top of page
Cyber Security, Compliance & Business Continuity Update
There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop. On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations
Last Update: August 2026
Title | CVE ID | Vendor | Product | Vulnerability Name | Date Added | Short Description | Likely Attack Vector |
|---|---|---|---|---|---|---|---|
CVE-2021-1905 | Qualcomm | Multiple Chipsets | Qualcomm Multiple Chipsets Use-After-Free Vulnerability | 03 November 2021 | Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously. | Application/System Exploitation | |
CVE-2020-10221 | rConfig | rConfig | rConfig OS Command Injection Vulnerability | 03 November 2021 | rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter. | Application/System Exploitation | |
CVE-2021-35395 | Realtek | AP-Router SDK | Realtek AP-Router SDK Buffer Overflow Vulnerability | 03 November 2021 | Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS). | Application/System Exploitation | |
CVE-2017-16651 | Roundcube | Roundcube Webmail | Roundcube Webmail File Disclosure Vulnerability | 03 November 2021 | Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins which are used by default. | Phishing (Malicious Attachment) | |
CVE-2020-11652 | SaltStack | Salt | SaltStack Salt Path Traversal Vulnerability | 03 November 2021 | SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. | Application/System Exploitation | |
CVE-2020-11651 | SaltStack | Salt | SaltStack Salt Authentication Bypass Vulnerability | 03 November 2021 | SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability. | Application/System Exploitation | |
CVE-2020-16846 | SaltStack | Salt | SaltStack Salt Shell Injection Vulnerability | 03 November 2021 | SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API. | Direct Remote Network Attack | |
CVE-2018-2380 | SAP | Customer Relationship Management (CRM) | SAP Customer Relationship Management (CRM) Path Traversal Vulnerability | 03 November 2021 | SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users. | Application/System Exploitation | |
CVE-2010-5326 | SAP | NetWeaver | SAP NetWeaver Remote Code Execution Vulnerability | 03 November 2021 | SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication allowing for remote code execution via a HTTP or HTTPS request. | Direct Remote Network Attack | |
CVE-2016-9563 | SAP | NetWeaver | SAP NetWeaver XML External Entity (XXE) Vulnerability | 03 November 2021 | SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote authenticated users to conduct XML External Entity (XXE) attacks. | Application/System Exploitation | |
CVE-2020-6287 | SAP | NetWeaver | SAP NetWeaver Missing Authentication for Critical Function Vulnerability | 03 November 2021 | SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users. | Direct Remote Network Attack | |
CVE-2020-6207 | SAP | Solution Manager | SAP Solution Manager Missing Authentication for Critical Function Vulnerability | 03 November 2021 | SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager. | Application/System Exploitation | |
CVE-2016-3976 | SAP | NetWeaver | SAP NetWeaver Directory Traversal Vulnerability | 03 November 2021 | SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files. | Application/System Exploitation | |
CVE-2019-16256 | SIMalliance | Toolbox Browser | SIMalliance Toolbox Browser Command Injection Vulnerability | 03 November 2021 | SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message. | Application/System Exploitation | |
CVE-2020-10148 | SolarWinds | Orion | SolarWinds Orion Authentication Bypass Vulnerability | 03 November 2021 | SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands. | Application/System Exploitation | |
CVE-2021-35211 | SolarWinds | Serv-U | SolarWinds Serv-U Remote Code Execution Vulnerability | 03 November 2021 | SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution. | Direct Remote Network Attack | |
CVE-2016-3643 | SolarWinds | Virtualization Manager | SolarWinds Virtualization Manager Privilege Escalation Vulnerability | 03 November 2021 | SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo. | Application/System Exploitation | |
CVE-2020-10199 | Sonatype | Nexus Repository | Sonatype Nexus Repository Remote Code Execution Vulnerability | 03 November 2021 | Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution. | Direct Remote Network Attack | |
CVE-2021-20021 | SonicWall | SonicWall Email Security | SonicWall Email Security Improper Privilege Management Vulnerability | 03 November 2021 | SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation. | Perimeter Gateway Breach | |
CVE-2019-7481 | SonicWall | SMA100 | SonicWall SMA100 SQL Injection Vulnerability | 03 November 2021 | SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources. | Perimeter Gateway Breach | |
CVE-2021-20022 | SonicWall | SonicWall Email Security | SonicWall Email Security Unrestricted Upload of File Vulnerability | 03 November 2021 | SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation. | Perimeter Gateway Breach | |
CVE-2021-20023 | SonicWall | SonicWall Email Security | SonicWall Email Security Path Traversal Vulnerability | 03 November 2021 | SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation. | Perimeter Gateway Breach | |
CVE-2021-20016 | SonicWall | SSLVPN SMA100 | SonicWall SSLVPN SMA100 SQL Injection Vulnerability | 03 November 2021 | SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker. | Perimeter Gateway Breach | |
CVE-2020-12271 | Sophos | SFOS | Sophos SFOS SQL Injection Vulnerability | 03 November 2021 | Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s) portal admins and user accounts used for remote access (but not external Active Directory or LDAP passwords). | Perimeter Gateway Breach | |
