boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Saturday, September 26, 2026 · all times UTC← 2026-09-25 · archive

Security Box Score — September 26, 2026

248 CVEs published, led by openclaw (79).

248 CVEs published September 26, 2026: 16 critical, 134 high, 87 medium, 10 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 1 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 223 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published1323548214——
KEV catalog size1726

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

3101 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux21146205530263871311560.17.8.0019+606 ▲
microsoft10022901203199069216290311.17.8.0047+533 ▲
google5182686332105011831218090.37.5.0027+117 ▲
red hat2338625235940546200.06.7.0037+23 ▲
apple24656367165317148881.46.5.0019+202 ▲
freebsd04823673000.07.8.0016-32 ▼
canonical0421311135000.07.8.0019-15 ▼
suse1341721121000.07.5.0039+8 ▲
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco97181537255159168.87.7.0046+51 ▲
ubiquiti665362810334.69.1.0050-17 ▼
palo alto networks9461426151324.34.7.0022-3 ▼
fortinet1141111017329717.17.2.0040+4 ▲
netgear23400277000.04.3.0027-7 ▼
f592671441527.78.7.0050+9 ▲
ivanti10246162025520.88.8.0152+7 ▲
sonicwall519784019421.18.3.0050-7 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache137649148275208163320.37.5.0064-18 ▼
mozilla113301102126730900.08.8.0034+54 ▲
gitlab241007245811533.05.3.0034+2 ▲
drupal2694119668411.15.7.0027+9 ▲
github623211100000.07.4.0054+1 ▲
docker3121830000.08.4.0017+1 ▲
wordpress1614103350.08.7.0340-1 ▼
go440211000.05.9.0034+4 ▲
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle634290558116605631012840.17.8.0036-256 ▼
ibm398101719646733618610.17.5.0037+24 ▲
adobe2248308236437592150.67.5.0036+126 ▲
progress3641539100611.68.1.0046-16 ▼
zohocorp273762470000.08.1.0109+23 ▲
solarwinds3261853010415.49.1.0067+3 ▲
veeam01961030100.08.6.0042-13 ▼
servicenow5107300200.09.4.0036+5 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
d-link277222261212300.08.5.0182+11 ▲
siemens1552633103000.07.3.0026-5 ▼
synology1946510256000.05.6.0032+18 ▲
rockwell automation184353260000.08.6.0029+17 ▲
advantech172021710000.08.6.0071+17 ▲
schneider electric91821150000.08.5.0044+9 ▲
hikvision390540000.07.1.0038+3 ▲
abb291530000.07.2.0018+2 ▲
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
dell1953663117014322210.37.2.0029+124 ▲
sourcecodester632320013894000.05.5.0043+15 ▲
openclaw8221541098121000.07.1.0031+82 ▲
nvidia5118521127370000.07.8.0040-1 ▼
spring017013608314000.06.5.0033-27 ▼
mongodb71169699604100.07.1.0038+39 ▲
itsourcecode371530037116000.02.1.0033+7 ▲
hewlett packard enterprise (hpe)1391481777486110.77.2.0044+136 ▲

