959

IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 contain a critical flaw that lets a remote authenticated attacker run arbitrary code on the system. The vulnerability is a shell command injection that can compromise confidentiality, integrity, and availability. It is rated CVSS 9.1.

Critical· 9.11% likely
published 2d agodeletes in 44d
12

CVE-2026-60606

A critical flaw in Oracle PeopleSoft Enterprise CC Common Application Objects (version 9.2) lets anyone on the network create, delete, or modify sensitive data without authentication. The vulnerability can be triggered over HTTP and requires no special privileges or user interaction. It poses a serious risk to the confidentiality and integrity of PeopleSoft data.

Critical· 9.1<1% likely
published 9d agodeletes in 37d
Jul 30, 04:01 AM
batch #287
1 new · 0 summarized
(success)
Jul 29, 11:01 PM
batch #282
1 new · 0 summarized
(success)
Jul 29, 09:01 PM
batch #280
16 new · 9 summarized
(success)
01

CVE-2026-16326

A flaw in consul‑mcp‑server versions 0.1.0 through 0.1.3 lets a client’s authentication token be reused by other clients, because session state isn’t isolated in stateless mode. The issue is fixed in version 0.1.4.

Critical· 10fix available
published 16h agodeletes in 30d
02

CVE-2026-67429

Flyto2 Core, an automation and AI‑agent workflow engine, had a flaw that let attackers write files anywhere the process could access. The vulnerability existed in all versions before 2.26.6 and was fixed in that release. It allows an attacker to place arbitrary files on the system.

Critical· 10fix available
published 16h agodeletes in 30d
03

CVE-2026-43750

Apple Macos

A buffer overflow in macOS can let an application run code outside its sandbox or with elevated privileges. The flaw has been fixed in recent macOS releases. Users should update to the latest version to protect themselves.

Critical· 9.8<1% likelyfix available
published 3d agodeletes in 29d
04

CVE-2026-60202

Oracle Weblogic Server +3 more

Oracle WebLogic Server has a critical flaw that lets anyone on the network take over the server without needing credentials. The flaw can be triggered through the T3 or IIOP protocols. A successful attack would give the attacker full control over the server.

Critical· 9.8<1% likely
published 9d agodeletes in 37d
05

CVE-2026-43778

Apple Ipados +5 more

A critical flaw in Apple operating systems allows an attacker to free memory and then use it again, potentially crashing the system or corrupting kernel memory. The issue is fixed in recent OS releases. Users should update to the latest version.

Critical· 9.8<1% likelyfix available
published 3d agodeletes in 29d
06

CVE-2026-53398

Linux Linux Kernel

A flaw in the Linux kernel’s NFS server can cause the server to crash when it receives a malformed request. The bug involves uninitialized memory that may be freed incorrectly, leading to a denial‑of‑service attack.

Critical· 9.8<1% likelyfix available
published 11d agodeletes in 21d
07

CVE-2026-53399

Linux Linux Kernel

A use-after-free vulnerability in the Linux kernel's NFS daemon (CVE-2026-53399) allows an attacker to execute arbitrary code, cause a denial of service, or escalate privileges when setting a lease fails. The flaw occurs because the kernel frees a layout state ID without removing it from an internal IDR table, leaving a dangling pointer that subsequent code can dereference. The issue is fixed by initializing delayed work earlier and using the proper cleanup function (nfs4_put_stid) instead of manual freeing.

Critical· 9.8<1% likelyfix available
published 11d agodeletes in 21d
08

CVE-2026-63800

Linux Linux Kernel +5 more

A critical use‑after‑free bug was found in the Linux kernel’s pNFS layout handling. The flaw could let an attacker read or corrupt memory after a layout update. The issue has been fixed in a kernel update.

Critical· 9.8<1% likelyfix available
published 11d agodeletes in 21d
09

CVE-2026-43810

Apple Ipados +5 more

A critical vulnerability in Apple’s operating systems allows a remote attacker to crash the system or corrupt kernel memory. The flaw has been fixed in recent releases of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Updating to the latest OS version removes the risk.

Critical· 9.8<1% likelyfix available
published 3d agodeletes in 29d
10

CVE-2026-13385

Certain ASUS routers have a flaw that lets a remote attacker trick the device into downloading and running malicious commands. The vulnerability is due to improper validation of integrity checks and certificates. A firmware update from ASUS fixes the issue.

Critical· 9.5<1% likelyfix available
published 15d agodeletes in 30d
11

CVE-2026-67426

Flyto2 Core, an automation and AI‑agent workflow engine, had a flaw before version 2.26.7 that let anyone send a POST request to /run on port 8344. The service would then forward that request to a user‑supplied URL, exposing the server to unauthenticated Server‑Side Request Forgery (SSRF) and leaking a secret key.

