top of page

Cyber Security, Compliance & Business Continuity Update

There's always something on the horizon with business continuity and cyber security: regulations change, new expectations arise and industry intelligence continues to develop.  On this page we maintain a curated list of developments and issues that could affect the information security and business continuity arrangements of SME organisations

Last Update: August 2026

Title
CVE ID
Vendor
Product
Vulnerability Name
Date Added
Short Description
Likely Attack Vector
CVE-2021-1905
Qualcomm
Multiple Chipsets
Qualcomm Multiple Chipsets Use-After-Free Vulnerability
03 November 2021
Multiple Qualcomm Chipsets contain a use after free vulnerability due to improper handling of memory mapping of multiple processes simultaneously.
Application/System Exploitation
CVE-2020-10221
rConfig
rConfig
rConfig OS Command Injection Vulnerability
03 November 2021
rConfig lib/ajaxHandlers/ajaxAddTemplate.php contains an OS command injection vulnerability that allows remote attackers to execute OS commands via shell metacharacters in the fileName POST parameter.
Application/System Exploitation
CVE-2021-35395
Realtek
AP-Router SDK
Realtek AP-Router SDK Buffer Overflow Vulnerability
03 November 2021
Realtek AP-Router SDK HTTP web server boa contains a buffer overflow vulnerability due to unsafe copies of some overly long parameters submitted in the form that lead to denial-of-service (DoS).
Application/System Exploitation
CVE-2017-16651
Roundcube
Roundcube Webmail
Roundcube Webmail File Disclosure Vulnerability
03 November 2021
Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins which are used by default.
Phishing (Malicious Attachment)
CVE-2020-11652
SaltStack
Salt
SaltStack Salt Path Traversal Vulnerability
03 November 2021
SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
Application/System Exploitation
CVE-2020-11651
SaltStack
Salt
SaltStack Salt Authentication Bypass Vulnerability
03 November 2021
SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some methods without authentication which can be used to retrieve user tokens from the salt master and/or run commands on salt minions. Salt users who follow fundamental internet security guidelines and best practices are not affected by this vulnerability.
Application/System Exploitation
CVE-2020-16846
SaltStack
Salt
SaltStack Salt Shell Injection Vulnerability
03 November 2021
SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users running the Salt API.
Direct Remote Network Attack
CVE-2018-2380
SAP
Customer Relationship Management (CRM)
SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
03 November 2021
SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.
Application/System Exploitation
CVE-2010-5326
SAP
NetWeaver
SAP NetWeaver Remote Code Execution Vulnerability
03 November 2021
SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication allowing for remote code execution via a HTTP or HTTPS request.
Direct Remote Network Attack
CVE-2016-9563
SAP
NetWeaver
SAP NetWeaver XML External Entity (XXE) Vulnerability
03 November 2021
SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote authenticated users to conduct XML External Entity (XXE) attacks.
Application/System Exploitation
CVE-2020-6287
SAP
NetWeaver
SAP NetWeaver Missing Authentication for Critical Function Vulnerability
03 November 2021
SAP NetWeaver Application Server Java Platforms contains a missing authentication for critical function vulnerability allowing unauthenticated access to execute configuration tasks and create administrative users.
Direct Remote Network Attack
CVE-2020-6207
SAP
Solution Manager
SAP Solution Manager Missing Authentication for Critical Function Vulnerability
03 November 2021
SAP Solution Manager User Experience Monitoring contains a missing authentication for critical function vulnerability which results in complete compromise of all SMDAgents connected to the Solution Manager.
Application/System Exploitation
CVE-2016-3976
SAP
NetWeaver
SAP NetWeaver Directory Traversal Vulnerability
03 November 2021
SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet. This allows remote attackers to read files.
Application/System Exploitation
CVE-2019-16256
SIMalliance
Toolbox Browser
SIMalliance Toolbox Browser Command Injection Vulnerability
03 November 2021
SIMalliance Toolbox Browser contains an command injection vulnerability that could allow remote attackers to retrieve location and IMEI information or execute a range of other attacks by modifying the attack message.
Application/System Exploitation
CVE-2020-10148
SolarWinds
Orion
SolarWinds Orion Authentication Bypass Vulnerability
03 November 2021
SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.
Application/System Exploitation
CVE-2021-35211
SolarWinds
Serv-U
SolarWinds Serv-U Remote Code Execution Vulnerability
03 November 2021
SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.