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-85706.914399.810.0
CVE-2026-85046.488898.88.8
CVE-2026-76461.282798.19.8
CVE-2026-93616.196597.39.8
CVE-2026-87902.181797.18.1
CVE-2026-82329.141296.59.8
CVE-2026-76460.140396.410.0
CVE-2026-86218.129396.210.0
CVE-2026-83549.107695.77.8
CVE-2026-83548.087695.010.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-8570610.0.9143KEV
CVE-2026-7646010.0.1403KEV
CVE-2026-8621810.0.1293KEV
CVE-2026-8354810.0.0876KEV
CVE-2026-7565010.0.0395KEV
CVE-2026-8200410.0.0325
CVE-2026-8615210.0.0288
CVE-2026-8222210.0.0225
CVE-2026-8245610.0.0173
CVE-2026-8597810.0.0144
Most disclosures (vendor)
VendorCVEs
linux2250
microsoft1010
oracle634
google518
ibm414
apple246
red hat245
adobe224
dell196
apache147
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco16
google9
apple8
fortinet7
linux6
adobe5
ivanti5
berriai4
checkpoint4
Most-affected ecosystems
EcosystemAdvisories
Maven93
Packagist15
npm15
PyPI14
crates.io9
Go2
RubyGems2
NuGet1
Fastest to KEV
CVEVendorDays
CVE-2026-58704Google0
CVE-2026-75650Adobe0
CVE-2026-83548SonicWall0
CVE-2026-83549SonicWall0
CVE-2026-85046Google0
CVE-2026-87491Google0
CVE-2026-93952Arista Networks0
CVE-2026-84869ConnectWise2
CVE-2026-86218N-able2
CVE-2026-87902WordPress2
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171774
CVE-2021-27102n/a2021-11-171774
CVE-2021-27101n/a2021-11-171774
CVE-2021-27103n/a2021-11-171774
CVE-2021-21017Adobe2021-11-171774
CVE-2021-28550Adobe2021-11-171774
CVE-2021-42013Apache Software Foundation2021-11-171774
CVE-2021-41773Apache Software Foundation2021-11-171774
CVE-2021-30858Apple2021-11-171774
CVE-2021-30860Apple2021-11-171774

Transactions

EXPLOIT PUBLISHED — CVE-2026-100310 (GNU libextractor). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-67615 (Apereo Foundation openEQUELLA). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-92764 (opencve). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-93349 (frictionlessdata frictionless-py). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-94109 (openEQUELLA). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-95811 (Lemonldap-NG-Handler). Public exploit reference added.

DUE DATE PASSED — CVE-2026-42016 (jfrog artifactory). CISA remediation deadline was September 25, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-42018 (jfrog artifactory). CISA remediation deadline was September 25, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-85102 (checkpoint Quantum Security Gateway). CISA remediation deadline was September 25, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-93616 (checkpoint Quantum Security Management). CISA remediation deadline was September 25, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-93952 (Arista Networks VeloCloud Orchestrator (VCO) On-Prem). CISA remediation deadline was September 25, 2026; still in catalog.

DUE DATE PASSED — CVE-2026-94127 (F5 BIG-IP). CISA remediation deadline was September 25, 2026; still in catalog.

RESCORED — CVE-2025-39889 (Linux). CVSS 8.1 → 5.5 (NVD).

PATCH SHIPPED — CVE-2026-94367 (OpenEye Apex Network Video Recorder (NVR)). Fixed in Apex Network Video Recorder (NVR) 3.4.3.