CVE-2020-10181 | Sumavision | Enhanced Multimedia Router (EMR) | Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability | 03 November 2021 | Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device. | Application/System Exploitation | |
CVE-2017-6327 | Symantec | Symantec Messaging Gateway | Symantec Messaging Gateway Remote Code Execution Vulnerability | 03 November 2021 | Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution an attacker may also desire to perform privilege escalating actions. | Perimeter Gateway Breach | |
CVE-2019-18988 | TeamViewer | Desktop | TeamViewer Desktop Bypass Remote Login Vulnerability | 03 November 2021 | TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system). | Application/System Exploitation | |
CVE-2017-9248 | Progress | ASP.NET AJAX and Sitefinity | Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability | 03 November 2021 | Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey) perform cross-site-scripting (XSS) attacks compromise the ASP.NET ViewState and/or upload and download files. | Application/System Exploitation | |
CVE-2021-31755 | Tenda | AC11 Router | Tenda AC11 Router Stack Buffer Overflow Vulnerability | 03 November 2021 | Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request. | Application/System Exploitation | |
CVE-2020-10987 | Tenda | AC1900 Router AC15 Model | Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability | 03 November 2021 | Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter. | Application/System Exploitation | |
CVE-2018-14558 | Tenda | AC7, AC9, and AC10 Routers | Tenda AC7 AC9 and AC10 Routers Command Injection Vulnerability | 03 November 2021 | Tenda AC7 AC9 and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request. | Application/System Exploitation | |
CVE-2018-20062 | ThinkPHP | noneCms | ThinkPHP "noneCms" Remote Code Execution Vulnerability | 03 November 2021 | ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter. | Direct Remote Network Attack | |
CVE-2019-9082 | ThinkPHP | ThinkPHP | ThinkPHP Remote Code Execution Vulnerability | 03 November 2021 | ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command. | Direct Remote Network Attack | |
CVE-2019-18187 | Trend Micro | OfficeScan | Trend Micro OfficeScan Directory Traversal Vulnerability | 03 November 2021 | Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server leading to remote code execution. | Direct Remote Network Attack | |
CVE-2020-8467 | Trend Micro | Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability | 03 November 2021 | Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution. | Direct Remote Network Attack | |
CVE-2020-8468 | Trend Micro | Apex One, OfficeScan and Worry-Free Business Security Agents | Trend Micro Multiple Products Content Validation Escape Vulnerability | 03 November 2021 | Trend Micro Apex One OfficeScan and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components. | Application/System Exploitation | |
CVE-2020-24557 | Trend Micro | Apex One, OfficeScan, and Worry-Free Business Security | Trend Micro Multiple Products Improper Access Control Vulnerability | 03 November 2021 | Trend Micro Apex One OfficeScan and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily abuse a specific Windows function and attain privilege escalation. | Application/System Exploitation | |
CVE-2020-8599 | Trend Micro | Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability | 03 November 2021 | Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login. | Application/System Exploitation | |
CVE-2021-36742 | Trend Micro | Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Multiple Products Improper Input Validation Vulnerability | 03 November 2021 | Trend Micro Apex One Apex One as a Service and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation. | Application/System Exploitation | |
CVE-2021-36741 | Trend Micro | Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Multiple Products Improper Input Validation Vulnerability | 03 November 2021 | Trend Micro Apex One Apex One as a Service and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files. | Application/System Exploitation | |
CVE-2019-20085 | TVT | NVMS-1000 | TVT NVMS-1000 Directory Traversal Vulnerability | 03 November 2021 | TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests. | Application/System Exploitation | |
CVE-2020-5849 | Unraid | Unraid | Unraid Authentication Bypass Vulnerability | 03 November 2021 | Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution. | Direct Remote Network Attack | |
CVE-2020-5847 | Unraid | Unraid | Unraid Remote Code Execution Vulnerability | 03 November 2021 | Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access. | Application/System Exploitation | |
CVE-2019-16759 | vBulletin | vBulletin | vBulletin PHP Module Remote Code Execution Vulnerability | 03 November 2021 | The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request. | Direct Remote Network Attack | |
CVE-2020-17496 | vBulletin | vBulletin | vBulletin PHP Module Remote Code Execution Vulnerability | 03 November 2021 | The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759. | Direct Remote Network Attack | |
CVE-2019-5544 | VMware | VMware ESXi and Horizon DaaS | VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability | 03 November 2021 | VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution. | Direct Remote Network Attack | |
CVE-2020-3992 | VMware | ESXi | VMware ESXi OpenSLP Use-After-Free Vulnerability | 03 November 2021 | VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution. | Direct Remote Network Attack | |
CVE-2020-3950 | VMware | Multiple Products | VMware Multiple Products Privilege Escalation Vulnerability | 03 November 2021 | VMware Fusion Remote Console (VMRC) for Mac and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root. | Application/System Exploitation | |
