| CVE-2026-76460 |
10.0 |
N/A |
🔥 28
|
Cisco |
Cisco Identity Services Engine Software; Cisco ISE Passive Identity Connector |
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.
This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. |
| CVE-2026-94127 |
9.8 |
N/A |
🔥 19
|
F5 |
BIG-IP |
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability.
Impact:
This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
| CVE-2026-85102 |
9.8 |
0.33% |
🔥 14
|
checkpoint |
Quantum Security Gateway |
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. |
| CVE-2026-87902 |
8.1 |
2.88% |
🔥 10
|
WordPress |
WordPress |
An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE. |
| CVE-2026-93952 |
10.0 |
0.42% |
🔥 9
|
Arista Networks |
VeloCloud Orchestrator (VCO) On-Prem |
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.
Hosted, including Dedicated, versions of VCO were impacted and have already been patched. |
| CVE-2026-93616 |
9.8 |
N/A |
🔥 9
|
checkpoint |
Quantum Security Management |
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. |
| CVE-2026-65660 |
8.8 |
1.22% |
🔥 6
|
Microsoft |
Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition |
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2026-5430 |
10.0 |
0.37% |
🔥 6
|
WSO2 |
WSO2 Universal Gateway; WSO2 Traffic Manager; WSO2 API Control Plane; WSO2 API Manager; WSO2 Carbon API Manager Rest API Utility |
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.
Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary. |
| CVE-2026-28324 |
9.8 |
N/A |
🔥 3
|
SolarWinds |
Observability Self-Hosted |
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected. |
| CVE-2026-1003 |
4.3 |
0.21% |
🔥 2
|
roxnor |
GetGenie – AI Content Writer with Keyword Research & SEO Tracking Tools |
The GetGenie plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.3.0. This is due to the plugin not properly verifying that a user is authorized to delete a specific post. This makes it possible for authenticated attackers, with Author-level access and above, to delete any post on the WordPress site, including posts authored by other users. |