Vulnary
(what landed, by batch)

Digests

Vulnary ingests every hour. Each batch is grouped below so you can catch up on exactly the critical entries that surfaced, hour by hour.

Sep 13, 12:01 PM
batch #1375
2 new · 6 summarized
(success)
Sep 13, 08:01 AM
batch #1371
71 new · 0 summarized
(success)
01

CVE-2026-80980

A race condition in the Linux kernel’s SMC (Socket Message Control) subsystem allows an attacker to corrupt internal state by writing to three single‑bit flags that share a byte. The flaw was fixed by allocating each flag a separate byte, preventing accidental overlap. The issue is now resolved in the kernel source.

Critical· 9.8<1% likelyfix available
published 2d agodeletes in 30d
02

CVE-2026-81002

CVE-2026-81002 is a critical flaw in the Linux kernel's XDP zero-copy packet handling. When an AF_XDP packet is redirected through a CPU map, packet data can be placed in the wrong part of its memory page, potentially causing memory corruption and a kernel panic.

Critical· 9.8<1% likelyfix available
published 2d agodeletes in 30d
03

CVE-2026-89538

In the Linux kernel's SUNRPC implementation, the gss_krb5_unwrap_v2 function incorrectly handles Kerberos v2 wrap tokens that have an oversized 'extra count' (ec) field. Although the field is authenticated, a peer with a valid GSS context can encrypt a token where ec exceeds the plaintext length, leaving the internal buffer in an inconsistent state after processing. This flaw can be exploited to cause a denial‑of‑service or other impacts and is rated critical with a CVSS base score of 9.8.

Critical· 9.8<1% likelyfix available
published 2d agodeletes in 30d
04

CVE-2026-80981

A use‑after‑free bug in the Linux kernel’s SMC LLC code lets an attacker read memory that has already been freed, which can lead to arbitrary code execution or a crash. The flaw has been fixed in newer kernel releases.

Critical· 9.8<1% likelyfix available
published 2d agodeletes in 30d
05

CVE-2026-89482

A critical vulnerability in the Linux kernel’s NVMe‑TCP driver could cause a wild‑memory‑access when handling WRITE_ZEROES commands. The issue has been resolved by adding a check for the number of physical segments before using the payload size in the driver’s command setup. This fix is documented in the NVD description.

Critical· 9.8<1% likelyfix available
published 2d agodeletes in 30d
06

CVE-2026-89636

A critical use-after-free vulnerability exists in the Linux kernel's SMB client, allowing remote code execution with no user interaction. When freeing target structures, a pointer to freed memory is not cleared, leading to memory corruption. The issue has been resolved in a kernel patch.

Critical· 9.8<1% likelyfix available
published 2d agodeletes in 30d
07

CVE-2026-89637

A use‑after‑free bug in the Linux kernel’s CIFS client can be triggered by sending malformed SMB packets. The flaw can leak memory and allow attackers to corrupt memory, potentially leading to arbitrary code execution or a crash. The kernel has already been patched to fix the issue.

Critical· 9.8<1% likelyfix available
published 2d agodeletes in 30d
08

CVE-2026-89658

A critical flaw in the Linux kernel’s NFSv4.0 revoked‑state cleanup can allow an attacker to trigger a use‑after‑free, potentially leading to arbitrary code execution. The bug occurs when the kernel drops a client lock while another process is still using the client reference. The issue has been fixed in newer kernel releases.

Critical· 9.8<1% likelyfix available
published 2d agodeletes in 30d
09

CVE-2026-89610

A flaw in the Linux kernel’s NTFS file system driver can let a specially crafted NTFS image cause the kernel to read memory beyond the volume’s limits. This can corrupt memory and allow an attacker to gain higher privileges. The issue has been fixed in recent kernel releases.

Critical· 9.8<1% likelyfix available
published 2d agodeletes in 30d
10

CVE-2026-80926

A critical use-after-free vulnerability (CVE-2026-80926) in the Linux kernel's ksmbd subsystem allows a race condition where a freed connection can be reused after being detached, potentially leading to arbitrary code execution. The bug occurs because ksmbd_oplock_break_notify() dereferences opiniono->conn without proper locking while other threads may have already freed it.