Yesterday's Results

How to read these box scores · glossary

248 CVEs published. 25 box scores, 223 table rows — nothing truncated.

crivion Laranode — Laranode before 1.2.1 Path Traversal in File Manager Upload Endpoint
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0094   59.3     —
AFFECTED
  Product   Versions     Fixed
  Laranode  unspecified  —
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 7 references · NVD status: Received
OpenClaw before 2026.8.1 Reusable Exec Approvals Authorization Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   N   P   H   H   H    7.7   .0058   45.4     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 Path Traversal via Structured Attachments
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0043   34.6     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Addify Request a Quote for WooCommerce — Request a Quote for WooCommerce <= 2.9.2 - Unauthenticated Arbitrary File Upload via AJAX Popup Handler
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0041   33.0     —
AFFECTED
  Product                          Versions     Fixed
  Request a Quote for WooCommerce  unspecified  —
TIMELINE
  Jul 28  Reserved by CNA
  Sep 26  Published (CNA: Wordfence)
CWE-434 · CNA: Wordfence · CVSS v3.1 · 2 references · NVD status: Received
OpenClaw before 2026.8.2 Denial of Service via Browser Relay
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0035   25.9     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.8.2
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-400 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 SMS Webhook Rate Limit Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0035   25.9     —
AFFECTED
  Product   Versions    Fixed
  OpenClaw  2026.6.6 –  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-400 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 Denial of Service via Rate Limit
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   L    6.9   .0035   25.9     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  2026.3.25 –  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-400 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 Information Disclosure via Configuration Hash
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   H   H   H    7.7   .0035   25.7     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-200 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.7.1 Remote Code Execution via cron tool
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0034   25.2     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.7.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-178 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
openclaw Slack before 2026.8.1 Authorization Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0033   23.3     —
AFFECTED
  Product  Versions     Fixed
  slack    unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-639 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.7.1 Sandbox Bypass via Browser Node
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   L    8.7   .0032   22.4     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.7.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chrome
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0031   20.9     —
AFFECTED
  Product   Versions    Fixed
  OpenClaw  2026.5.1 –  2026.7.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-78 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw Matrix before 2026.8.1 Authorization Bypass via Case Folding
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   H   H   H    7.7   .0030   20.7     —
AFFECTED
  Product  Versions    Fixed
  matrix   2026.2.2 –  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-178 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.7.1 Authentication Bypass via node.invoke
