Skip to content

Daily CVE Report — 2026-05-21 (67 CVEs, 9 critical) #11

Description

@github-actions

Daily CVE Report — 2026-05-21

67 CVEs published in the last 24 hours with CVSS ≥ 7.0

  • 🔴 Critical (9.0–10.0): 9
  • 🟠 High (7.0–8.9): 58

IOCs listed are potential indicators based on vulnerability class — treat as a starting point for threat hunting, not confirmed detections.


CVE-2026-20223 | CVSS 10.0 🔴 CRITICAL

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-20223
Weakness: CWE-306

Situation

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role.

This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user. 

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-45444 | CVSS 10.0 🔴 CRITICAL

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-45444
Weakness: CWE-434

Situation

Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files.

This issue affects Gift Cards For WooCommerce Pro: from n/a through 4.2.6.

Potential IOCs

  • Unexpected file types uploaded to the server
  • New executable files in upload directories
  • Unexpected outbound connections from upload directories

Remediation


CVE-2026-44050 | CVSS 9.9 🔴 CRITICAL

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44050
Weakness: CWE-122

Situation

A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause a denial of service.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-9139 | CVSS 9.8 🔴 CRITICAL

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9139
Weakness: CWE-798

Situation

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where authentication is implemented entirely in client-side JavaScript in login.zhtml, exposing static plaintext credentials in the page source. Unauthenticated attackers with network access can recover administrative credentials directly from the client-side validate() function to obtain full administrative access to the device.

Potential IOCs

  • Successful logins from unexpected IPs using default credentials
  • Brute-force attempts against known default accounts

Remediation


CVE-2026-9141 | CVSS 9.8 🔴 CRITICAL

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9141
Weakness: CWE-306

Situation

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers to access internal application pages without any session management or server-side authentication checks. Attackers with network access can directly request internal resources such as index.zhtml, point.zhtml, and log.shtml to gain full administrative read and write access, enabling unauthorized modification of alarm routing, device configuration, and disruption of monitoring and control functions.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-6279 | CVSS 9.8 🔴 CRITICAL

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-6279
Weakness: CWE-74

Situation

The Avada Builder (fusion-builder) plugin for WordPress is vulnerable to Unauthenticated Remote Code Execution via PHP Function Injection in versions up to and including 3.15.2. This is due to the wp_conditional_tags case in Fusion_Builder_Conditional_Render_Helper::get_value() passing attacker-controlled values from a base64-decoded JSON blob directly to call_user_func() without any allowlist validation. This is exploitable by unauthenticated attackers through the fusion_get_widget_markup AJAX endpoint, which is registered for non-privileged (unauthenticated) users via wp_ajax_nopriv_fusion_get_widget_markup. The endpoint is protected only by a nonce (fusion_load_nonce), but this nonce is generated for user ID 0 and is deterministically exposed in the JavaScript output of any public-facing page containing a Post Cards ([fusion_post_cards]) or Table of Contents ([fusion_table_of_contents]) element. This makes it possible for unauthenticated attackers to execute arbitrary code on affected sites.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-8598 | CVSS 9.1 🔴 CRITICAL

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-8598
Weakness: CWE-288

Situation

An undocumented configuration export port is accessible on some models
of ZKTeco CCTV cameras. This port does not require authentication and
exposes critical information about the camera such as open services and
camera account credentials.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-5433 | CVSS 9.1 🔴 CRITICAL

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-5433

Situation

Honeywell Control
Network Module (CNM) contains command injection vulnerability
in the web interface. An attacker could exploit this vulnerability via command
delimiters, potentially resulting in Remote Code Execution (RCE).

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-22314 | CVSS 9.0 🔴 CRITICAL

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-22314
Weakness: CWE-94

Situation

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

Potential IOCs

  • Unexpected code execution events in app logs
  • New processes spawned by the application runtime

Remediation


CVE-2026-24425 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-24425
Weakness: CWE-693

Situation

Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-44925 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44925
Weakness: CWE-352

Situation

Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-44926 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44926
Weakness: CWE-284

Situation

InfoScale CmdServer before 7.4.2 mishandles access control.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-24217 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-24217
Weakness: CWE-29

Situation

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-9111 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9111
Weakness: CWE-416

Situation

Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Potential IOCs

  • Heap corruption indicators in crash/core dumps
  • Unexpected memory access violations in system logs

Remediation


CVE-2026-9112 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9112
Weakness: CWE-416

Situation

Use after free in GPU in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Potential IOCs

  • Heap corruption indicators in crash/core dumps
  • Unexpected memory access violations in system logs

Remediation


CVE-2026-9114 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9114
Weakness: CWE-416

Situation

Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)

Potential IOCs

  • Heap corruption indicators in crash/core dumps
  • Unexpected memory access violations in system logs

Remediation


CVE-2026-9118 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9118
Weakness: CWE-416