Critical· 9.8<1% likelyfix available
published 2d agodeletes in 30d
11

CVE-2026-80976

An unprivileged local user can exploit a flaw in the Linux kernel's seg6 subsystem to cause an out-of-bounds memory read. By injecting a crafted IPv6 packet with specific extension headers, the kernel retains stale offset information from the outer packet after decapsulation, leading to reading beyond the packet buffer. This could potentially lead to information disclosure or denial of service.

Critical· 9.8<1% likelyfix available
published 2d agodeletes in 30d
12

CVE-2026-89478

A flaw in the Linux kernel’s SCTP (Stream Control Transmission Protocol) handling can let an attacker send specially crafted packets that cause the kernel to crash or become unresponsive. The bug involves a race condition where a removed transport is still referenced, leading to a use‑after‑free. The issue has been fixed in the kernel, but no specific version or patch is listed in the provided sources.

Critical· 9.8<1% likely
published 2d agodeletes in 45d
Sep 13, 12:01 AM
batch #1363
1 new · 0 summarized
(success)
Sep 12, 07:01 PM
batch #1358
1 new · 0 summarized
(success)
Sep 12, 05:01 PM
batch #1356
8 new · 0 summarized
(success)
01

CVE-2026-82845

The Masteriyo LMS WordPress plugin before version 3.4.1 can deserialize user‑supplied data, allowing attackers to inject PHP objects that can write files or execute code on the server. This flaw can be triggered even by users with minimal privileges.

Critical· 9.9<1% likelyfix available
published 1d agodeletes in 30d
02

CVE-2026-75800

The Frontegg SAML SSO WordPress plugin up to version 1.0.1 does not verify the signature or issuer of SAML responses, allowing attackers to log in as any user, including administrators, and create arbitrary accounts. This flaw lets unauthenticated users gain full control of the site. The vulnerability is critical with a CVSS score of 9.8.

Critical· 9.8<1% likely
published 1d agodeletes in 45d
03

CVE-2026-84171

The piclect WordPress plugin version 1.0 lets anyone upload files without checking their type or name, allowing attackers to place malicious files on the server. This can lead to arbitrary code execution and full compromise of the site. The vulnerability is rated critical.

Critical· 9.8<1% likely
published 1d agodeletes in 45d
04

CVE-2026-81402

The DS Ad Rotator WordPress plugin up to version 0.8 has a serious flaw that lets anyone upload any file, including PHP scripts, to the site without permission. This can let attackers run code on the server.

Critical· 9.8<1% likely
published 1d agodeletes in 45d
05

CVE-2026-85681

The WP Component WordPress plugin up to version 2.2.4 allows unauthenticated users to overwrite any site option because it lacks capability or nonce checks. This can lead to a full site takeover, including enabling registration with administrator privileges. The vulnerability is critical with a CVSS score of 9.8.

Critical· 9.8<1% likely
published 1d agodeletes in 45d
06

CVE-2026-79724

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a critical flaw that lets attackers run any operating‑system commands on the host. The vulnerability is caused by improper handling of special characters in command strings.

Critical· 9.8<1% likely
published 3d agodeletes in 43d
07

CVE-2026-77006

The WebTotem Backups WordPress plugin (up to version 1.0.1) fails to validate file paths, ignore user permissions, and bypass CSRF checks, allowing any logged‑in user to delete arbitrary files on the server. This flaw can lead to a complete takeover of the site.

Critical· 9.6<1% likely
published 1d agodeletes in 45d
08

CVE-2026-77005

This critical vulnerability (CVE-2026-77005) affects the CODE MONKEYS WordPress plugin (version 1.0.1 and earlier) because it fails to validate user-supplied file paths before deletion and does not properly verify user permissions. Any authenticated user—including low-privilege accounts like subscribers—can exploit this flaw to delete arbitrary files on the server, potentially resulting in full site compromise.

Critical· 9.6<1% likely
published 1d agodeletes in 45d
Sep 12, 09:01 AM
batch #1348
2 new · 0 summarized
(success)
Sep 12, 04:01 AM
batch #1343
1 new · 0 summarized
(success)
Sep 12, 12:01 PM
batch #1351
1 new · 0 summarized
(success)