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   L    8.7   .0030   20.4     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.7.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 Path Traversal via Unicode Fallback
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   H   N   N    6.0   .0029   19.4     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
openclaw discord — Vulnerability in discord
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   H   N   N    6.0   .0028   18.6     —
AFFECTED
  Product  Versions     Fixed
  discord  unspecified  2026.9.3
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-862 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 Resource Exhaustion via WebSocket Upgrade
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   N   N   H    8.7   .0028   18.2     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-400 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 Authentication Bypass via Session Reset
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   L   L   L    5.3   .0028   18.2     —
AFFECTED
  Product   Versions    Fixed
  OpenClaw  2026.5.2 –  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 Path Traversal via QQBot voice filenames
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   L   L    5.3   .0028   18.0     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-22 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
openclaw WhatsApp before 2026.8.1 Authentication Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   N   H   H    7.2   .0027   17.3     —
AFFECTED
  Product   Versions     Fixed
  whatsapp  unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-862 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 Session Cancellation Authorization Bypass
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   N   N   L    2.3   .0027   16.6     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-639 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 Privilege Escalation via Session Memory
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   H   P   L   N   H   H   H    7.7   .0026   16.4     —
AFFECTED
  Product   Versions    Fixed
  OpenClaw  2026.4.5 –  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 Policy Bypass via Native Tools
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0026   16.0     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw Slack before 2026.8.1 Authentication Bypass via Group DM
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   H   H    8.7   .0026   16.0     —
AFFECTED
  Product  Versions     Fixed
  slack    unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-862 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
OpenClaw before 2026.8.1 Local File Read via Outbound Attachments
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   L   N   H   N   N    7.1   .0026   15.7     —
AFFECTED
  Product   Versions     Fixed
  OpenClaw  unspecified  2026.8.1
TIMELINE
  Sep 26  Reserved by CNA
  Sep 26  Published (CNA: VulnCheck)
CWE-863 · CNA: VulnCheck · CVSS v4.0 · 2 references · NVD status: Received
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-1005422.315.7OpenClawOpenClawCWE-400OpenClaw before 2026.8.1 Extraction Limit Bypass via tar.bz2
CVE-2026-1005678.915.1OpenClawOpenClawCWE-918OpenClaw before 2026.8.1 DNS Rebinding via CDP Hostname
CVE-2026-1005688.714.7OpenClawOpenClawCWE-200OpenClaw before 2026.8.1 Unauthorized Command Job Access
CVE-2026-1005486.014.7OpenClawOpenClawCWE-200OpenClaw before 2026.8.1 Credential Exposure via Embedding Fallback
CVE-2026-1005598.614.5OpenClawOpenClawCWE-78OpenClaw before 2026.8.1 Command Injection via Escaped Newlines
CVE-2026-1005618.614.5OpenClawOpenClawCWE-88OpenClaw before 2026.8.1 Authentication Bypass via Exec Wrapper