Situation

Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Potential IOCs

  • Heap corruption indicators in crash/core dumps
  • Unexpected memory access violations in system logs

Remediation


CVE-2026-9119 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9119
Weakness: CWE-122

Situation

Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-9120 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9120
Weakness: CWE-416

Situation

Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

Potential IOCs

  • Heap corruption indicators in crash/core dumps
  • Unexpected memory access violations in system logs

Remediation


CVE-2026-9121 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9121
Weakness: CWE-125

Situation

Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

Potential IOCs

  • Out-of-bounds read signals in crash reports
  • Application crashes or unexpected exits

Remediation


CVE-2026-9126 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9126
Weakness: CWE-416

Situation

Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

Potential IOCs

  • Heap corruption indicators in crash/core dumps
  • Unexpected memory access violations in system logs

Remediation


CVE-2026-44047 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44047
Weakness: CWE-89

Situation

An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial of service.

Potential IOCs

  • SQL syntax strings in HTTP parameters or logs
  • Excessive database error responses (500s)
  • Unusual database query volumes or timings

Remediation


CVE-2026-44048 | CVSS 8.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44048
Weakness: CWE-121

Situation

A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-40165 | CVSS 8.7 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-40165
Weakness: CWE-91, CWE-287, CWE-436

Situation

authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Injection. Due to how authentik extracted the NameID value from a SAML assertion, it was possible for an attacker to trick authentik into only seeing a part of the NameID value, potentially allowing an attacker to gain access to other accounts. This issue could be exploited on an authentik instance with a SAML Source, where the attacker had an account on the SAML Source and the ability to modify their NameID value (commonly username or E-mail), and XML Signing was enabled. The attacker could modify the SAML assertion given to authentik by injecting a comment within the NameID value, which effectively truncated the NameID value to the snippet before the comment, and gave the attacker access to any user account. This issue has been fixed in versions 2025.12.5 and 2026.2.3.

Potential IOCs

  • Authentication bypass attempts in access logs
  • Logins without corresponding credential validation events
  • Sessions created without prior authentication events

Remediation


CVE-2026-39310 | CVSS 8.6 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-39310
Weakness: CWE-284, CWE-306

Situation

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3) allows full authentication bypass when running in an Electron environment. When Trilium detects an Electron environment, it explicitly disables authentication middleware for the Clipper API, exposing endpoints such as /api/clipper/notes to the network with no password, API token, or CSRF protection. An attacker on a shared network (for example, a corporate LAN or public Wi-Fi) can scan for open high-range ports using a tool like nmap, since Trilium often binds to ports such as 37840. Once a candidate port is found, an unauthenticated request to the Clipper handshake endpoint, which also bypasses authentication, confirms a Trilium instance by returning the application name and protocol version. This facilitates unauthorized data access, phishing, and local system compromise. The issue has been fixed in version 0.102.2.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-9157 | CVSS 8.4 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9157
Weakness: CWE-20, CWE-434

Situation

Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion.

This issue affects Web Fax: from 3.0 before 3.1.

Potential IOCs

  • Malformed or oversized input in application logs
  • Validation error spikes in application metrics
  • Unexpected file types uploaded to the server
  • New executable files in upload directories
  • Unexpected outbound connections from upload directories

Remediation


CVE-2026-24188 | CVSS 8.2 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-24188
Weakness: CWE-787

Situation

NVIDIA TensorRT contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to data tampering.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-45584 | CVSS 8.1 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-45584
Affected: microsoft malware_protection_engine
Weakness: CWE-122

Situation

Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-24218 | CVSS 8.1 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-24218
Weakness: CWE-321

Situation

NVIDIA DGX OS contains a vulnerability in the factory provisioning process, where the cloning of a base image causes identical SSH host keys to be deployed across multiple systems. The sharing of cryptographic identifiers across all similarly provisioned systems enables host impersonation or attacker-in-the-middle attacks. A successful exploit of this vulnerability might lead to code execution, data tampering, escalation of privileges, information disclosure, and denial of service.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-44051 | CVSS 8.1 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44051
Weakness: CWE-59

Situation

An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite arbitrary files via attacker-controlled symlink creation.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2025-11954 | CVSS 8.0 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-11954
Weakness: CWE-352

Situation

Cross-Site request forgery (CSRF) vulnerability in Sitemio Information Technologies Trade Ltd. Co. WISECP allows Cross Site Request Forgery.

