Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2710+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
37 articles

#Critical Vulnerability

All CosmicBytez Labs articles tagged #Critical Vulnerability, across news, security advisories, how-to guides, and projects.

  • SecuritySep 7, 2026

    CVE-2026-79697: Advantech WISE-6610 Unauthenticated Command Injection

    A CVSS 9.9 command injection flaw in Advantech WISE-6610 industrial gateways lets remote attackers run arbitrary OS commands; a public exploit exists.

  • SecuritySep 6, 2026

    CVE-2026-86148: Tenda CP3 OS Command Injection via AlarmVoiceURL

    A critical unauthenticated OS command injection flaw in Tenda CP3 Wi-Fi cameras lets remote attackers run arbitrary commands via the AlarmVoiceURL parameter.

  • SecuritySep 6, 2026

    CVE-2026-86149: Tenda CP3 OS Command Injection via NetCheckPing

    A second critical command injection flaw in Tenda CP3 cameras lets remote attackers execute OS commands through the ping utility's host/interface argument.

  • SecuritySep 6, 2026

    CVE-2026-16310: MemberDash WordPress Plugin Unauthenticated Account Takeover

    MemberDash ≤ 1.8.5 has an IDOR letting unauthenticated attackers change any WordPress user's password via a crafted registration request.

  • SecuritySep 6, 2026

    CVE-2026-86152: Max-Severity Tenda CP3 Command Injection via AutoAddWifi

    CVSS 10.0 flaw in Tenda CP3's Kylin AutoAddWifi thread lets remote attackers inject and execute arbitrary OS commands.

  • SecuritySep 6, 2026

    CVE-2026-86151: Tenda CP3 OS Command Injection via Network Config Handler

    Tenda CP3 firmware 27.5.57.101 lets remote attackers inject OS commands through its network configuration handler, no authentication noted.

  • SecuritySep 6, 2026

    CVE-2026-86153: Tenda CP3 Improper Privilege Management in Redirect Service

    Tenda CP3's SetRedirectEnable function lacks authorization checks, letting remote attackers alter port-forwarding without admin access.

  • SecuritySep 5, 2026

    CVE-2026-75925: IXON VPN Client CRLF Injection Enables Root/SYSTEM Command Execution

    IXON VPN Client before v1.4.7 lets a local attacker inject CRLF sequences into a config file consumed by a privileged process, gaining root or SYSTEM.

  • SecuritySep 4, 2026

    CVE-2026-85061: MapLibre GL JS DOM Sanitizer Bypass Enables Stored XSS

    A live-collection iteration bug in MapLibre GL JS's DOM.sanitize() lets attacker-supplied attribution strings smuggle an event handler past sanitization.

  • SecuritySep 4, 2026

    CVE-2026-85181: CAT Session Cookie Forgery Grants Admin Access

    CAT relies solely on an unkeyed Java hashCode for session integrity, letting attackers forge admin cookies and bypass IP binding via X-Forwarded-For.

  • SecuritySep 4, 2026

    CVE-2026-85222: D-Link DNS-340L Command Injection Has No Fix Coming

    An unauthenticated OS command injection in the DNS-340L's Add-On Center CGI grants root — and D-Link has declared the device end-of-life.

  • SecuritySep 1, 2026

    CVE-2026-82854: Nodemailer SMTP Command Injection via envelope.size

    Nodemailer before 8.0.4 lets attackers inject SMTP commands via unsanitized envelope.size, silently adding recipients to outbound mail.

  • SecuritySep 1, 2026

    CVE-2026-82855: @hulumi/policies Cross-Resource Evidence Validation Bypass

    hulumi/policies before 1.3.2 let attackers suppress guardrail violations using compliant evidence from an unrelated resource in the same stack.

  • SecuritySep 1, 2026

    CVE-2026-82856: @hulumi/policies GitHub OIDC Trust Policy Bypass

    hulumi/policies before 1.3.2 missed set-qualified IAM operators, letting wildcard GitHub Actions OIDC conditions slip past guardrails.

  • SecuritySep 1, 2026

    CVE-2026-82857: hulumi Privilege Escalation via Weekly Integration IAM Policy

    hulumi before 1.3.2 let attackers create persistent higher-privilege af-e2e-* roles in the sandbox account via a flawed IAM boundary.

  • SecurityAug 29, 2026

    CVE-2026-37751: Critical Command Injection in AI Maestro

    A CVSS 9.8 OS command injection in AI Maestro's session-kill function lets attackers run arbitrary commands on self-hosted orchestrator hosts.

  • SecurityAug 29, 2026

    CVE-2026-42007: Critical Use-After-Free in Dovecot's Sieve Editheader Extension

    Dovecot's Sieve editheader extension has a critical use-after-free (CVSS 9.1) letting authenticated users corrupt memory during mail delivery.

  • SecurityAug 28, 2026

    CVE-2026-50152: Ceph Monitor Flaw Exposes Cluster SSH Keys and Disk Encryption Secrets

    A low-privilege, read-only CephX role can read Ceph's entire config-key store, exposing cephadm SSH keys and OSD LUKS passphrases.