CVE-2026-1005448.714.2openclawvoice-callCWE-862openclaw voice-call before 2026.8.1 Authorization Bypass
CVE-2026-1005868.714.2OpenClawOpenClawCWE-269OpenClaw Codex before 2026.7.1 Authorization Bypass via Bind
CVE-2026-1005878.714.2OpenClawOpenClawCWE-862OpenClaw before 2026.7.1 Authorization Bypass via Codex Install
CVE-2026-1005968.714.2OpenClawOpenClawCWE-862OpenClaw before 2026.7.1 Authorization Bypass via MCP Configuration
CVE-2026-1005255.314.1openclawdiagnostics-prometheusCWE-862OpenClaw diagnostics-prometheus before 2026.9.3 Authentication Bypass
CVE-2026-1005285.914.0OpenClawOpenClawCWE-200OpenClaw before 2026.8.1 Credential Disclosure via Provider Endpoint
CVE-2026-1005947.113.7OpenClawOpenClawCWE-200OpenClaw before 2026.7.1 Authorization Bypass via trajectory export
CVE-2026-1005957.113.7OpenClawOpenClawCWE-200OpenClaw before 2026.7.1 Authorization Bypass via diagnostics
CVE-2026-1005578.713.2OpenClawOpenClawCWE-863OpenClaw before 2026.8.1 Authorization Bypass via Skill Tool Dispatch
CVE-2026-1005407.612.6openclawfeishuCWE-863OpenClaw Feishu before 2026.8.1 Authentication Bypass via Disabled Account
CVE-2026-1005748.212.5OpenClawOpenClawCWE-918OpenClaw before 2026.8.1 SSRF via Trusted-Host DNS
CVE-2026-1005787.212.2OpenClawOpenClawCWE-269OpenClaw before 2026.7.1 Authorization Bypass via chat.send
CVE-2026-1005797.212.2OpenClawOpenClawCWE-639OpenClaw before 2026.7.1 Authentication Bypass via Spoofed Requester
CVE-2026-1005542.310.8OpenClawOpenClawCWE-613OpenClaw before 2026.8.1 Canvas Capability Revocation Bypass
CVE-2026-152736.410.8Automatic.cssAutomatic.cssCWE-79Automatic.css 4.0.0 - Unauthenticated Stored Cross-Site Scripting via REQUEST…
CVE-2026-1005535.310.7OpenClawOpenClawCWE-863OpenClaw 2026.6.9 before 2026.8.1 Cross-Context Policy Bypass via Feishu unpin
CVE-2026-1005225.110.2CotontiCotontiCWE-79Cotonti through 1.0.0 Reflected XSS via message.php lng parameter
CVE-2026-1005827.19.9openclawmsteamsCWE-862OpenClaw Channel Plugins before 2026.8.1 Channel Read Allowlist Bypass
CVE-2026-1005765.310.0OpenClawOpenClawCWE-918OpenClaw before 2026.8.1 SSRF via Browser Wait Predicates
CVE-2026-1005297.49.4OpenClawOpenClawCWE-863OpenClaw before 2026.8.1 Authorization Scope Widening via File-Transfer
CVE-2026-1005456.09.4OpenClawOpenClawCWE-863OpenClaw before 2026.8.1 Policy Bypass via Session Filename Generation
CVE-2026-1005392.19.3OpenClawOpenClawCWE-863OpenClaw before 2026.8.1 Memory Access Control Bypass
CVE-2026-1005666.99.0openclawlineCWE-863OpenClaw LINE before 2026.8.1 Access Control Inheritance
CVE-2026-1005215.18.9CotontiCotontiCWE-79Cotonti through 1.0.0 Reflected XSS via search highlight parameter
CVE-2026-1005557.18.5OpenClawOpenClawCWE-918OpenClaw before 2026.8.1 DNS Rebinding via attachment delivery
CVE-2026-1005858.68.1OpenClawOpenClawCWE-862OpenClaw before 2026.7.1 Authentication Bypass via MCP Channel
CVE-2026-1003122.18.0mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection
CVE-2026-1003112.07.8mathurvishalCloudClassroom-PHP-ProjectCWE-79mathurvishal CloudClassroom-PHP-Project Faculty Video Management managevideos…
CVE-2026-1005505.37.6OpenClawOpenClawCWE-863OpenClaw before 2026.8.1 Authentication Bypass via Access Group
CVE-2026-1005625.37.6OpenClawOpenClawCWE-863OpenClaw before 2026.8.1 Authorization Bypass via sessions.create
CVE-2026-1005635.37.6OpenClawOpenClawCWE-1236OpenClaw before 2026.8.1 CSV Formula Injection via Session Labels
CVE-2026-1005645.37.6OpenClawOpenClawCWE-1236OpenClaw before 2026.8.1 CSV Formula Injection via Attendance Export
CVE-2026-1005235.17.5CotontiCotontiCWE-601Cotonti through 1.0.0 Open Redirect via message.php redirect parameter
CVE-2026-1005372.37.5OpenClawOpenClawCWE-862OpenClaw before 2026.8.1 Authentication Bypass via Active Memory
CVE-2026-1005308.57.2OpenClawOpenClawCWE-863OpenClaw before 2026.8.1 Exec Approval Directory Binding