Direct Remote Network Attack
CVE-2016-3643
SolarWinds
Virtualization Manager
SolarWinds Virtualization Manager Privilege Escalation Vulnerability
03 November 2021
SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.
Application/System Exploitation
CVE-2020-10199
Sonatype
Nexus Repository
Sonatype Nexus Repository Remote Code Execution Vulnerability
03 November 2021
Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution.
Direct Remote Network Attack
CVE-2021-20021
SonicWall
SonicWall Email Security
SonicWall Email Security Improper Privilege Management Vulnerability
03 November 2021
SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.
Perimeter Gateway Breach
CVE-2019-7481
SonicWall
SMA100
SonicWall SMA100 SQL Injection Vulnerability
03 November 2021
SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.
Perimeter Gateway Breach
CVE-2021-20022
SonicWall
SonicWall Email Security
SonicWall Email Security Unrestricted Upload of File Vulnerability
03 November 2021
SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.
Perimeter Gateway Breach
CVE-2021-20023
SonicWall
SonicWall Email Security
SonicWall Email Security Path Traversal Vulnerability
03 November 2021
SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.
Perimeter Gateway Breach
CVE-2021-20016
SonicWall
SSLVPN SMA100
SonicWall SSLVPN SMA100 SQL Injection Vulnerability
03 November 2021
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
Perimeter Gateway Breach
CVE-2020-12271
Sophos
SFOS
Sophos SFOS SQL Injection Vulnerability
03 November 2021
Sophos Firewall operating system (SFOS) firmware contains a SQL injection vulnerability when configured with either the administration (HTTPS) service or the User Portal is exposed on the WAN zone. Successful exploitation may cause remote code execution to exfiltrate usernames and hashed passwords for the local device admin(s) portal admins and user accounts used for remote access (but not external Active Directory or LDAP passwords).
Perimeter Gateway Breach
CVE-2020-10181
Sumavision
Enhanced Multimedia Router (EMR)
Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability
03 November 2021
Sumavision Enhanced Multimedia Router (EMR) contains a cross-site request forgery (CSRF) vulnerability allowing the creation of users with elevated privileges as administrator on a device.
Application/System Exploitation
CVE-2017-6327
Symantec
Symantec Messaging Gateway
Symantec Messaging Gateway Remote Code Execution Vulnerability
03 November 2021
Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution an attacker may also desire to perform privilege escalating actions.
Perimeter Gateway Breach
CVE-2019-18988
TeamViewer
Desktop
TeamViewer Desktop Bypass Remote Login Vulnerability
03 November 2021
TeamViewer Desktop allows for bypass of remote-login access control because the same AES key is used for different customers' installations. If an attacker were to know this key they could decrypt protected information stored in registry or configuration files or decryption of the Unattended Access password to the system (which allows for remote login to the system).
Application/System Exploitation
CVE-2017-9248
Progress
ASP.NET AJAX and Sitefinity
Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
03 November 2021
Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey) perform cross-site-scripting (XSS) attacks compromise the ASP.NET ViewState and/or upload and download files.
Application/System Exploitation
CVE-2021-31755
Tenda
AC11 Router
Tenda AC11 Router Stack Buffer Overflow Vulnerability
03 November 2021
Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request.
Application/System Exploitation
CVE-2020-10987
Tenda
AC1900 Router AC15 Model
Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability
03 November 2021
Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter.
Application/System Exploitation
CVE-2018-14558
Tenda
AC7, AC9, and AC10 Routers
Tenda AC7 AC9 and AC10 Routers Command Injection Vulnerability
03 November 2021
Tenda AC7 AC9 and AC10 devices contain a command injection vulnerability due to the "formsetUsbUnload" function executes a dosystemCmd function with untrusted input. Successful exploitation allows an attacker to execute OS commands via a crafted goform/setUsbUnload request.
Application/System Exploitation
CVE-2018-20062
ThinkPHP
noneCms
ThinkPHP "noneCms" Remote Code Execution Vulnerability
03 November 2021
ThinkPHP "noneCms" contains an unspecified vulnerability that allows for remote code execution through crafted use of the filter parameter.
Direct Remote Network Attack
CVE-2019-9082
ThinkPHP
ThinkPHP
ThinkPHP Remote Code Execution Vulnerability
03 November 2021
ThinkPHP contains an unspecified vulnerability that allows for remote code execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
Direct Remote Network Attack
CVE-2019-18187
Trend Micro
OfficeScan
Trend Micro OfficeScan Directory Traversal Vulnerability
03 November 2021
Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server leading to remote code execution.
