Digests
Vulnary ingests every hour. Each batch is grouped below so you can catch up on exactly the critical entries that surfaced, hour by hour.
CVE-2026-44104
A critical flaw in the firmware update process of a charging controller’s basemodule allows attackers to install tampered firmware because only a CRC32 checksum is checked, not a cryptographic signature.
CVE-2026-7849
An unauthenticated attacker can inject a command into a system configuration file that is then executed with root privileges. The flaw comes from improper handling of special characters, allowing arbitrary code execution. This could let a remote attacker take full control of the affected system.
CVE-2026-44108
A flaw in the shutdown process causes the firewall to stop too early, briefly exposing internal services to the outside world. This gives an attacker a chance to connect to those services and take over the system. The vulnerability is rated critical because it can lead to full compromise without any user interaction.
CVE-2026-44101
The CHARX OCPP Agent service lacks authentication, allowing anyone on the network to reconfigure its backend connection. This can cause denial of service and expose confidential data. The vulnerability is rated critical due to its high impact and ease of exploitation.
CVE-2026-44090
An unauthenticated attacker can connect to an MQTT broker that lacks authentication, potentially taking full control of the device. The broker is only protected by a firewall, so if the firewall is bypassed or misconfigured, the device is at risk. No vendor patch or official fix is documented.
CVE-2025-38429
A critical flaw in the Linux kernel’s MHI subsystem allows a race condition that can cause the host to read incomplete or uninitialized data. The issue occurs when the read pointer is updated before the buffer is written, potentially leading to data corruption. The flaw has been fixed in a kernel update.
CVE-2025-22021
In the Linux kernel, the following vulnerability has been resolved: netfilter: socket: Lookup orig tuple for IPv6 SNAT nf_sk_lookup_slow_v4 does the conntrack lookup for IPv4 pac…
CVE-2025-21663
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwmac-tegra: Read iommu stream id from device tree Nvidia's Tegra MGBE controllers require the IO…
CVE-2026-58046
A critical flaw in Plesk’s XML‑RPC API lets an authenticated low‑privileged user inject SQL. The attacker can read any data from the database and ultimately take full control of the panel. The issue is severe because it requires only a normal user account and no special privileges.
CVE-2025-40212
A critical flaw in the Linux kernel’s NFS server can be triggered by a specially crafted NFSv4 filehandle, leading to a use‑after‑free and potential denial of service. The bug was fixed in a kernel update that corrected reference counting in the nfsd_set_fh_dentry function.
CVE-2025-39880
A flaw in the Linux kernel's Ceph module allows for improper memory access when handling connection information. This occurs because the system fails to verify which version of a data structure is active before reading from or writing to it.
CVE-2025-40257
A race condition in the Linux kernel’s MPTCP implementation can cause a use‑after‑free error, potentially crashing the system or allowing arbitrary code execution. The flaw occurs when a timer is stopped while its data structure is freed. The issue has been fixed by adding RCU protection to the timer handling code.
CVE-2025-39673
A critical race condition in the Linux kernel’s PPP module can cause a system crash. The flaw allows an attacker to trigger a panic by manipulating PPP channels. The issue has been fixed in recent kernel releases.
CVE-2025-39703
A critical bug in the Linux kernel can cause a crash when it receives a corrupted HSR frame that does not have enough space for the HSR tag. The crash occurs in the networking stack and can bring the system down. The issue is triggered by a malformed packet that can be sent over the network.
CVE-2025-38724
A use-after-free vulnerability exists in the Linux kernel's NFS server implementation. The nfsd4_setclientid_confirm() function fails to check the return value from get_client_locked(), allowing a race condition where a confirmed client can expire and later be accessed after being freed. This flaw can be exploited to execute arbitrary code with high impact, as reflected by a CVSS v3.1 base score of 9.8 (Critical).
CVE-2025-38566
A critical flaw in the Linux kernel’s NFS over TLS implementation allows attackers to trigger a crash or denial of service by sending malformed TLS alerts. The vulnerability arises from improper handling of control messages in the kTLS layer. It has been fixed in kernel 6.17.
CVE-2025-39682
A flaw in the Linux kernel’s TLS handling can cause problems when a zero‑length record is processed. The bug can lead to improper record type handling, potentially allowing an attacker to disrupt the TLS connection. The issue has been fixed in newer kernel releases.
CVE-2026-65887
A Joomla extension called Gridbox, used in many websites, has a flaw that lets anyone reset any user’s password without authentication. The flaw exists in all versions older than 2.20.2. If exploited, an attacker could take over normal user accounts.
CVE-2026-65884
A flaw in the Gridbox extension for Joomla lets anyone create an administrator account without logging in. The issue exists in versions before 2.20.2 and can be fixed by updating the extension.
