CVE-2026-18577
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
Critical vulnerabilities, curated daily for security professionals
Content management and web application platforms account for most of yesterday's critical disclosures, led by three unauthenticated flaws in MaxSite CMS and a remote code execution issue in Pluck CMS. The day brought 26 critical CVEs, down 41 percent from the prior day's 44, alongside 74 high-priority vulnerabilities, essentially flat against 75. Notable entries include CVE-2026-70553, CVE-2026-70554, and CVE-2026-70552 (MaxSite CMS, CVSS 9.8), CVE-2026-63455 in HPE EdgeConnect SD-WAN Orchestrator (CVSS 9.8), and CVE-2026-43682 affecting Apple macOS (CVSS 9.8). Enterprise infrastructure also features, with four vulnerabilities under active exploitation in N-able N-central, Apache Tomcat, and IBM Langflow OSS. Patch data is unavailable for the full set at disclosure time, so treat vendor advisories as the authoritative source and prioritize internet-facing CMS and management platforms.
Immediate action: Prioritize N-able N-central, Apache Tomcat, and IBM Langflow OSS instances given confirmed exploitation, then move to internet-facing MaxSite CMS and Pluck CMS deployments and HPE EdgeConnect SD-WAN Orchestrator. Patch availability was not confirmed at disclosure, so check each vendor advisory for a fixed release and apply access restrictions or WAF rules where no update exists yet.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An incomplete patch for CVE-2026-18556 in N-able N-central creates an authentication bypass and account takeover vulnerability.
N-able N-central is affected by an authentication bypass vulnerability using an alternate path or channel, potentially allowing unauthorized access.
Apache Tomcat contains a vulnerability involving missing encryption of sensitive data, which is currently being actively exploited in the wild.
A critical code injection vulnerability in IBM Langflow OSS allows unauthenticated attackers to gain superuser privileges and execute arbitrary code on the host system.
MaxSite CMS is vulnerable to remote code execution due to improper handling of database configuration inputs, allowing unauthenticated attackers to inject malicious PHP code.
The Improve SEO WordPress plugin fails to validate file extensions during uploads, allowing unauthenticated attackers to upload executable PHP files and gain remote code execution.
Atals-Livre contains an improper access control vulnerability in admin controllers that allows unauthenticated attackers to bypass authentication and execute destructive actions.
MaxSite CMS is susceptible to PHP object injection via the maxsite_comuser cookie, allowing unauthenticated remote code execution.
A use after free vulnerability in the Android kernel vpu_ioctl.c functions could allow an unauthenticated remote attacker to escalate privileges.
Pluck CMS lacks robust CSRF protection, allowing attackers to force authenticated administrators to perform sensitive actions including remote code execution.
The Stock-Inventory-Management-System contains a SQL injection vulnerability and hardcoded credentials in the login module, allowing for total authentication bypass by unauthenticated remote attackers.
MaxSite CMS contains an authentication bypass flaw in the AJAX dispatcher, allowing unauthenticated attackers to invoke privileged administrative functions via crafted requests.
A memory handling vulnerability in macOS Sequoia, Sonoma, and Tahoe allows remote attackers to trigger system termination or kernel memory corruption.
HPE EdgeConnect SD-WAN Orchestrator contains multiple REST API vulnerabilities that allow unauthenticated remote attackers to bypass authentication and gain access to sensitive system functions.
Multiple vulnerabilities in the HPE EdgeConnect SD-WAN Orchestrator REST API allow unauthenticated remote attackers to bypass authentication and modify sensitive system information.
The kotaemon application contains an insecure deserialization vulnerability that allows unauthenticated attackers to achieve remote code execution by injecting arbitrary Python classes.
A memory handling vulnerability in macOS Sequoia, Sonoma, and Tahoe allows applications to trigger system termination or write to kernel memory.
A memory handling vulnerability in Apple macOS may allow an unauthenticated attacker to cause system termination or corrupt kernel memory.
A permissions vulnerability in multiple Apple operating systems allows an application to fingerprint a user due to insufficient permission restrictions.
OpenSIPS contains a stack-based buffer overflow vulnerability in the sip_to_json() function, allowing unauthenticated remote attackers to cause a crash or achieve remote code execution.
Keysight IxChariot Endpoint contains a heap-based buffer overflow vulnerability that allows an unauthenticated remote attacker to execute arbitrary code or crash the system via crafted network packets.
Keysight IxChariot Endpoint contains a stack-based buffer overflow vulnerability that allows an unauthenticated remote attacker to execute arbitrary code or crash the system via crafted network packets.
Multiple Keysight products contain a stack-based buffer overflow vulnerability, allowing an unauthenticated remote attacker to execute arbitrary code with administrative privileges.
Puwell IP Camera firmware versions 2.x through 4.x contain an authentication bypass vulnerability, allowing unauthenticated attackers to control device functions via TCP port 23456.
A critical code injection vulnerability in Veeam ONE allows remote unauthenticated attackers to execute arbitrary code on the agent host.
Puwell IP Camera firmware versions 2.x through 4.x contain an unauthenticated command injection vulnerability in the DebugShell interface on TCP port 34567.
The NASA-AMMOS plandev sequencing-server contains an authentication bypass flaw in the session role derivation middleware, allowing unauthenticated attackers to perform unauthorized administrative actions.
NVIDIA Dynamo for Linux is vulnerable to an out-of-bounds write in the multimodal serving topology, potentially leading to remote code execution or system compromise.
A stack-based buffer overflow in Qualcomm Snapdragon occurs when processing Device Capability Extended attributes in NAN Service Discovery Frames with invalid length values.
Multiple H3C network devices contain command injection vulnerabilities in the /api/esps request handler, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.
Amazon Bedrock AgentCore contains an input validation vulnerability that allows authenticated users to bypass security controls and execute tools via crafted conversation messages.
The Dokan plugin for WordPress is susceptible to a privilege escalation vulnerability due to missing authorization checks in its REST API controllers.
The FasterXML jackson-core library is vulnerable to resource exhaustion due to insufficient limits on resource allocation during processing.
A SQL injection vulnerability in Veeam ONE allows low-privileged users to execute unauthorized database queries and extract sensitive information.
The Smart Popup by Supsystic plugin for WordPress is vulnerable to improper privilege management, allowing authenticated users to escalate their permissions.
The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() function.
A memory corruption flaw in Apple products allows an attacker to trigger application termination via a maliciously crafted video file.
A state management vulnerability in the Apple macOS Keychain allows an attacker to modify sensitive state information.
Information disclosure in the Graphics: ImageLib component.
Information disclosure in the Privacy component in Firefox for Android.
Information disclosure in the Framework component in DevTools.
Denial-of-service in the Graphics: WebGPU component.
Other issue in the DOM: Copy & Paste and Drag & Drop component.
Information disclosure due to uninitialized memory in the Graphics: WebGPU component.
The WPFormify plugin for WordPress is vulnerable to unauthorized modification or deletion of Stripe payment credentials due to missing authorization checks.
The Mailmunch Forms for Mailchimp plugin for WordPress is vulnerable to unauthorized data modification due to missing capability checks on specific AJAX handlers.
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery, allowing unauthorized actions via manipulated requests.
The Create Block Theme WordPress plugin is susceptible to code injection, which may allow authenticated users with high privileges to execute arbitrary code.
The CAFEHAUS API WordPress plugin through 1.
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.
PDM is vulnerable to code injection and inclusion of functionality from untrusted control spheres, potentially allowing arbitrary code execution.
PDM is vulnerable to path traversal, which could allow an attacker to read or write files outside of the intended directory.
The MPG WordPress plugin before 4.1.8 fails to sanitize input, allowing unauthenticated attackers to execute reflected cross-site scripting (XSS) attacks.
The Dromara lamp-cloud platform is vulnerable to remote code execution due to improper handling of Groovy scripts.
An unauthenticated vulnerability in the Veeam Service Provider Console allows unauthorized access to the proxied appliance API as a Portal Administrator during a narrow session window.
A local privilege escalation vulnerability in Veeam ONE allows a high-privileged user to escalate their permissions to the context of the Reporter service.
Use After Free vulnerability in the Rust deserialization logic of Apache Fory.
NVIDIA Dynamo for Linux is susceptible to a deserialization vulnerability that allows an attacker to process untrusted data, potentially leading to service disruption.
A stack-based buffer overflow vulnerability in the Autodesk FBX SDK allows remote attackers to execute arbitrary code via a maliciously crafted FBX file.
A stack-based buffer overflow in the Autodesk FBX SDK function fbxsdk::ExtractDrive allows for potential code execution when parsing a maliciously crafted FBX file.
Rancher improperly manages long-lived registration tokens for cluster authentication, leading to potential security exposure of sensitive information.
A memory corruption vulnerability in the UTT HiPER 1200GW router, specifically a stack-based buffer overflow, allows authenticated attackers to potentially execute arbitrary code.
The UTT HiPER 1250GW router contains a memory corruption vulnerability, identified as a stack-based buffer overflow, which may allow an authenticated attacker to execute arbitrary code.
A stack-based buffer overflow vulnerability in the UTT HiPER 1250GW router allows for potential memory corruption and system compromise.
A missing authorization vulnerability in Odysseus allows authenticated non-admin users to modify server-wide embedding backend configurations by bypassing admin-only endpoint guards.
A command injection vulnerability in Lenovo XClarity Orchestrator (LXCO) allows authenticated users to execute arbitrary operating system commands due to improper input validation.
A command injection vulnerability in GL.iNet AX1800 allows authenticated users with low privileges to execute arbitrary system commands, potentially leading to full system compromise.
Django is susceptible to server-side request forgery and path traversal vulnerabilities, potentially allowing authenticated attackers to manipulate file paths or perform unauthorized requests.
Flowise is vulnerable to an authorization bypass and improper modification of object attributes, potentially allowing unauthenticated attackers to manipulate application behavior.
A missing authorization vulnerability exists in HAVELSAN Liman MYS that allows an authenticated user to perform unauthorized actions.
Perspective 5 contains an improper neutralization of directives flaw, allowing for code injection via dynamically evaluated expressions.
A missing authorization vulnerability in HAVELSAN Liman MYS allows authenticated users to bypass security checks and perform unauthorized operations.
Eclipse Milo versions before 1.1.5 contain a missing authorization check, allowing unauthenticated remote attackers to perform unauthorized integrity modifications.
OpenStack Swift contains an inefficient regular expression complexity vulnerability that can be exploited by unauthenticated remote attackers to cause a denial of service.
OpenSIPS contains input validation and NULL pointer dereference vulnerabilities that allow unauthenticated remote attackers to crash the SIP server.
A stack-based buffer overflow vulnerability in OpenSIPS allows unauthenticated remote attackers to trigger a denial of service via malformed SIP traffic.
A NULL pointer dereference vulnerability in OpenSIPS allows unauthenticated remote attackers to trigger a denial of service by sending specifically crafted SIP requests.
A stored cross-site scripting (XSS) vulnerability in Open WebUI allows authenticated attackers with low privileges to execute arbitrary scripts in the context of other users' sessions.
Flowise contains an incomplete list of disallowed inputs, which may allow an authenticated user to perform unauthorized actions within the Large Language Model flow interface.
Veeam Service Provider Console is susceptible to memory exhaustion, allowing an unauthenticated attacker to cause a denial of service on the host system.
Veeam ONE contains an arbitrary file read vulnerability that allows unauthenticated attackers to access sensitive host files and escalate privileges locally.
Eclipse Milo contains an authorization bypass vulnerability, allowing unauthenticated remote attackers to perform unauthorized actions.
Eclipse Milo is susceptible to a memory leak vulnerability due to improper resource management, which can lead to a denial of service condition.
Veeam ONE is vulnerable to a code injection flaw that allows a high-privileged user to execute arbitrary code on the server.
The CVAT computer vision annotation tool is vulnerable to cross-site scripting and unrestricted file uploads, which can be leveraged by authenticated users.
Flowise contains an authorization bypass vulnerability due to improper handling of user-controlled keys, allowing authenticated administrators to manipulate data.
NetKids iMark is affected by an unquoted search path vulnerability, which could allow an authenticated user to execute arbitrary code with elevated privileges.
Flowise contains an improper access control vulnerability, enabling unauthenticated attackers to bypass authorization checks via user-controlled keys.
Flowise contains a vulnerability involving missing authorization and improper information exposure, allowing authenticated users to access unauthorized sensitive data.
Crater contains an authorization bypass vulnerability where invoice and expense policies fail to properly enforce company isolation, allowing users to access data outside their authorized scope.
Shiori versions 1.6.0 and 1.6.1 contain an authentication bypass vulnerability in the CheckToken function due to improperly secured v1 API endpoints.
Open WebUI is susceptible to Cross-site Scripting and UI layer restriction flaws that could allow an authenticated attacker to execute malicious scripts or manipulate the interface.
NVIDIA Dynamo for Linux is vulnerable to an out-of-bounds write, which could allow a remote, unauthenticated attacker to cause a denial of service or potentially impact system integrity.
Leantime is affected by a missing authorization vulnerability, which allows an authenticated user to perform unauthorized actions within the application.
Typemill's login endpoint lacks rate-limiting or account lockout mechanisms when the captcha is disabled, allowing for potential brute-force attacks.
Open WebUI suffers from missing and incorrect authorization flaws that allow authenticated users to perform unauthorized actions.
Open WebUI is susceptible to an improper authentication flaw that can be exploited by an attacker via user interaction.
Qualcomm Snapdragon components contain a cryptographic vulnerability due to missing authentication during the processing of registration requests.
Amazon Kiro IDE is susceptible to an uncontrolled search path element vulnerability, potentially allowing local privilege escalation or arbitrary code execution.
Amazon Kiro CLI contains an uncontrolled search path element vulnerability that may allow local attackers to escalate privileges or execute arbitrary commands.
An integer overflow vulnerability in Qualcomm Snapdragon allows for memory corruption when processing packets with sizes near the maximum allowed limit.
A buffer overflow vulnerability exists in the Qualcomm Snapdragon fingerprint Trusted Application, triggered by the handling of malformed request parameters.
An untrusted pointer dereference vulnerability in the Qualcomm Snapdragon IOCTL device driver allows for memory corruption when processing requests with invalid arguments.