Critical· 9.3fix available
published 16h agodeletes in 30d
12

CVE-2026-61511

vBulletin 5.x and 6.x versions up to 5.7.5 and 6.2.1 contain a critical flaw that lets anyone on the internet run arbitrary PHP code on the server. The bug is triggered by sending a specially crafted value in the pagenav[pagenumber] parameter to the ajax/render template route. Because no authentication is required, attackers can take full control of the affected site.

Critical· 9.31% likely
published 3d agodeletes in 43d
Jul 29, 08:01 PM
batch #279
28 new · 2 summarized
(success)
01

CVE-2026-54735

Prebid Server, an open‑source platform for real‑time ad auctions, had a critical flaw that let attackers trick the server into making requests to arbitrary internal URLs. The vulnerability was fixed in version 4.4.0. Users should update to that version or later.

Critical· 10fix available
published 19h agodeletes in 30d
02

CVE-2026-60644

Oracle Webcenter Content +1 more

This vulnerability is a critical flaw in Oracle WebCenter Content that lets anyone on the network take full control of the system. An attacker can exploit it without authentication or user interaction, potentially compromising all data and services. The flaw affects specific versions of the product.

Critical· 10<1% likely
published 9d agodeletes in 37d
03

CVE-2026-50746

Ui Unifi Connect Application

A critical flaw in UniFi Connect Application allows attackers to run arbitrary commands on the device. The vulnerability is exploitable over the network without authentication or user interaction. It can lead to full control of the affected system.

Critical· 103% likely
published 28d agodeletes in 45d
04

CVE-2026-60627

A critical flaw in Oracle JD Edwards EnterpriseOne Tools (version 9.2.26.3) allows attackers with low privileges and network access over HTTP to take full control of the system. The vulnerability is easily exploitable and changes the security scope, potentially affecting other products. It can lead to a complete takeover of the application.

Critical· 9.9<1% likely
published 9d agodeletes in 37d
05

CVE-2026-51302

Sqlite Sqlite

SQLite version 3.41 contains a use-after-free flaw in its expression evaluation logic. The sqlite3ReleaseTempReg function incorrectly frees temporary register resources, which are then accessed by exprComputeOperands, allowing a remote attacker to trigger denial of service, information disclosure, or arbitrary code execution via a malicious SQL statement. The vulnerability is rated critical with a CVSS base score of 9.8.

Critical· 9.8<1% likely
published 3d agodeletes in 44d
06

CVE-2026-64772

Apple Ipados +4 more

A critical vulnerability (CVE‑2026‑64772) allows a remote attacker to write data beyond the intended memory bounds in Apple operating systems. This can cause applications to crash or corrupt memory, potentially leading to denial‑of‑service or more severe exploits. The flaw is fixed in newer releases of iOS, iPadOS, macOS, tvOS, and visionOS.

Critical· 9.8<1% likelyfix available
published 3d agodeletes in 29d
07

CVE-2026-64775

Apple Ipados +5 more

A critical memory initialization flaw in Apple’s operating systems can let an app cause the system to crash. The issue is fixed in recent OS releases. Users should update to the latest version to protect their devices.

Critical· 9.8<1% likelyfix available
published 3d agodeletes in 29d
08

CVE-2026-53384

Linux Linux Kernel

A flaw in the Linux kernel’s 8250_dw serial driver can leave a port registered even when a clock notifier fails, causing a use‑after‑free that could let an attacker run arbitrary code. The kernel has fixed the issue by unregistering the port on error. Users should update to a kernel version that includes this patch.

Critical· 9.8<1% likelyfix available
published 11d agodeletes in 21d
09

CVE-2026-53633

A security flaw in the Vitest testing framework allows remote users to execute unauthorized code. This occurs because certain browser testing features do not properly restrict commands sent to the browser.

Critical· 9.8<1% likelyfix available
published 16d agodeletes in 30d
10

CVE-2025-61140

Dchester Jsonpath

A critical security flaw in the jsonpath library version 1.1.1 allows attackers to manipulate the library’s internal prototype chain. This can lead to arbitrary code execution or data tampering when the library processes untrusted input. The vulnerability is known as Prototype Pollution.

Critical· 9.8<1% likely
published Jan 28, 2026deletes in 44d
11

CVE-2026-64727

Apple Macos +1 more

CVE-2026-64727 is a critical type confusion vulnerability in macOS and tvOS that could allow apps to cause unexpected system crashes. It is fixed in macOS Tahoe 26.6 and tvOS 26.6.

Critical· 9.8<1% likelyfix available
published 3d agodeletes in 29d
12

CVE-2026-48321

Adobe Coldfusion +32 more

Adobe ColdFusion 2023 is vulnerable to an incorrect authorization flaw that lets attackers gain unauthorized read and write access. The flaw can be exploited without user interaction and can lead to privilege escalation. It is rated critical with a CVSS score of 9.3.

Critical· 9.3<1% likely
published 16d agodeletes in 45d
Jul 29, 07:01 PM
batch #278
2 new · 4 summarized
(success)