CVE-2026-65888
A Joomla extension called Gridbox has a flaw that lets attackers log in as any user. The problem is in the socialLogin method and affects all versions older than 2.20.2. Updating the extension fixes the issue.
CVE-2026-60429
A critical flaw in Oracle Unified Directory lets attackers with LDAP network access take over the directory service. The vulnerability can be exploited by low‑privileged users and can affect other Oracle products. It is rated CVSS 9.9.
CVE-2026-14446
IBM WebSphere Application Server versions 9.0 and 8.5 contain a broken access control vulnerability in the administrative console that could allow privilege escalation. The flaw is rated critical with a CVSS base score of 9.8. No known exploitation or public exploit is reported, and the provided sources do not document an official fix.
CVE-2026-14512
IBM WebSphere Application Server versions 9.0 and 8.5 traditional are vulnerable to unsafe deserialization before authentication. An attacker can bypass login or run arbitrary code on the server. The flaw is exploitable remotely without any user interaction.
CVE-2026-16610
The Admin and Site Enhancements (ASE) Pro plugin for WordPress contains a critical flaw that lets anyone run arbitrary code on the server. The vulnerability lies in the recursive_html function, which is triggered by the [post_cf_form] shortcode. Attackers can exploit it without needing to log in or provide any user interaction.
CVE-2026-14529
A critical flaw in IBM WebSphere Application Server allows attackers to trick the server into making arbitrary requests to internal or external resources. The vulnerability exists when the SIP container feature is enabled and can be exploited without authentication or user interaction.
CVE-2026-65885
A Joomla extension called Gridbox from balbooa.com allows authenticated users to upload any file. If an attacker can create an account, they can use this flaw together with another vulnerability (CVE-2026-65884) to run code on the server. The flaw is serious because it requires only an authenticated user and can lead to full control of the site.
CVE-2026-58179
A stack overflow in Apache Traffic Server’s regex_remap plugin can be triggered by malformed substitution input, allowing attackers to run arbitrary code. The flaw exists in several major releases and can be fixed by upgrading to the latest patched versions.
CVE-2026-14959
IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 contain a critical flaw that lets a remote authenticated attacker run arbitrary code on the system. The vulnerability is a shell command injection that can compromise confidentiality, integrity, and availability. It is rated CVSS 9.1.
CVE-2026-60606
A critical flaw in Oracle PeopleSoft Enterprise CC Common Application Objects (version 9.2) lets anyone on the network create, delete, or modify sensitive data without authentication. The vulnerability can be triggered over HTTP and requires no special privileges or user interaction. It poses a serious risk to the confidentiality and integrity of PeopleSoft data.
CVE-2026-16326
A flaw in consul‑mcp‑server versions 0.1.0 through 0.1.3 lets a client’s authentication token be reused by other clients, because session state isn’t isolated in stateless mode. The issue is fixed in version 0.1.4.
CVE-2026-67429
Flyto2 Core, an automation and AI‑agent workflow engine, had a flaw that let attackers write files anywhere the process could access. The vulnerability existed in all versions before 2.26.6 and was fixed in that release. It allows an attacker to place arbitrary files on the system.
CVE-2026-43750
A buffer overflow in macOS can let an application run code outside its sandbox or with elevated privileges. The flaw has been fixed in recent macOS releases. Users should update to the latest version to protect themselves.
CVE-2026-60202
Oracle WebLogic Server has a critical flaw that lets anyone on the network take over the server without needing credentials. The flaw can be triggered through the T3 or IIOP protocols. A successful attack would give the attacker full control over the server.
CVE-2026-43778
A critical flaw in Apple operating systems allows an attacker to free memory and then use it again, potentially crashing the system or corrupting kernel memory. The issue is fixed in recent OS releases. Users should update to the latest version.
CVE-2026-53398
A flaw in the Linux kernel’s NFS server can cause the server to crash when it receives a malformed request. The bug involves uninitialized memory that may be freed incorrectly, leading to a denial‑of‑service attack.
CVE-2026-53399
A use-after-free vulnerability in the Linux kernel's NFS daemon (CVE-2026-53399) allows an attacker to execute arbitrary code, cause a denial of service, or escalate privileges when setting a lease fails. The flaw occurs because the kernel frees a layout state ID without removing it from an internal IDR table, leaving a dangling pointer that subsequent code can dereference. The issue is fixed by initializing delayed work earlier and using the proper cleanup function (nfs4_put_stid) instead of manual freeing.
CVE-2026-63800
A critical use‑after‑free bug was found in the Linux kernel’s pNFS layout handling. The flaw could let an attacker read or corrupt memory after a layout update. The issue has been fixed in a kernel update.
