🔐 acmailer Authorization Flaw Enables Admin-Level Sub-Accounts
Organizations running acmailer should prioritize remediation because successful abuse could give an otherwise limited user administrative access. Apply vendor fixes or mitigations when available, especially on internet-facing or multi-user deployments.
CVE-2026-70408 is an incorrect authorization vulnerability in acmailer that may allow a user to create a sub-account with administrative privileges. The issue is rated HIGH with CVSS 8.7.
🔗 Read more 🔗
Source: NVD
🗑️ Atarim WordPress Plugin File Deletion Can Lead to RCE
WordPress administrators using Atarim through version 5.1.1 should treat this as a high-priority remediation item. The author-level access requirement limits exposure somewhat, but arbitrary file deletion with a path to remote code execution warrants prompt action and vendor-recommended mitigations or updates when available.
CVE-2026-19942 affects the Atarim – AI Agency for WordPress plugin through version 5.1.1 and allows authenticated attackers with author-level access or higher to delete arbitrary server files. By manipulating attachment metadata and triggering the replace-media-file functionality, an attacker can target sensitive files such as wp-config.php, potentially leading to remote code execution. The vulnerability is rated HIGH with CVSS 8.1.
🔗 Read more 🔗
Source: NVD
📡 TRENDnet Router Ping Interface Exposed to Command Injection
Owners and administrators of affected TRENDnet routers should apply fixed firmware when available and restrict management interfaces from untrusted networks. Public exploit availability materially raises the urgency even though the entry does not confirm active exploitation.
CVE-2026-75985 is a remotely exploitable command-injection vulnerability affecting TRENDnet Router 1.1.02b01 in /cgi-bin/ping.cgi. Manipulation of the wan_type argument can inject commands, and a public exploit is available. The issue is rated HIGH with CVSS 7.4.
🔗 Read more 🔗
Source: NVD
🔒 armeria-xds TLS Verification Flaw Enables MITM Attacks
Teams using armeria-xds should upgrade to version 1.41.0 or later urgently, particularly where xDS controls sensitive service-to-service traffic. Silent loss of TLS peer verification undermines a core transport-security guarantee.
CVE-2026-11751 affects armeria-xds versions prior to 1.41.0 and may silently disable TLS peer verification for xDS upstream connections. This can allow man-in-the-middle attacks against upstream connections managed through xDS. The vulnerability is rated CRITICAL with CVSS 9.1.
🔗 Read more 🔗
Source: NVD
⚠️ TRENDnet TEW-823DRU Admin Endpoint Allows Command Injection
Administrators of TEW-823DRU devices should apply fixed firmware when available and keep the administration interface inaccessible from untrusted networks. A public exploit makes exposed devices especially risky, although the entry does not confirm active exploitation.
CVE-2026-75984 affects TRENDnet TEW-823DRU 1.1.02b01 and allows remote command injection through the Hostname argument in /cgi-bin/admin.cgi. The exploit is public and may be used against vulnerable devices. The issue is rated HIGH with CVSS 7.4.
🔗 Read more 🔗
Source: NVD
💥 Critical TRENDnet TEW-823DRU Buffer Overflow Has Public Exploit
Affected router owners should treat this as an urgent firmware-remediation or device-isolation issue and apply fixed firmware when available. The near-maximum severity, remote attack path, and public exploit substantially increase the risk to reachable devices, though active exploitation is not confirmed in the entry.
CVE-2026-75976 is a stack-based buffer overflow in TRENDnet TEW-823DRU 1.1.02b01 affecting strcpy usage in /cgi-bin/wan.cgi. Remote manipulation of the wan_l2tp_password argument can trigger the flaw, and an exploit has been made public. The vulnerability is rated CRITICAL with CVSS 9.9.
🔗 Read more 🔗
Source: NVD
📦 SPLWare esProc Exposed to Remote Deserialization Flaw
Organizations running affected esProc versions should apply vendor remediation when available and limit network access to the vulnerable service in the meantime. Remote deserialization flaws deserve prompt attention because their downstream impact can be severe depending on application context.
CVE-2026-75987 affects SPLWare esProc through 20260507 and involves deserialization through ObjectInputStream.readUnshared in SocketData.java. The vulnerability can be exploited remotely. It is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
💉 Online Job Portal Password Recovery Hit by SQL Injection
Anyone operating this application should apply vendor remediation when available, reduce public exposure, and review database activity for suspicious requests to the password-recovery endpoint. Public exploit availability increases the likelihood of opportunistic probing, although active exploitation is not confirmed.
CVE-2026-75986 affects code-projects Online Job Portal System 1.0 and allows remote SQL injection through the txtUserName argument in /ForPass.php. The flaw is in the password-recovery component, and a public exploit has been disclosed. The vulnerability is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
💉 Food Ordering System Menu Deletion Endpoint Has SQL Injection
Operators of this SourceCodester application should apply vendor remediation when available and restrict access to administrative endpoints in the meantime. Because exploit details are public, exposed installations may attract automated probing even though active exploitation is not confirmed.
CVE-2026-76050 affects SourceCodester Simple Online Food Ordering System 1.0 and permits remote SQL injection through the ID argument in /admin/ajax.php?action=delete_menu. A public exploit has been made available. The issue is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
💉 SourceCodester Menu Save Function Vulnerable to SQL Injection
Administrators should apply vendor remediation when available and limit access to the vulnerable administrative functionality until it is fixed. Public exploit disclosure raises the risk of opportunistic attacks, although the entry does not confirm active exploitation.
CVE-2026-76049 affects SourceCodester Simple Online Food Ordering System 1.0 and allows remote SQL injection through the ID argument in /admin/ajax.php?action=save_menu. Exploit information has been disclosed publicly and may be used. The vulnerability is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
🔑 SourceCodester Login Endpoint Exposed to SQL Injection
Internet-facing deployments should receive vendor remediation when available or be removed from public exposure, with special attention to authentication and database logs. A publicly documented SQL-injection path in a login endpoint is attractive for automated attacks, although active exploitation is not confirmed.
CVE-2026-76048 affects SourceCodester Simple Online Food Ordering System 1.0 and enables remote SQL injection through the Username argument in /admin/ajax.php?action=login. A public exploit has been published and may be used. The vulnerability is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
🚨 Comfast CF-N1-S Remote Buffer Overflow Scores Critical 10
Owners of affected Comfast devices should prioritize vendor remediation when available and isolate vulnerable management or CGI interfaces from untrusted networks. A remotely reachable CVSS 10.0 memory-corruption flaw warrants emergency handling even though this entry does not state that a public exploit or active exploitation exists.
CVE-2026-76008 is a remotely triggerable stack-based buffer overflow in Comfast CF-N1-S 2.6.0.1. The flaw affects get_para_from_uri in /cgi-bin/mbox-config, where manipulation of the width or height arguments can cause the overflow. The vulnerability is rated CRITICAL with CVSS 10.0.
🔗 Read more 🔗
Source: NVD