Direct Remote Network Attack
CVE-2020-8467
Trend Micro
Apex One and OfficeScan
Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability
03 November 2021
Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.
Direct Remote Network Attack
CVE-2020-8468
Trend Micro
Apex One, OfficeScan and Worry-Free Business Security Agents
Trend Micro Multiple Products Content Validation Escape Vulnerability
03 November 2021
Trend Micro Apex One OfficeScan and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components.
Application/System Exploitation
CVE-2020-24557
Trend Micro
Apex One, OfficeScan, and Worry-Free Business Security
Trend Micro Multiple Products Improper Access Control Vulnerability
03 November 2021
Trend Micro Apex One OfficeScan and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily abuse a specific Windows function and attain privilege escalation.
Application/System Exploitation
CVE-2020-8599
Trend Micro
Apex One and OfficeScan
Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability
03 November 2021
Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login.
Application/System Exploitation
CVE-2021-36742
Trend Micro
Apex One, Apex One as a Service, and Worry-Free Business Security
Trend Micro Multiple Products Improper Input Validation Vulnerability
03 November 2021
Trend Micro Apex One Apex One as a Service and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.
Application/System Exploitation
CVE-2021-36741
Trend Micro
Apex One, Apex One as a Service, and Worry-Free Business Security
Trend Micro Multiple Products Improper Input Validation Vulnerability
03 November 2021
Trend Micro Apex One Apex One as a Service and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.
Application/System Exploitation
CVE-2019-20085
TVT
NVMS-1000
TVT NVMS-1000 Directory Traversal Vulnerability
03 November 2021
TVT devices utilizing NVMS-1000 software contain a directory traversal vulnerability via GET /.. requests.
Application/System Exploitation
CVE-2020-5849
Unraid
Unraid
Unraid Authentication Bypass Vulnerability
03 November 2021
Unraid contains an authentication bypass vulnerability that allows attackers to gain access to the administrative interface. This CVE is chainable with CVE-2020-5847 for remote code execution.
Direct Remote Network Attack
CVE-2020-5847
Unraid
Unraid
Unraid Remote Code Execution Vulnerability
03 November 2021
Unraid contains a vulnerability due to the insecure use of the extract PHP function that can be abused to execute remote code as root. This CVE is chainable with CVE-2020-5849 for initial access.
Application/System Exploitation
CVE-2019-16759
vBulletin
vBulletin
vBulletin PHP Module Remote Code Execution Vulnerability
03 November 2021
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
Direct Remote Network Attack
CVE-2020-17496
vBulletin
vBulletin
vBulletin PHP Module Remote Code Execution Vulnerability
03 November 2021
The PHP module within vBulletin contains an unspecified vulnerability that allows for remote code execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. This CVE ID resolves an incomplete patch for CVE-2019-16759.
Direct Remote Network Attack
CVE-2019-5544
VMware
VMware ESXi and Horizon DaaS
VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability
03 November 2021
VMware ESXi and Horizon Desktop as a Service (DaaS) OpenSLP contains a heap-based buffer overflow vulnerability that allows an attacker with network access to port 427 to overwrite the heap of the OpenSLP service to perform remote code execution.
Direct Remote Network Attack
CVE-2020-3992
VMware
ESXi
VMware ESXi OpenSLP Use-After-Free Vulnerability
03 November 2021
VMware ESXi OpenSLP contains a use-after-free vulnerability that allows an attacker residing in the management network with access to port 427 to perform remote code execution.
Direct Remote Network Attack
CVE-2020-3950
VMware
Multiple Products
VMware Multiple Products Privilege Escalation Vulnerability
03 November 2021
VMware Fusion Remote Console (VMRC) for Mac and Horizon Client for Mac contain a privilege escalation vulnerability due to improper use of setuid binaries that allows attackers to escalate privileges to root.
Application/System Exploitation
CVE-2021-22005
VMware
vCenter Server
VMware vCenter Server File Upload Vulnerability
03 November 2021
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.
Application/System Exploitation
CVE-2020-3952
VMware
vCenter Server
VMware vCenter Server Information Disclosure Vulnerability
03 November 2021
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement access controls. Successful exploitation allows an attacker with network access to port 389 to extract sensitive information.
Application/System Exploitation
CVE-2021-21972
VMware
vCenter Server
VMware vCenter Server Remote Code Execution Vulnerability
03 November 2021
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.
Direct Remote Network Attack
CVE-2021-21985
VMware
vCenter Server
VMware vCenter Server Improper Input Validation Vulnerability
03 November 2021
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server which allows for remote code execution.
Direct Remote Network Attack
CVE-2020-4006
VMware
Multiple Products
Multiple VMware Products Command Injection Vulnerability
03 November 2021
VMware Workspace One Access Access Connector Identity Manager and Identity Manager Connector contain a command injection vulnerability. An attacker with network access to the administrative configurator on port 8443 and a valid password for the configurator administrator account can execute commands with unrestricted privileges on the underlying operating system.
Direct Remote Network Attack
CVE-2020-25213
WordPress
File Manager Plugin
WordPress File Manager Plugin Remote Code Execution Vulnerability
03 November 2021
WordPress File Manager plugin contains a remote code execution vulnerability that allows unauthenticated users to execute PHP code and upload malicious files on a target site.
Direct Remote Network Attack
CVE-2020-11738
WordPress
Snap Creek Duplicator Plugin
WordPress Snap Creek Duplicator Plugin File Download Vulnerability
03 November 2021
WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard. This vulnerability affects Duplicator and Dulplicator Pro.
Application/System Exploitation
CVE-2019-9978
WordPress
Social Warfare Plugin
WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability
03 November 2021
WordPress Social Warfare plugin contains a cross-site scripting (XSS) vulnerability that allows for remote code execution. This vulnerability affects Social Warfare and Social Warfare Pro.
Direct Remote Network Attack
CVE-2021-27561
Yealink
Device Management
Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability
03 November 2021
Yealink Device Management contains a server-side request forgery (SSRF) vulnerability that allows for unauthenticated remote code execution.
Direct Remote Network Attack
CVE-2021-40539
Zoho
ManageEngine
Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability
03 November 2021
Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs which allow for remote code execution.
Direct Remote Network Attack
CVE-2020-10189
Zoho
ManageEngine
Zoho ManageEngine Desktop Central File Upload Vulnerability
03 November 2021
Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution.
Direct Remote Network Attack
CVE-2019-8394
Zoho
ManageEngine
Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
03 November 2021
Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization.
Application/System Exploitation
CVE-2020-29583
Zyxel
Multiple Products
Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability
03 November 2021
Zyxel firewalls (ATP USG VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with an unchangeable password.
Perimeter Gateway Breach
CVE-2026-63077
JetBrains
TeamCity
JetBrains TeamCity Deserialization of Untrusted Data Vulnerability
05 August 2026
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
Direct Remote Network Attack
CVE-2026-18556
N-able
N-central
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
04 August 2026
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Application/System Exploitation
CVE-2026-34486
Apache
Tomcat
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
04 August 2026
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
Application/System Exploitation
CVE-2026-9198
IBM
Langflow
IBM Langflow Code Injection Vulnerability
04 August 2026
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
Direct Remote Network Attack
CVE-2026-18577
N-able
N-central
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
03 August 2026
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
Application/System Exploitation
CVE-2026-20316
Cisco
Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
29 July 2026
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
Perimeter Gateway Breach
CVE-2025-68686
Fortinet
FortiOS
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
27 July 2026
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability at filesystem level.
Perimeter Gateway Breach
CVE-2026-16812
Arista
VeloCloud Orchestrator
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
27 July 2026
Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality integrity and availability of the orchestrator and data managed by the orchestrator.
Application/System Exploitation
CVE-2026-16232
Check Point
SmartConsole
Check Point SmartConsole Improper Authentication Vulnerability
22 July 2026
Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
Direct Remote Network Attack
CVE-2026-50522
Microsoft
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
22 July 2026
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
Phishing / User Interaction
CVE-2026-60137
WordPress
Core
WordPress Core SQL Injection Vulnerability
21 July 2026
WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations.
Direct Remote Network Attack
CVE-2026-63030
WordPress
Core
WordPress Core Interpretation Conflict Vulnerability
21 July 2026
WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.
Direct Remote Network Attack
CVE-2026-0770
Langflow
Langflow
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
21 July 2026
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
Application/System Exploitation
CVE-2021-27137
DD-WRT
DD-WRT
DD-WRT Stack-Based Buffer Overflow Vulnerability
21 July 2026
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
Direct Remote Network Attack
CVE-2026-58644
Microsoft
SharePoint
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
16 July 2026
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
Phishing / User Interaction
CVE-2026-25089
Fortinet
FortiSandbox
Fortinet FortiSandbox OS Command Injection Vulnerability
16 July 2026
Fortinet FortiSandbox FortiSandbox Cloud and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.
Perimeter Gateway Breach
CVE-2026-39808
Fortinet
FortiSandbox
Fortinet FortiSandbox OS Command Injection Vulnerability
16 July 2026
Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.
Perimeter Gateway Breach
CVE-2026-46817
Oracle
E-Business Suite
Oracle E-Business Suite Improper Privilege Management Vulnerability
15 July 2026
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
Direct Remote Network Attack
CVE-2023-4346
KNX Association
KNX Protocol Connection Authorization Option 1
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
15 July 2026
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.
Application/System Exploitation
CVE-2026-56155
Microsoft
Active Directory Federation Services
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
14 July 2026
Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.
Application/System Exploitation
CVE-2026-56164
Microsoft
SharePoint Server
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
14 July 2026
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
Application/System Exploitation
CVE-2026-15409
SonicWall
SMA1000 Appliances
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
14 July 2026
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
Perimeter Gateway Breach
CVE-2026-15410
SonicWall
SMA1000 Appliances
SonicWall SMA1000 Appliances Code Injection Vulnerability
14 July 2026
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
Perimeter Gateway Breach
CVE-2008-4128
Cisco
IOS
Cisco IOS Cross-Site Request Forgery Vulnerability
13 July 2026
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
Application/System Exploitation
CVE-2026-56291
Balbooa
Forms
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
10 July 2026
Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.
Direct Remote Network Attack
CVE-2026-48939
iCagenda
iCagenda
iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
10 July 2026
iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature ultimately resulting in PHP code upload and execution.
Phishing (Malicious Attachment)
CVE-2026-48908
JoomShaper
SP Page Builder
JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
07 July 2026
JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files ultimately resulting in the upload and execution of PHP code.
Direct Remote Network Attack
CVE-2026-55255
Langflow
Langflow
Langflow Authorization Bypass Through User-Controlled Key Vulnerability
07 July 2026
Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.
Application/System Exploitation
CVE-2026-56290
Joomlack
Page Builder
Joomlack Page Builder Improper Access Control Vulnerability
07 July 2026
Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.
Direct Remote Network Attack
CVE-2026-48282
Adobe
ColdFusion
Adobe ColdFusion Path Traversal Vulnerability
07 July 2026
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
Phishing / User Interaction
CVE-2026-45659
Microsoft
SharePoint Server
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
01 July 2026
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
Application/System Exploitation
CVE-2026-48558
SimpleHelp
SimpleHelp
SimpleHelp Authentication Bypass Vulnerability
29 June 2026
SimpleHelp contains an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration a remote unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations this may also allow bypass of multi-factor authentication.
Direct Remote Network Attack
CVE-2026-12569
PTC
Windchill and FlexPLM
PTC Windchill and FlexPLM Improper Input Validation Vulnerability
25 June 2026
PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated remote attacker to execute arbitrary code by sending a malicious request to the network.
Direct Remote Network Attack
CVE-2026-20230
Cisco
Unified Communications Manager
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
25 June 2026
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated remote attacker to write files to the underlying operating system that could be used later to elevate to root.
Direct Remote Network Attack
CVE-2025-67038
Lantronix
EDS5000
Lantronix EDS5000 Code Injection Vulnerability
23 June 2026
Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.
Application/System Exploitation
CVE-2026-34910
Ubiquiti
UniFi OS
Ubiquiti UniFi OS Improper Input Validation Vulnerability
23 June 2026
Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.
Application/System Exploitation
CVE-2026-34909
Ubiquiti
UniFi OS
Ubiquiti UniFi OS Path Traversal Vulnerability
23 June 2026
Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.
Application/System Exploitation
CVE-2026-34908
Ubiquiti
UniFi OS
Ubiquiti UniFi OS Improper Access Control Vulnerability
23 June 2026
Ubiquiti UniFi OS contains an improper access control vulnerability which could allow a malicious actor with access to the network to make unauthorized changes to the system.
Application/System Exploitation
CVE-2026-20253
Splunk
Enterprise
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
18 June 2026
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
Direct Remote Network Attack

Opeining times are listed here 

  • Steve Dance Managing Partner
  • Linkedin

Follow or connect with Steve,  RiskCentric's owner & founder via LinkedIn

bottom of page