This issue affects WISECP: through 20022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-4858 | CVSS 8.0 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-4858
Weakness: CWE-22

Situation

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermost auth token using via path traversal in integration action URL.. Mattermost Advisory ID: MMSA-2026-00640

Potential IOCs

  • Directory traversal sequences (../) in request paths
  • Access to files outside expected document root in logs

Remediation


CVE-2026-0856 | CVSS 7.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-0856
Weakness: CWE-284

Situation

Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables a normal user gaining access to the admin panel. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-41091 | CVSS 7.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-41091
Affected: microsoft malware_protection_engine
Weakness: CWE-59

Situation

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-42834 | CVSS 7.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42834
Affected: microsoft windows_admin_center
Weakness: CWE-59

Situation

Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-22554 | CVSS 7.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-22554
Weakness: CWE-122

Situation

MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-24216 | CVSS 7.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-24216
Weakness: CWE-502

Situation

NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

Potential IOCs

  • Malformed or unexpected serialized objects in requests
  • Unexpected object instantiation or class-loading in app logs

Remediation


CVE-2026-28764 | CVSS 7.8 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-28764
Weakness: CWE-823

Situation

MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-9133 | CVSS 7.7 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9133
Weakness: CWE-489

Situation

Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process.

To remediate this issue, customers should upgrade to version 0.2.1 of rabbitmq-aws. If RabbitMQ is configured to use TLS for connections, we also recommend rotating any associated private certificate keys.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-42383 | CVSS 7.6 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42383
Weakness: CWE-89

Situation

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooCommerce Product Add-Ons allows Blind SQL Injection.

This issue affects YITH WooCommerce Product Add-Ons: from n/a through 4.29.0.

Potential IOCs

  • SQL syntax strings in HTTP parameters or logs
  • Excessive database error responses (500s)
  • Unusual database query volumes or timings

Remediation


CVE-2026-5783 | CVSS 7.6 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-5783
Weakness: CWE-79

Situation

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Software Design Industry and Trade Ltd. Co. CityPLus allows Reflected XSS.

This issue affects CityPLus: before V24.29750.1.0.

Potential IOCs

  • Script tags or encoded JS in user-supplied input
  • Unexpected outbound requests from client browsers
  • CSP violation reports

Remediation


CVE-2026-9144 | CVSS 7.6 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9144
Weakness: CWE-79

Situation

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedded web configuration interface that allows authenticated attackers to execute persistent JavaScript by fragmenting malicious payloads across multiple administrative form fields. Attackers can bypass front-end length restrictions using JavaScript comments and template literals to concatenate executable script fragments that are rendered in administrative dashboard views such as index.zhtml, resulting in persistent script execution within administrative sessions.

Potential IOCs

  • Script tags or encoded JS in user-supplied input
  • Unexpected outbound requests from client browsers
  • CSP violation reports

Remediation


CVE-2026-44068 | CVSS 7.6 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44068
Weakness: CWE-22

Situation

Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.

Potential IOCs

  • Directory traversal sequences (../) in request paths
  • Access to files outside expected document root in logs

Remediation


CVE-2026-3039 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-3039
Weakness: CWE-771

Situation

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS environments.
This issue affects BIND 9 versions 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-5946 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-5946
Weakness: CWE-20, CWE-125, CWE-617, CWE-754, CWE-843

Situation

Multiple flaws have been identified in named related to the handling of DNS messages whose CLASS is not Internet (IN) — for example, CHAOS or HESIOD, or DNS messages that specify meta-classes (ANY or NONE) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (UPDATE), zone change notifications (NOTIFY), or processing of IN-specific record types in non-IN data — can cause assertion failures in named.
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

Potential IOCs

  • Malformed or oversized input in application logs
  • Validation error spikes in application metrics
  • Out-of-bounds read signals in crash reports
  • Application crashes or unexpected exits

Remediation


CVE-2026-5947 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-5947
Weakness: CWE-362, CWE-416

Situation

Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the "recursive-clients" limit is reached (as would occur during a query flood), and that same DNS message is discarded per the limit, there is a brief window of time while the SIG(0) validation may attempt to read the now-discarded DNS message.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1.
BIND 9 versions 9.18.28 through 9.18.49 and 9.18.28-S1 through 9.18.49-S1 are NOT affected.

Potential IOCs

  • Heap corruption indicators in crash/core dumps
  • Unexpected memory access violations in system logs

Remediation


CVE-2025-32750 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-32750
Weakness: CWE-548

Situation

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-39047 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-39047
Weakness: CWE-121

Situation

Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Printing Service (JetDirect) on TCP port 9100

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-20239 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-20239
Weakness: CWE-532

Situation

In Splunk Enterprise versions below 10.2.2 and 10.0.5, and Splunk Cloud Platform versions below 10.3.2512.8, 10.2.2510.11, 10.1.2507.21, and 10.0.2503.13, a user with a role that has access to the _internal index could view session cookies and response bodies that contain sensitive data.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-9117 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9117
Weakness: CWE-843

Situation

Type Confusion in GFX in Google Chrome on Linux, ChromeOS prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-9123 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-9123
Weakness: CWE-122

Situation

Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: Medium)