CVE-2026-43810
A critical vulnerability in Apple’s operating systems allows a remote attacker to crash the system or corrupt kernel memory. The flaw has been fixed in recent releases of iOS, iPadOS, macOS, tvOS, visionOS, and watchOS. Updating to the latest OS version removes the risk.
CVE-2026-13385
Certain ASUS routers have a flaw that lets a remote attacker trick the device into downloading and running malicious commands. The vulnerability is due to improper validation of integrity checks and certificates. A firmware update from ASUS fixes the issue.
CVE-2026-67426
Flyto2 Core, an automation and AI‑agent workflow engine, had a flaw before version 2.26.7 that let anyone send a POST request to /run on port 8344. The service would then forward that request to a user‑supplied URL, exposing the server to unauthenticated Server‑Side Request Forgery (SSRF) and leaking a secret key.
CVE-2026-61511
vBulletin 5.x and 6.x versions up to 5.7.5 and 6.2.1 contain a critical flaw that lets anyone on the internet run arbitrary PHP code on the server. The bug is triggered by sending a specially crafted value in the pagenav[pagenumber] parameter to the ajax/render template route. Because no authentication is required, attackers can take full control of the affected site.
CVE-2026-54735
Prebid Server, an open‑source platform for real‑time ad auctions, had a critical flaw that let attackers trick the server into making requests to arbitrary internal URLs. The vulnerability was fixed in version 4.4.0. Users should update to that version or later.
CVE-2026-60644
This vulnerability is a critical flaw in Oracle WebCenter Content that lets anyone on the network take full control of the system. An attacker can exploit it without authentication or user interaction, potentially compromising all data and services. The flaw affects specific versions of the product.
CVE-2026-50746
A critical flaw in UniFi Connect Application allows attackers to run arbitrary commands on the device. The vulnerability is exploitable over the network without authentication or user interaction. It can lead to full control of the affected system.
CVE-2026-60627
A critical flaw in Oracle JD Edwards EnterpriseOne Tools (version 9.2.26.3) allows attackers with low privileges and network access over HTTP to take full control of the system. The vulnerability is easily exploitable and changes the security scope, potentially affecting other products. It can lead to a complete takeover of the application.
CVE-2026-51302
SQLite version 3.41 contains a use-after-free flaw in its expression evaluation logic. The sqlite3ReleaseTempReg function incorrectly frees temporary register resources, which are then accessed by exprComputeOperands, allowing a remote attacker to trigger denial of service, information disclosure, or arbitrary code execution via a malicious SQL statement. The vulnerability is rated critical with a CVSS base score of 9.8.
CVE-2026-64772
A critical vulnerability (CVE‑2026‑64772) allows a remote attacker to write data beyond the intended memory bounds in Apple operating systems. This can cause applications to crash or corrupt memory, potentially leading to denial‑of‑service or more severe exploits. The flaw is fixed in newer releases of iOS, iPadOS, macOS, tvOS, and visionOS.
CVE-2026-64775
A critical memory initialization flaw in Apple’s operating systems can let an app cause the system to crash. The issue is fixed in recent OS releases. Users should update to the latest version to protect their devices.
CVE-2026-53384
A flaw in the Linux kernel’s 8250_dw serial driver can leave a port registered even when a clock notifier fails, causing a use‑after‑free that could let an attacker run arbitrary code. The kernel has fixed the issue by unregistering the port on error. Users should update to a kernel version that includes this patch.
CVE-2026-53633
A security flaw in the Vitest testing framework allows remote users to execute unauthorized code. This occurs because certain browser testing features do not properly restrict commands sent to the browser.
CVE-2025-61140
A critical security flaw in the jsonpath library version 1.1.1 allows attackers to manipulate the library’s internal prototype chain. This can lead to arbitrary code execution or data tampering when the library processes untrusted input. The vulnerability is known as Prototype Pollution.
CVE-2026-64727
CVE-2026-64727 is a critical type confusion vulnerability in macOS and tvOS that could allow apps to cause unexpected system crashes. It is fixed in macOS Tahoe 26.6 and tvOS 26.6.
CVE-2026-48321
Adobe ColdFusion 2023 is vulnerable to an incorrect authorization flaw that lets attackers gain unauthorized read and write access. The flaw can be exploited without user interaction and can lead to privilege escalation. It is rated critical with a CVSS score of 9.3.
CVE-2026-60112
The AIT GUI before version 2.5.1 allows anyone on the network to create a session without authentication and then send arbitrary spacecraft commands. This flaw lets an attacker gain full control over the spacecraft’s command bus.
CVE-2026-41939
Care Everywhere Gateway 14.3.10 contains a hard‑coded credentials flaw in its bundled WildFly 8.2.0.Final management interface. Unauthenticated attackers can log in with default credentials, deploy a malicious web archive, and execute code as the Windows machine account. The vulnerability is critical with a CVSS score of 9.3.