Digests
Vulnary ingests every hour. Each batch is grouped below so you can catch up on exactly the critical entries that surfaced, hour by hour.
CVE-2026-90561
Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 have a stored cross‑site scripting flaw in the content manager’s WYSIWYG preview component. The component fails to strip script tags from rich‑text fields, allowing an Author‑role user to embed malicious scripts that run when the preview pane is expanded. This can lead to account takeover by privileged users such as Editors or Super Admins.
CVE-2026-90562
LangBot versions before 4.10.11 generate password recovery keys with only 24 bits of entropy and expose an unauthenticated reset‑password endpoint without rate limiting. This allows attackers who know the administrator’s email to brute‑force the recovery key and reset the admin password. The result is full administrative access to the system.
CVE-2026-80980
A race condition in the Linux kernel’s SMC (Socket Message Control) subsystem allows an attacker to corrupt internal state by writing to three single‑bit flags that share a byte. The flaw was fixed by allocating each flag a separate byte, preventing accidental overlap. The issue is now resolved in the kernel source.
CVE-2026-81002
CVE-2026-81002 is a critical flaw in the Linux kernel's XDP zero-copy packet handling. When an AF_XDP packet is redirected through a CPU map, packet data can be placed in the wrong part of its memory page, potentially causing memory corruption and a kernel panic.
CVE-2026-89538
In the Linux kernel's SUNRPC implementation, the gss_krb5_unwrap_v2 function incorrectly handles Kerberos v2 wrap tokens that have an oversized 'extra count' (ec) field. Although the field is authenticated, a peer with a valid GSS context can encrypt a token where ec exceeds the plaintext length, leaving the internal buffer in an inconsistent state after processing. This flaw can be exploited to cause a denial‑of‑service or other impacts and is rated critical with a CVSS base score of 9.8.
CVE-2026-80981
A use‑after‑free bug in the Linux kernel’s SMC LLC code lets an attacker read memory that has already been freed, which can lead to arbitrary code execution or a crash. The flaw has been fixed in newer kernel releases.
CVE-2026-89482
A critical vulnerability in the Linux kernel’s NVMe‑TCP driver could cause a wild‑memory‑access when handling WRITE_ZEROES commands. The issue has been resolved by adding a check for the number of physical segments before using the payload size in the driver’s command setup. This fix is documented in the NVD description.
CVE-2026-89636
A critical use-after-free vulnerability exists in the Linux kernel's SMB client, allowing remote code execution with no user interaction. When freeing target structures, a pointer to freed memory is not cleared, leading to memory corruption. The issue has been resolved in a kernel patch.
CVE-2026-89637
A use‑after‑free bug in the Linux kernel’s CIFS client can be triggered by sending malformed SMB packets. The flaw can leak memory and allow attackers to corrupt memory, potentially leading to arbitrary code execution or a crash. The kernel has already been patched to fix the issue.
CVE-2026-89658
A critical flaw in the Linux kernel’s NFSv4.0 revoked‑state cleanup can allow an attacker to trigger a use‑after‑free, potentially leading to arbitrary code execution. The bug occurs when the kernel drops a client lock while another process is still using the client reference. The issue has been fixed in newer kernel releases.
CVE-2026-89610
A flaw in the Linux kernel’s NTFS file system driver can let a specially crafted NTFS image cause the kernel to read memory beyond the volume’s limits. This can corrupt memory and allow an attacker to gain higher privileges. The issue has been fixed in recent kernel releases.
CVE-2026-80926
A critical use-after-free vulnerability (CVE-2026-80926) in the Linux kernel's ksmbd subsystem allows a race condition where a freed connection can be reused after being detached, potentially leading to arbitrary code execution. The bug occurs because ksmbd_oplock_break_notify() dereferences opiniono->conn without proper locking while other threads may have already freed it.
CVE-2026-80976
An unprivileged local user can exploit a flaw in the Linux kernel's seg6 subsystem to cause an out-of-bounds memory read. By injecting a crafted IPv6 packet with specific extension headers, the kernel retains stale offset information from the outer packet after decapsulation, leading to reading beyond the packet buffer. This could potentially lead to information disclosure or denial of service.
CVE-2026-89478
A flaw in the Linux kernel’s SCTP (Stream Control Transmission Protocol) handling can let an attacker send specially crafted packets that cause the kernel to crash or become unresponsive. The bug involves a race condition where a removed transport is still referenced, leading to a use‑after‑free. The issue has been fixed in the kernel, but no specific version or patch is listed in the provided sources.
CVE-2026-82845
The Masteriyo LMS WordPress plugin before version 3.4.1 can deserialize user‑supplied data, allowing attackers to inject PHP objects that can write files or execute code on the server. This flaw can be triggered even by users with minimal privileges.
CVE-2026-75800
The Frontegg SAML SSO WordPress plugin up to version 1.0.1 does not verify the signature or issuer of SAML responses, allowing attackers to log in as any user, including administrators, and create arbitrary accounts. This flaw lets unauthenticated users gain full control of the site. The vulnerability is critical with a CVSS score of 9.8.
CVE-2026-84171
The piclect WordPress plugin version 1.0 lets anyone upload files without checking their type or name, allowing attackers to place malicious files on the server. This can lead to arbitrary code execution and full compromise of the site. The vulnerability is rated critical.
CVE-2026-81402
The DS Ad Rotator WordPress plugin up to version 0.8 has a serious flaw that lets anyone upload any file, including PHP scripts, to the site without permission. This can let attackers run code on the server.
CVE-2026-85681
The WP Component WordPress plugin up to version 2.2.4 allows unauthenticated users to overwrite any site option because it lacks capability or nonce checks. This can lead to a full site takeover, including enabling registration with administrator privileges. The vulnerability is critical with a CVSS score of 9.8.
CVE-2026-79724
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a critical flaw that lets attackers run any operating‑system commands on the host. The vulnerability is caused by improper handling of special characters in command strings.
CVE-2026-77006
The WebTotem Backups WordPress plugin (up to version 1.0.1) fails to validate file paths, ignore user permissions, and bypass CSRF checks, allowing any logged‑in user to delete arbitrary files on the server. This flaw can lead to a complete takeover of the site.
CVE-2026-77005
This critical vulnerability (CVE-2026-77005) affects the CODE MONKEYS WordPress plugin (version 1.0.1 and earlier) because it fails to validate user-supplied file paths before deletion and does not properly verify user permissions. Any authenticated user—including low-privilege accounts like subscribers—can exploit this flaw to delete arbitrary files on the server, potentially resulting in full site compromise.
CVE-2026-78006
The Events Calendar plugin for WordPress is vulnerable to remote code execution in all versions up to 6.17.4. The flaw lies in the is_safe_widget_instance function, which can be bypassed to inject code. Unauthenticated attackers can run arbitrary code if comments are enabled on events.
CVE-2026-78159
The Events Calendar plugin for WordPress is vulnerable to remote code execution in all versions up to and including 6.17.3. An attacker can inject malicious code by submitting a specially crafted comment that contains a wp:legacy-widget block, which is processed when the event page is rendered. This flaw allows unauthenticated attackers to run arbitrary code on the server.