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-40092 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-40092
Weakness: CWE-252

Situation

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademlia DHT record. The maliciously crafted record would contain a TaggedSigned<ValidatorRecord, KeyPair> with a signature field whose byte length is not exactly 64 in order to cause a crash. When the victim node's DHT verifier calls TaggedSigned::verify, execution reaches Ed25519Signature::from_bytes(sig).unwrap() in the TaggedPublicKey implementation for Ed25519PublicKey. The from_bytes call fails because ed25519_zebra::Signature::try_from rejects slices not 64 bytes, and the unwrap() panics. The BLS TaggedPublicKey implementation correctly returns false on error; only the Ed25519 implementation panics. This issue has been fixed in version 1.4.0.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-44049 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44049
Weakness: CWE-787

Situation

An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character data.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-44052 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44052
Weakness: CWE-532

Situation

Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker with access to the log files to obtain LDAP credentials.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-44055 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44055
Weakness: CWE-78

Situation

A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to inject OS commands and execute arbitrary code.

Potential IOCs

  • Unexpected child processes spawned by the web/app server
  • Unusual system command executions in OS audit logs
  • New cron jobs or scheduled tasks

Remediation


CVE-2026-44060 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44060
Weakness: CWE-191

Situation

An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to cause a denial of service via a crafted DSI write request.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-44062 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44062
Weakness: CWE-787

Situation

A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character set data.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-42001 | CVSS 7.5 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42001

Situation

Insufficient Validation of Autoprimary SOA Queries

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-3593 | CVSS 7.4 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-3593
Weakness: CWE-416

Situation

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1.
BIND 9 versions 9.18.0 through 9.18.48 and 9.18.11-S1 through 9.18.48-S1 are NOT affected.

Potential IOCs

  • Heap corruption indicators in crash/core dumps
  • Unexpected memory access violations in system logs

Remediation


CVE-2026-39850 | CVSS 7.4 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-39850
Weakness: CWE-20, CWE-98

Situation

Yii 2 is a PHP application framework. Versions 2.0.54 and prior contain flawed logic in the core view rendering method View::renderPhpFile() that leads to Local File Inclusion. The function calls extract($params, EXTR_OVERWRITE) before the require statement that loads the view file. As a result, a caller-controlled file key in the $params array overwrites the internal local variable specifying which file to include, potentially enabling RCE if an attacker can write PHP files through a separate primitive, as well as information disclosure. This issue has been fixed in version 2.0.55.

Potential IOCs

  • Malformed or oversized input in application logs
  • Validation error spikes in application metrics

Remediation


CVE-2026-44053 | CVSS 7.4 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44053
Weakness: CWE-327

Situation

Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote attacker to obtain authentication credentials or impersonate a user via cryptanalytic attack.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-22315 | CVSS 7.2 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-22315
Weakness: CWE-266

Situation

Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables the export  of user data, including cleartext passwords, via the SQL editor. This issue affects Meona Client Launcher Component: through 19.06.2020 15:11:49; Meona Server Component: through 2025.04 5+323020.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation


CVE-2026-7613 | CVSS 7.2 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-7613
Weakness: CWE-79

Situation

The Cost of Goods by PixelYourSite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csvdata[0][cost_of_goods_value]' parameter in versions up to, and including, 1.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Potential IOCs

  • Script tags or encoded JS in user-supplied input
  • Unexpected outbound requests from client browsers
  • CSP violation reports

Remediation


CVE-2026-44058 | CVSS 7.2 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44058
Weakness: CWE-287

Situation

An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenticate as an arbitrary user via the admin auth user mechanism.

Potential IOCs

  • Authentication bypass attempts in access logs
  • Logins without corresponding credential validation events
  • Sessions created without prior authentication events

Remediation


CVE-2026-44064 | CVSS 7.1 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44064
Weakness: CWE-125

Situation

An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited information or cause a denial of service via a crafted ASP request.

Potential IOCs

  • Out-of-bounds read signals in crash reports
  • Application crashes or unexpected exits

Remediation


CVE-2026-44066 | CVSS 7.1 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-44066
Weakness: CWE-125

Situation

Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote authenticated attacker to obtain sensitive information or cause a minor service disruption.

Potential IOCs

  • Out-of-bounds read signals in crash reports
  • Application crashes or unexpected exits

Remediation


CVE-2026-29518 | CVSS 7.0 🟠 HIGH

NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-29518
Weakness: CWE-367

Situation

Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitive system files and achieving privilege escalation when the daemon runs with elevated privileges. This vulnerability can only be triggered if the chroot setting is false.

Potential IOCs

  • Unexpected outbound network connections from the affected service
  • Unusual process creation or privilege escalation events
  • New or modified files in application directories
  • Spike in error rates or application crashes around the affected component

Remediation



Generated by daily-cves · Source: NVD

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions