SignalSec: Vulns & Hacks
Known Exploited Vulnerabilities and latest CVEs
CVE-2026-88771
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
CISA KEV Alert: Added on 9/27/2026. Action due: 9/30/2026.
CVE-2026-88772
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
CISA KEV Alert: Added on 9/27/2026. Action due: 9/30/2026.
CVE-2026-65660
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
CISA KEV Alert: Added on 9/25/2026. Action due: 9/28/2026.
CVE-2026-87902
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.
CISA KEV Alert: Added on 9/25/2026. Action due: 9/28/2026.
CVE-2026-5430
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.
CISA KEV Alert: Added on 9/24/2026. Action due: 9/27/2026.
CVE-2026-71362
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
CISA KEV Alert: Added on 9/24/2026. Action due: 9/27/2026.
CVE-2026-93616
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
CISA KEV Alert: Added on 9/22/2026. Action due: 9/25/2026.
CVE-2026-94127
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.
CISA KEV Alert: Added on 9/22/2026. Action due: 9/25/2026.
CVE-2026-93952
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
CISA KEV Alert: Added on 9/22/2026. Action due: 9/25/2026.
CVE-2026-7273
Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
CISA KEV Alert: Added on 9/21/2026. Action due: 9/24/2026.
CVE-2026-53266
Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CISA KEV Alert: Added on 9/18/2026. Action due: 9/21/2026.
CVE-2025-39964
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
CISA KEV Alert: Added on 9/18/2026. Action due: 9/21/2026.
CVE-2025-39682
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CISA KEV Alert: Added on 9/18/2026. Action due: 9/21/2026.
CVE-2026-76460
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
CISA KEV Alert: Added on 9/16/2026. Action due: 9/19/2026.
CVE-2026-58704
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
CISA KEV Alert: Added on 9/16/2026. Action due: 9/19/2026.
CVE-2026-87886
Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.
CISA KEV Alert: Added on 9/16/2026. Action due: 9/19/2026.
CVE-2026-76461
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.
CISA KEV Alert: Added on 9/14/2026. Action due: 9/17/2026.
CVE-2026-42018
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
CISA KEV Alert: Added on 9/11/2026. Action due: 9/25/2026.
CVE-2026-85706
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
CISA KEV Alert: Added on 9/11/2026. Action due: 9/14/2026.
CVE-2026-84869
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation.
CISA KEV Alert: Added on 9/11/2026. Action due: 9/14/2026.
CVE-2026-85102
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
CISA KEV Alert: Added on 9/22/2026. Action due: 9/25/2026.
CVE-2025-25249
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
CISA KEV Alert: Added on 9/9/2026. Action due: 9/12/2026.
CVE-2026-87491
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CISA KEV Alert: Added on 9/9/2026. Action due: 9/23/2026.
CVE-2026-20079
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
CISA KEV Alert: Added on 9/9/2026. Action due: 9/12/2026.
CVE-2026-81963
Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
CISA KEV Alert: Added on 9/8/2026. Action due: 9/22/2026.
CVE-2026-75650
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CISA KEV Alert: Added on 9/8/2026. Action due: 9/11/2026.
CVE-2026-85880
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
CISA KEV Alert: Added on 9/8/2026. Action due: 9/22/2026.
CVE-2026-86218
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
CISA KEV Alert: Added on 9/8/2026. Action due: 9/11/2026.
CVE-2026-86060
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CISA KEV Alert: Added on 9/10/2026. Action due: 9/13/2026.
CVE-2026-67279
RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CISA KEV Alert: Added on 9/25/2026. Action due: 9/28/2026.
CVE-2026-67277
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CISA KEV Alert: Added on 9/10/2026. Action due: 9/13/2026.
CVE-2026-85046
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CISA KEV Alert: Added on 9/4/2026. Action due: 9/18/2026.
CVE-2026-9586
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
CISA KEV Alert: Added on 9/2/2026. Action due: 9/5/2026.
CVE-2026-83549
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
CISA KEV Alert: Added on 9/2/2026. Action due: 9/5/2026.
CVE-2026-59822
BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.
CISA KEV Alert: Added on 9/2/2026. Action due: 9/16/2026.
CVE-2026-83548
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CISA KEV Alert: Added on 9/2/2026. Action due: 9/5/2026.
CVE-2026-82329
JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.
CISA KEV Alert: Added on 9/2/2026. Action due: 9/5/2026.
CVE-2026-48710
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
CISA KEV Alert: Added on 9/2/2026. Action due: 9/16/2026.
CVE-2026-82078
PaperCut NG/MF contains an unsafe reflection vulnerability that allows an attacker to manipulate system configuration parameters and execute arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process. This vulnerability can be chained with CVE-2026-81578.
CISA KEV Alert: Added on 8/28/2026. Action due: 9/11/2026.
CVE-2026-81578
PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.
CISA KEV Alert: Added on 8/28/2026. Action due: 9/11/2026.
CVE-2026-66384
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.
CISA KEV Alert: Added on 8/27/2026. Action due: 9/10/2026.
CVE-2023-49105
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured.
CISA KEV Alert: Added on 8/27/2026. Action due: 8/30/2026.
CVE-2015-5287
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CISA KEV Alert: Added on 8/26/2026. Action due: 9/9/2026.
CVE-2026-8452
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
CISA KEV Alert: Added on 8/26/2026. Action due: 8/29/2026.
CVE-2021-23758
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
CISA KEV Alert: Added on 8/26/2026. Action due: 9/9/2026.
CVE-2022-0995
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
CISA KEV Alert: Added on 8/26/2026. Action due: 9/9/2026.
CVE-2015-3246
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
CISA KEV Alert: Added on 8/26/2026. Action due: 9/9/2026.
CVE-2019-1068
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
CISA KEV Alert: Added on 8/26/2026. Action due: 8/29/2026.
CVE-2026-60004
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
CISA KEV Alert: Added on 8/25/2026. Action due: 8/28/2026.
CVE-2026-21962
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data.
CISA KEV Alert: Added on 8/24/2026. Action due: 8/27/2026.