  • SecurityAug 28, 2026

    CVE-2026-40541: Cross-Site Scripting Flaw in Synology Chat Server Enables File Tampering

    Synology Chat Server's unsanitized link-preview domain lets authenticated users read/write arbitrary DSM files and cause denial-of-service.

  • SecurityAug 28, 2026

    CVE-2026-82082: Critical Unauthenticated OS Command Injection in NUMail

    Unauthenticated OS command injection in Green-Computing's NUMail lets remote attackers run arbitrary commands on the mail server. CVSS 9.8.

  • SecurityAug 27, 2026

    CVE-2026-59682: OpenRGB Arbitrary File Overwrite via SAVE_PROFILE

    OpenRGB's network protocol lets remote attackers overwrite (and delete) arbitrary files through the SAVE_PROFILE message, up to v1.0rc3.

  • SecurityAug 27, 2026

    CVE-2026-77533: UniFi Protect Command Injection via Improper Input Validation

    A critical flaw in UniFi Protect lets a low-privileged, network-adjacent attacker inject OS commands on the host device. Patch to 7.2.105+.

  • SecurityAug 27, 2026

    CVE-2026-80235: EFence Unauthenticated Arbitrary File Upload to RCE

    EFence by Thinking Software Technology allows unauthenticated remote attackers to upload web shells and achieve full code execution.

  • SecurityAug 26, 2026

    CVE-2026-16286: Unauthenticated Web Shell Upload in TRtek Software Repository Management

    Unrestricted file upload flaw lets attackers plant a web shell on TRtek's Software Repository Management with no authentication required.

  • SecurityAug 26, 2026

    CVE-2026-63586: Unauthenticated Root RCE in Weidmueller IE-SR-2TX-WL Industrial Routers

    Critical OS command injection via the HTTP Basic Auth username lets unauthenticated attackers run root commands on Weidmueller security routers.

  • SecurityAug 24, 2026

    CVE-2026-7808: justhtml HTML Sanitization Bypass (Critical XSS)

    Critical XSS in justhtml before 1.16.0. Multiple bypass paths let dangerous content survive sanitization, enabling script injection with no auth required.

  • SecurityAug 24, 2026

    CVE-2026-8445: justhtml Markdown Conversion XSS via Unescaped Angle Brackets

    Critical XSS in justhtml <=1.11.0. The to_markdown() function leaves angle brackets unescaped, allowing raw HTML to reach downstream Markdown renderers.

  • SecurityAug 22, 2026

    CVE-2026-73570: Zimbra ZCS OS Command Injection via SMTP

    Zimbra Collaboration Suite contains a critical unauthenticated OS command injection flaw allowing RCE as the Zimbra user via crafted SMTP requests.

  • NewsAug 13, 2026

    Adobe Patches Three CVSS 10.0 Flaws in ColdFusion and Campaign Classic

    Adobe's August 2026 patch cycle fixes 3 maximum-severity RCE vulnerabilities across ColdFusion and Campaign Classic. Priority 1 — patch within 72 hours.

  • SecurityJul 18, 2026

    CVE-2026-47865: Critical Authentication Bypass in VMware Avi Load Balancer

    A CVSS 9.8 authentication bypass vulnerability allows unauthenticated remote attackers to gain full access to the VMware Avi Load Balancer Control Plane....

  • SecurityJul 17, 2026

    CVE-2026-14890: SGLang ZeroMQ Unauthenticated RCE via Pickle Deserialization

    A critical unauthenticated remote code execution vulnerability in the SGLang AI inference framework allows attackers to deliver malicious pickle payloads...

  • SecurityJul 17, 2026

    CVE-2026-45695: Kopia Backup Tool Exposes Unauthenticated HTTP API

    A critical authentication bypass in Kopia, a cross-platform backup tool for Windows, macOS, and Linux, allows unauthenticated access to repository API...

  • NewsJun 6, 2026

    Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites

    Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin, enabling them to take complete control of…

  • SecurityMay 29, 2026

    CVE-2026-46775 — Oracle REST Data Services Critical Compromise via HTTPS

    A CVSS 9.9 critical vulnerability in Oracle REST Data Services (ORDS) versions 24.2.0 through 26.1.0 allows a low-privileged network attacker to fully...

  • NewsMay 12, 2026

    Fortinet Warns of Critical RCE Flaws in FortiSandbox and FortiAuthenticator

    Fortinet has released emergency security patches for two critical vulnerabilities in FortiSandbox and FortiAuthenticator that could enable attackers to...

  • SecurityMay 10, 2026

    CVE-2026-42569: phpVMS Critical Unauthenticated Legacy

    A critical vulnerability (CVSS 9.4) in phpVMS before version 7.0.6 allows unauthenticated attackers to access a legacy import feature, potentially...

  • NewsJan 30, 2026

    Cisco Patches Critical Webex Vulnerability Allowing Remote

    Cisco has released emergency patches for a critical vulnerability in Webex that could allow unauthenticated remote code execution. Organizations urged to...