Tag

#Critical Vulnerability

blogCRITICAL 9.8

Understanding and Defending Against CVE-2026-82435: A Critical Vulnerability in Apache Storm

CVE-2026-82435 is a critical vulnerability in Apache Storm that allows for unauthenticated, remote exploitation, potentially leading to denial-of-service (DoS) attacks. The vulnerability has a CVSS score of 9.8 and affects Apache Storm versions prior to 3.1.0. This analysis will delve into the root cause, attack surface, exploitation mechanics, and provide defensive recommendations.

1 source
newsCRITICAL 9.8

Critical Vulnerability in Apache Storm Client: CVE-2026-82431

A critical vulnerability (CVE-2026-82431, CVSS score: 9.8) was discovered in the Apache Storm Client, affecting versions 3.0.0 and earlier. The vulnerability allows an attacker to bypass access controls, permitting every authenticated principal to perform user-level operations. Immediate action is required to upgrade to version 3.1.0 or apply mitigations.

1 source
newsCRITICAL 9.9

Critical Vulnerability in WatchMan-Site7 WordPress Plugin Allows Arbitrary Code Execution

A critical vulnerability (CVE-2026-77009, CVSS 9.9) in the WatchMan-Site7 WordPress plugin through version 4.2.0 allows any authenticated user to execute arbitrary PHP code on the server. This vulnerability is exploitable via a debugging console that does not restrict access. Immediate action is required to protect against potential exploitation.

1 source
articleCRITICAL 9.8

Critical Vulnerability in Dell PowerStore: CVE-2026-58574

A critical vulnerability, CVE-2026-58574, with a CVSS score of 9.8, was discovered in Dell PowerStore. This vulnerability allows an unauthenticated attacker with network access to the restricted management interface to potentially read internal system information from the appliance filesystem, exposing sensitive information and credentials. Affected versions include PowerStore 500T, 1000T, 1200T, and others prior to version 4.1.0.6-2771237 or 4.3.1.2-2771239. Immediate patching is recommended.

1 source
articleCRITICAL 9.1

Critical Remote Code Execution Vulnerability in Zscaler Client Connector (CVE-2026-59568)

A critical vulnerability (CVE-2026-59568) with a CVSS score of 9.1 affects multiple versions of Zscaler Client Connector, allowing remote code execution. This vulnerability enables an unauthenticated, unprivileged user to execute arbitrary code in the ZCC context. Affected platforms include Windows, MacOS, Linux, iOS, Android, and ChromeOS. Immediate patching is recommended to prevent potential exploitation.

1 source
articleCRITICAL 9.1

Critical Vulnerability in FormGent WordPress Plugin Allows Unauthenticated Arbitrary File Deletion

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2. This critical vulnerability, with a CVSS score of 9.1, allows unauthenticated attackers to delete arbitrary files within the formgent uploads directory and potentially bypass path traversal protection to delete critical files like wp-config.php, leading to complete site takeover. Immediate patching is recommended.

1 source
newsCRITICAL 9.8

Critical Directory Traversal Vulnerability in IBM App Connect Enterprise (CVE-2026-15435)

A critical vulnerability (CVE-2026-15435) with a CVSS score of 9.8 affects IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.7.2. An unauthenticated remote attacker could exploit this vulnerability to traverse directories and write arbitrary files on the system. Immediate action is required to mitigate this vulnerability.

1 source
articleCRITICAL 10.0

Critical Adobe Campaign Classic Vulnerability: CVE-2026-48449

A critical Incorrect Authorization vulnerability, CVE-2026-48449, has been discovered in Adobe Campaign Classic (ACC), potentially leading to arbitrary code execution. With a CVSS score of 10, this vulnerability has a significant impact and can be exploited without user interaction. Affected versions include ACC 7.4.3 build 9397 and earlier. Immediate patching is recommended.

1 source
newsCRITICAL 9.1

Critical Vulnerability in 微信二维码登陆 WordPress Plugin Allows Unauthenticated Login

A critical vulnerability (CVE-2026-13597, CVSS 9.1) in the 微信二维码登陆 WordPress plugin (version 1.3 and earlier) allows unauthenticated attackers to forge login events, read login codes, and log in as any user, including administrators, without a password. Immediate action is required to prevent exploitation.

1 source
articleCRITICAL 9.1

Critical Authentication Bypass Vulnerability in Check Point SmartConsole (CVE-2026-16232)

A critical authentication bypass vulnerability (CVE-2026-16232) has been discovered in Check Point SmartConsole, allowing unauthenticated remote attackers to obtain application login tokens and gain full administrative privileges. This vulnerability has a CVSS score of 9.1 and is actively being exploited. Affected products include various versions of Check Point Quantum Security Management and Multi-Domain Security Management. Immediate patching or mitigation is strongly recommended.

1 source
newsCRITICAL 10.0

Critical Shellcode Injection Vulnerability in openSUSE Build Service

A critical vulnerability (CVE-2026-56004) with a CVSS score of 10 has been discovered in the obs tar_scm source service before version 0.12.4. This vulnerability allows attackers to inject shellcode and execute code as the source service or local user. Immediate action is required to update to version 0.12.4 or later.

1 source
newsCRITICAL 10.0

Critical Stack Overflow Vulnerability in GeoVision GV-I/O Box 4E (CVE-2026-12846)

A critical stack overflow vulnerability (CVE-2026-12846) with a CVSS score of 10 has been discovered in GeoVision GV-I/O Box 4E, a smart embedded device. The vulnerability affects version V2.09 and can be exploited by sending a crafted UDP message to the DVRSearch service listening on port 10001. Immediate action is required to update to a non-vulnerable version.

1 source
articleCRITICAL 9.1

Critical Insecure Default Credentials Vulnerability in NI grpc-device

A critical vulnerability (CVE-2026-9142) with a CVSS score of 9.1 has been discovered in NI grpc-device, affecting versions 2.17.0 and prior. The vulnerability allows unauthenticated access to the server on the local network when TLS configuration is not present and the server is bound beyond loopback. Immediate patching is recommended to prevent potential exploitation.

1 source