Skip to content
Threat Feed

Tag

Critical

10 briefs RSS
critical threat

Heap Buffer Underflow in IBM MQ for HPE NonStop

IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow vulnerability in multi-segment message processing that allows authenticated attackers to execute arbitrary code or trigger denial of service.

exploited IBM MQ for HPE NonStop vulnerability remote-code-execution ibm-mq critical
1t 1c
critical advisory

Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic

Synology DiskStation Manager (DSM) contains an insufficient entropy vulnerability in its login logic that allows remote, unauthenticated attackers to perform arbitrary file read/write operations and trigger a denial-of-service condition.

DiskStation Manager +7 vulnerability critical remote-code-execution file-read-write dsm file-access synology cve +4
1t 6c
critical threat

Critical RCE Vulnerability in N-able N-central

A critical unauthenticated remote code execution vulnerability (CVE-2026-86218) in N-able N-central is under active exploitation, allowing attackers to gain full system control.

N-central +2 vulnerability rce critical remote-management
1t updated
critical advisory

Authentication Bypass in Proxmox Virtual Environment

CVE-2023-54391 allows unauthenticated remote attackers to bypass authentication in Proxmox VE 7.0-8.0 by providing a crafted tfa-challenge parameter to the API login endpoint.

Proxmox Virtual Environment vulnerability authentication-bypass critical
1r 1t 1c
critical advisory

Critical OS Command Injection in IBM Hardware Management Console

A critical unauthenticated command injection vulnerability (CVE-2026-12943) in IBM HMC and Novalink allows remote attackers to execute arbitrary commands with elevated privileges.

HMC V10.3 +2 vulnerability rce ibm-power critical
1c
critical advisory

X-Rite MA-T6 Remote Code Execution Vulnerability (CVE-2023-49899)

An unauthenticated remote attacker can exploit CVE-2023-49899 in X-Rite MA-T6 devices (versions prior to v2.33) to achieve arbitrary command execution by bypassing origin verification, leading to full compromise of the device.

MA-T6 vulnerability RCE ICS OT critical
2t 1c
critical advisory

EGroupware Critical RCE Vulnerability (CVE-2026-27823)

A critical remote code execution vulnerability (CVE-2026-27823) in EGroupware allows an authenticated attacker, or an unauthenticated attacker if self-registration is enabled, to execute arbitrary commands on the server by combining an authorization bypass, arbitrary file write via path traversal, and arbitrary file read, leading to full system compromise.

composer/egroupware/egroupware +1 RCE web-vulnerability egroupware php critical exploit
2r 4t
critical advisory

CVE-2026-4321: Critical SQL Injection in Raera Destekz Product

CVE-2026-4321 describes a critical SQL Injection vulnerability with a CVSS v3.1 score of 9.8 in the Destekz product by Raera - Ankara Web Design and Digital Advertising Agency, affecting all versions through June 2nd, 2026, which remains unpatched due to the vendor discontinuing support for the product, enabling unauthenticated attackers to potentially achieve full system compromise and data exfiltration.

Destekz sql-injection cve web-application vulnerability critical unsupported-product
1t 1c
critical advisory

Taiko AG1000-01A SMS Alert Gateway Authentication Bypass (CVE-2026-9141)

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability (CVE-2026-9141) in the embedded web configuration interface, allowing unauthenticated attackers to access internal application pages, modify alarm routing, and disrupt monitoring and control functions.

AG1000-01A SMS Alert Gateway authentication-bypass web-application critical
2r 1t 1c
medium advisory

Goobi Viewer Unauthenticated Solr Streaming Expression Proxy Vulnerability

The Goobi viewer REST endpoint accepted an arbitrary Solr streaming expression from unauthenticated network clients, enabling attackers to read, modify, or delete the complete Solr index; this was resolved by removing the affected API endpoint.

Goobi viewer solr proxy unauthenticated CVE-2026-45083 critical
2r 1t