CVE-2021-22005 | VMware | vCenter Server | VMware vCenter Server File Upload Vulnerability | 03 November 2021 | VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code. | Application/System Exploitation | |
CVE-2020-3952 | VMware | vCenter Server | VMware vCenter Server Information Disclosure Vulnerability | 03 November 2021 | VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information. | Application/System Exploitation | |
CVE-2021-21972 | VMware | vCenter Server | VMware vCenter Server Remote Code Execution Vulnerability | 03 November 2021 | VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system. | Direct Remote Network Attack | |
CVE-2021-21985 | VMware | vCenter Server | VMware vCenter Server Improper Input Validation Vulnerability | 03 November 2021 | VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server which allows for remote code execution. | Direct Remote Network Attack | |
CVE-2020-4006 | VMware | Multiple Products | Multiple VMware Products Command Injection Vulnerability | 03 November 2021 | VMware Workspace One Access Access Connector Identity Manager and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system. | Direct Remote Network Attack | |
CVE-2020-25213 | WordPress | File Manager Plugin | WordPress File Manager Plugin Remote Code Execution Vulnerability | 03 November 2021 | WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site. | Direct Remote Network Attack | |
CVE-2020-11738 | WordPress | Snap Creek Duplicator Plugin | WordPress Snap Creek Duplicator Plugin File Download Vulnerability | 03 November 2021 | WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro. | Application/System Exploitation | |
CVE-2019-9978 | WordPress | Social Warfare Plugin | WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability | 03 November 2021 | WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro. | Direct Remote Network Attack | |
CVE-2021-27561 | Yealink | Device Management | Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability | 03 November 2021 | Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution. | Direct Remote Network Attack | |
CVE-2021-40539 | Zoho | ManageEngine | Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability | 03 November 2021 | Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution. | Direct Remote Network Attack | |
CVE-2020-10189 | Zoho | ManageEngine | Zoho ManageEngine Desktop Central File Upload Vulnerability | 03 November 2021 | Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution. | Direct Remote Network Attack | |
CVE-2019-8394 | Zoho | ManageEngine | Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability | 03 November 2021 | Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization. | Application/System Exploitation | |
CVE-2020-29583 | Zyxel | Multiple Products | Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability | 03 November 2021 | Zyxel firewalls (ATP USG VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password. | Perimeter Gateway Breach | |
CVE-2026-63077 | JetBrains | TeamCity | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | 05 August 2026 | JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. | Direct Remote Network Attack | |
CVE-2026-18556 | N-able | N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 04 August 2026 | N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. | Application/System Exploitation | |
CVE-2026-34486 | Apache | Tomcat | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | 04 August 2026 | Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. | Application/System Exploitation | |
CVE-2026-9198 | IBM | Langflow | IBM Langflow Code Injection Vulnerability | 04 August 2026 | Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. | Direct Remote Network Attack | |
CVE-2026-18577 | N-able | N-central | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | 03 August 2026 | N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. | Application/System Exploitation | |
CVE-2026-20316 | Cisco | Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | 29 July 2026 | Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. | Perimeter Gateway Breach | |
CVE-2025-68686 | Fortinet | FortiOS | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 27 July 2026 | Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability at filesystem level. | Perimeter Gateway Breach | |
CVE-2026-16812 | Arista | VeloCloud Orchestrator | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | 27 July 2026 | Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality integrity and availability of the orchestrator and data managed by the orchestrator. | Application/System Exploitation | |
CVE-2026-16232 | Check Point | SmartConsole | Check Point SmartConsole Improper Authentication Vulnerability | 22 July 2026 | Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. | Direct Remote Network Attack | |
CVE-2026-50522 | Microsoft | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 22 July 2026 | Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. | Phishing / User Interaction | |
CVE-2026-60137 | WordPress | Core | WordPress Core SQL Injection Vulnerability | 21 July 2026 | WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. | Direct Remote Network Attack | |
CVE-2026-63030 | WordPress | Core | WordPress Core Interpretation Conflict Vulnerability | 21 July 2026 | WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. | Direct Remote Network Attack | |
CVE-2026-0770 | Langflow | Langflow | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | 21 July 2026 | Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. | Application/System Exploitation | |
CVE-2021-27137 | DD-WRT | DD-WRT | DD-WRT Stack-Based Buffer Overflow Vulnerability | 21 July 2026 | DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. | Direct Remote Network Attack | |
CVE-2026-58644 | Microsoft | SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 16 July 2026 | Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. | Phishing / User Interaction | |
CVE-2026-25089 | Fortinet | FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | 16 July 2026 | Fortinet FortiSandbox FortiSandbox Cloud and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. | Perimeter Gateway Breach | |
CVE-2026-39808 | Fortinet | FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | 16 July 2026 | Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. | Perimeter Gateway Breach | |
CVE-2026-46817 | Oracle | E-Business Suite | Oracle E-Business Suite Improper Privilege Management Vulnerability | 15 July 2026 | Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. | Direct Remote Network Attack | |
CVE-2023-4346 | KNX Association | KNX Protocol Connection Authorization Option 1 | KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | 15 July 2026 | KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device. | Application/System Exploitation | |
CVE-2026-56155 | Microsoft | Active Directory Federation Services | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | 14 July 2026 | Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. | Application/System Exploitation | |
CVE-2026-56164 | Microsoft | SharePoint Server | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | 14 July 2026 | Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. | Application/System Exploitation | |
CVE-2026-15409 | SonicWall | SMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | 14 July 2026 | SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. | Perimeter Gateway Breach | |
CVE-2026-15410 | SonicWall | SMA1000 Appliances | SonicWall SMA1000 Appliances Code Injection Vulnerability | 14 July 2026 | SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. | Perimeter Gateway Breach | |
CVE-2008-4128 | Cisco | IOS | Cisco IOS Cross-Site Request Forgery Vulnerability | 13 July 2026 | Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. | Application/System Exploitation | |
CVE-2026-56291 | Balbooa | Forms | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | 10 July 2026 | Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE. | Direct Remote Network Attack | |
CVE-2026-48939 | iCagenda | iCagenda | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | 10 July 2026 | iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature ultimately resulting in PHP code upload and execution. | Phishing (Malicious Attachment) | |
CVE-2026-48908 | JoomShaper | SP Page Builder | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | 07 July 2026 | JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files ultimately resulting in the upload and execution of PHP code. | Direct Remote Network Attack | |
CVE-2026-55255 | Langflow | Langflow | Langflow Authorization Bypass Through User-Controlled Key Vulnerability | 07 July 2026 | Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. | Application/System Exploitation | |
CVE-2026-56290 | Joomlack | Page Builder | Joomlack Page Builder Improper Access Control Vulnerability | 07 July 2026 | Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload. | Direct Remote Network Attack | |
CVE-2026-48282 | Adobe | ColdFusion | Adobe ColdFusion Path Traversal Vulnerability | 07 July 2026 | Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. | Phishing / User Interaction | |
CVE-2026-45659 | Microsoft | SharePoint Server | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | 01 July 2026 | Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. | Application/System Exploitation | |
CVE-2026-48558 | SimpleHelp | SimpleHelp | SimpleHelp Authentication Bypass Vulnerability | 29 June 2026 | SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration a remote unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations this may also allow bypass of multi-factor authentication. | Direct Remote Network Attack | |
CVE-2026-12569 | PTC | Windchill and FlexPLM | PTC Windchill and FlexPLM Improper Input Validation Vulnerability | 25 June 2026 | PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated remote attacker to execute arbitrary code by sending a malicious request to the network. | Direct Remote Network Attack | |
CVE-2026-20230 | Cisco | Unified Communications Manager | Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability | 25 June 2026 | Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated remote attacker to write files to the underlying operating system that could be used later to elevate to root. | Direct Remote Network Attack | |
CVE-2025-67038 | Lantronix | EDS5000 | Lantronix EDS5000 Code Injection Vulnerability | 23 June 2026 | Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges. | Application/System Exploitation | |
CVE-2026-34910 | Ubiquiti | UniFi OS | Ubiquiti UniFi OS Improper Input Validation Vulnerability | 23 June 2026 | Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection. | Application/System Exploitation | |
CVE-2026-34909 | Ubiquiti | UniFi OS | Ubiquiti UniFi OS Path Traversal Vulnerability | 23 June 2026 | Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account. | Application/System Exploitation | |
CVE-2026-34908 | Ubiquiti | UniFi OS | Ubiquiti UniFi OS Improper Access Control Vulnerability | 23 June 2026 | Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system. | Application/System Exploitation | |
CVE-2026-20253 | Splunk | Enterprise | Splunk Enterprise Missing Authentication for Critical Function Vulnerability | 18 June 2026 | Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. | Direct Remote Network Attack |
Opeining times are listed here
Follow or connect with Steve, RiskCentric's owner & founder via LinkedIn
bottom of page