CVE-2026-1005835.37.0openclawdiscordCWE-862OpenClaw Discord before 2026.7.1 Authorization Bypass
CVE-2026-1005466.16.9OpenClawOpenClawCWE-362OpenClaw 2026.7.2 before 2026.9.2 Authentication Bypass via Voice Transcript
CVE-2026-1005905.36.5OpenClawOpenClawCWE-863OpenClaw before 2026.7.1 Authorization Bypass via voice set
CVE-2026-98163await6.6LinuxLinux—cgroup: Avoid iteration of dying tasks with zero refcount
CVE-2026-1005519.06.2OpenClawOpenClawCWE-295OpenClaw iOS Control UI TLS Pin Enforcement Bypass
CVE-2026-850817.56.0UnknownFile ManagerCWE-79Multiple elFinder Plugins - DOM-based XSS via postMessage Origin Bypass
CVE-2026-892376.85.9UnknownBluff PostCWE-89Bluff Post <= 1.1.1 - Unauthenticated SQLi via 'table_name' and 'column_name'…
CVE-2026-840976.54.8Unknownwp-review-slider-proCWE-89WP Review Slider Pro < 12.7.12 - Subscriber+ SQLi via Stored Template Filter
CVE-2026-1005915.34.4OpenClawOpenClawCWE-862OpenClaw before 2026.7.1 Authentication Bypass via Active Memory
CVE-2026-1005925.34.4OpenClawOpenClawCWE-862OpenClaw before 2026.7.1 Authentication Bypass via Memory Dreaming
CVE-2026-840958.04.3Unknownwp-review-slider-proCWE-79WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Import
CVE-2026-840968.04.3Unknownwp-review-slider-proCWE-79WP Review Slider Pro < 12.7.12 - Subscriber+ Stored XSS via Review Form Fields
CVE-2026-165917.23.7UnknownWP Directory KitCWE-79WP Directory Kit < 1.5.8 - Listing Admin+ Stored XSS via Category and Locatio…
CVE-2026-924116.83.7UnknownWP DeliciousCWE-79WP Delicious < 1.10.8 - Contributor+ Stored XSS via Recipe Block Tag Name
CVE-2026-965316.83.7UnknownOptimoleCWE-79Optimole 4.0.0 - 4.2.12 - Author+ Stored XSS via Video Player Block
CVE-2026-197085.93.2UnknownFile ManagerCWE-200File Manager 7.2.2 - 8.0.4 - Unauthenticated Database Backup Disclosure
CVE-2026-118715.33.2UnknownTeam MembersCWE-200Team Showcase Supreme <= 9.2 - Unauthenticated Sensitive Data Disclosure via …
CVE-2026-1005935.33.0OpenClawOpenClawCWE-862OpenClaw before 2026.7.1 Authentication Bypass via activation
CVE-2026-1005775.32.9OpenClawOpenClawCWE-918OpenClaw before 2026.8.1 Server-Side Request Forgery via Video Asset
CVE-2026-965262.72.7UnknownMCP Server for WordPressCWE-200MCP Server for WordPress < 1.8.2 - Contributor+ Arbitrary Post Title Disclosu…
CVE-2026-965327.52.5UnknownTestimonials WidgetCWE-862Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update
CVE-2026-965335.82.5UnknownTestimonials WidgetCWE-918Testimonials Widget <= 4.0.4 - Unauthenticated SSRF via Featured Image URL
CVE-2026-1005708.52.4OpenClawOpenClawCWE-88OpenClaw before 2026.8.1 Remote Code Execution via CLOUDSDK_PYTHON_ARGS
CVE-2026-965252.72.3UnknownMCP Server for WordPressCWE-862MCP Server for WordPress < 1.8.2 - Contributor+ Workflow Modification and Del…
CVE-2026-1005047.32.0NationalSecurityAgencyghidraCWE-787Ghidra through 12.1.4 Stack-based Buffer Overflow via leftshift128
CVE-2026-1005476.81.9OpenClawOpenClawCWE-180OpenClaw before 2026.8.1 Authentication Bypass via File URL
CVE-2026-1005245.31.8CotontiCotontiCWE-352Cotonti through 1.0.0 Cross-Site Request Forgery via Extensions Manager
CVE-2026-1005034.81.5NationalSecurityAgencyghidraCWE-416Ghidra through 12.1.4 Heap Use-After-Free in Decompiler
CVE-2026-1005696.81.5OpenClawOpenClawCWE-522OpenClaw before 2026.8.1 Credential Exposure via Endpoint Override
CVE-2026-1005054.81.5NationalSecurityAgencyghidraCWE-125Ghidra 11.2 through 12.1.4 Heap Out-of-Bounds Read via StringManager
CVE-2026-1005987.51.4OpenClawOpenClawCWE-346OpenClaw before 2026.7.1 Approval Binding Logic Error
CVE-2026-1005734.81.0OpenClawOpenClawCWE-862OpenClaw before 2026.8.1 Sandbox Policy Bypass via MCP Loopback
CVE-2026-965248.80.8UnknownMCP Server for WordPressCWE-352MCP Server for WordPress < 1.8.2 - Administrator Account Creation via CSRF
CVE-2026-1005845.40.7OpenClawOpenClawCWE-426OpenClaw before 2026.7.1 Allowlist Bypass via Workspace Shadows
CVE-2026-1005978.80.2OpenClawOpenClawCWE-367OpenClaw before 2026.7.1 Path Traversal via Filesystem Race
CVE-2026-1005816.80.1OpenClawOpenClawCWE-312OpenClaw iOS before 2026.8.11 Credential Storage via Share Extension
CVE-2026-9716310.0—lomart.frUP plugin for JoomlaCWE-22Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP…
CVE-2026-829019.8—themeficUltra Addons for Contact Form 7CWE-434Ultra Addons for Contact Form 7 <= 3.5.50 - Unauthenticated Arbitrary File Up…
CVE-2026-859849.8—cyberlord92miniOrange OTP Login, Verification and SMS NotificationsCWE-287miniOrange OTP Login, Verification and SMS Notifications <= 5.5.5 - Unauthent…
CVE-2026-941329.5—acymailing.comAcyMailing Enterprise extension for JoomlaCWE-434Joomla Extension - acymailing.com - Remote Code Execution vulnerability in ma…
CVE-2026-971609.4—lomart.frUP plugin for JoomlaCWE-94Joomla Extension - lomart.fr - Authenticated, privileged PHP command injectio…
CVE-2026-1007069.4—kyvernokyvernoCWE-441kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath
CVE-2026-1007149.4—froxlorfroxlorCWE-88Froxlor before 2.3.12 Command Injection via letsencryptchallengepath
CVE-2026-1007169.4—froxlorfroxlorCWE-59Froxlor before 2.3.12 Privilege Escalation via Symlink
CVE-2026-941309.3—joomlaboat.comYouTube Gallery extension for JoomlaCWE-89Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube …
CVE-2026-1007209.3—froxlorfroxlorCWE-79Froxlor before 2.3.12 Stored XSS via SSL certificate issuer
CVE-2026-971619.2—lomart.frUP plugin for JoomlaCWE-22Joomla Extension - lomart.fr - Various path traversal / file access vectors i…
CVE-2026-1006069.2—FlowiseAIFlowiseCWE-287Flowise through 3.1.4 Authentication Bypass via SSO Email Match
CVE-2026-1006079.2—FlowiseAIFlowiseCWE-287Flowise through 3.1.4 Authentication Bypass via Email-Only SSO
CVE-2026-1006849.2—budibaseserverCWE-287Budibase Server 3.41.0 before 3.45.0 Authentication Bypass via OIDC
CVE-2026-1006838.9—budibaseserverCWE-89Budibase before 3.45.0 SQL Injection via column-rename DDL
CVE-2026-772038.8—itthinxGroups – Memberships and Access ControlCWE-269Groups <= 4.6.0 - Authenticated (Subscriber+) Privilege Escalation via 'group…
CVE-2026-1006768.8—stoatchatstoatchatCWE-693stoatchat before 0.15.5 Local Filesystem Read via SVG
CVE-2026-1006038.7—openclawclawhubCWE-799ClawHub before 8c2de6c506 Skill Hiding via Coordinated Reports
CVE-2026-1006088.7—FlowiseAIFlowiseCWE-862Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard
CVE-2026-1006148.7—Cap-gocapgo.appCWE-639Capgo before 12.244.1 Cross-Tenant Image Overwrite via Metadata Worker
CVE-2026-1006158.7—Cap-gocapgo.appCWE-269Cap-go capgo.app before 12.267.1 Privilege Escalation via API Key Rotation
CVE-2026-1006178.7—Cap-gocapgo.appCWE-862Cap-go capgo.app Authorization Bypass via channel_permission_overrides
CVE-2026-1006188.7—Cap-gocapgo.appCWE-639Capgo App Icon Update Privilege Escalation via Service-Role Worker
CVE-2026-1006198.7—Cap-gocapgo.appCWE-266Capgo OTA Manifest Poisoning via app_versions.manifest Bypass
CVE-2026-1006228.7—Cap-gocapgo.appCWE-200capgo.app through 12.129.0 Cache Restoration of Deleted Bundles
CVE-2026-1006238.7—Cap-gocapgo.appCWE-863Capgo Authentication Bypass via Direct PostgREST org_users Table Write
CVE-2026-1006258.7—Cap-gocapgo.appCWE-441Capgo Build Upload Proxy Authorization Bypass via TUS Resource
CVE-2026-1006288.7—Cap-gocapgo.appCWE-863capgo.app before 12.128.12 Authentication Bypass via apikey
CVE-2026-1006318.7—parse-communityparse-serverCWE-943Parse Server 9.0.0 Unauthenticated Installation Deletion via Operator Injection
CVE-2026-1006448.7—siyuan-notesiyuanCWE-89SiYuan before v3.8.4 SQL Injection via dailyNoteSavePath
CVE-2026-1006568.7—nettynettyCWE-770Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining
CVE-2026-1006578.7—nettynettyCWE-772Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder
CVE-2026-1006608.7—nettynettyCWE-770Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention
CVE-2026-1006618.7—nettynettyCWE-400Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation
CVE-2026-1006628.7—nettynettyCWE-400Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS
CVE-2026-1006638.7—nettynettyCWE-20Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3
CVE-2026-1006648.7—nettynettyCWE-20Netty 4.2.2 through 4.2.15 HTTP/1 Host Header Authority Confusion
CVE-2026-1006658.7—nettynettyCWE-295Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass
CVE-2026-1006698.7—getgravgravCWE-178Grav before 2.0.25 Sensitive File Disclosure via Case-Variation Bypass
CVE-2026-1006708.7—getgravgravCWE-639Grav CMS 2.0.14 through 2.0.24 Privilege Escalation via Blueprint Guard Bypass
CVE-2026-1006728.7—getgravgravCWE-306grav-plugin-comments before 1.2.11 Unauthenticated Information Disclosure
CVE-2026-1006828.7—budibaseserverCWE-22Budibase Server before 3.45.0 Arbitrary File Write via ZIP Symlink
CVE-2026-1006898.7—gitpython-developersGitPythonCWE-22GitPython before 3.1.62 Path Traversal via gitmodules path
CVE-2026-1006908.7—gohugoiohugoCWE-59Hugo v0.161.0 to v0.165.0 Arbitrary File Read via Symlinks
CVE-2026-1006928.7—gohugoiohugoCWE-59Hugo before v0.166.0 Path Traversal via Symlinked Mount Roots
CVE-2026-1007008.7—nodemailernodemailerCWE-407nodemailer before 10.0.6 Denial of Service via addressparser
CVE-2026-1007118.7—froxlorfroxlorCWE-613froxlor before 2.3.12 Authentication Bypass via Session Persistence
CVE-2026-1006128.6—Cap-gocapgo.appCWE-639Capgo SSO Provider ID Authentication Bypass via Incomplete Migration
CVE-2026-1006398.6—siyuan-notesiyuanCWE-79SiYuan before v3.8.4 Cross-Site Scripting via Kramdown IAL
CVE-2026-1006408.6—siyuan-notesiyuanCWE-200SiYuan before v3.8.4 Clipboard Data Disclosure via IPC
CVE-2026-1006418.6—siyuan-notesiyuanCWE-79SiYuan before v3.8.4 Stored XSS via Unescaped Flashcard Content
CVE-2026-1006458.6—siyuan-notesiyuanCWE-79SiYuan 3.7.0 before 3.8.4 Stored XSS via Gallery Kanban
CVE-2026-1006468.6—siyuan-notesiyuanCWE-346SiYuan before v3.8.4 Authentication Bypass via Missing Origin Header
CVE-2026-1006718.6—getgravgravCWE-200Grav before 2.0.25 Session Cookie Theft via Twig Sandbox
CVE-2026-1006808.6—budibaseserverCWE-200Budibase before 3.45.0 Arbitrary Local File Read via OpenAPI Import
CVE-2026-1006868.6—budibaseserverCWE-269Budibase before 3.45.0 Cross-Workspace Privilege Escalation via POST /api/glo…
CVE-2026-1006938.6—gohugoiohugoCWE-178Hugo v0.162.0 before v0.166.0 IP-literal Deny Rule Bypass
CVE-2026-1006338.5—siyuan-notesiyuanCWE-863SiYuan 3.8.0 through 3.8.3 Path Traversal via MCP File Operations
CVE-2026-1006438.5—siyuan-notesiyuanCWE-79SiYuan before v3.8.4 Stored XSS via Attribute View textarea
CVE-2026-1007158.5—froxlorfroxlorCWE-59Froxlor before 2.3.12 Arbitrary File Deletion via Symlink
CVE-2026-1007178.5—froxlorfroxlorCWE-93froxlor before 2.3.12 CRLF Injection via validateUrl userinfo
CVE-2026-1006738.4—getgravgravCWE-79Grav Data Manager before 1.4.5 Stored XSS via item-detail view
CVE-2026-941318.3—acymailing.comAcyMailing extension for JoomlaCWE-89Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion i…
CVE-2026-971628.3—lomart.frUP plugin for JoomlaCWE-89Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin ext…
CVE-2026-1006368.3—siyuan-notesiyuanCWE-22SiYuan before v3.8.4 Path Traversal via exportBrowserHTML folder
CVE-2026-1006378.3—siyuan-notesiyuanCWE-73SiYuan before v3.8.4 Path Traversal via checkoutRepo sessionID
CVE-2026-1006388.3—siyuan-notesiyuanCWE-73SiYuan before v3.8.4 Path Traversal via setNotebookIcon
CVE-2026-1006538.3—vllm-projectvllmCWE-348vLLM 0.22.1 before 0.28.0 Incomplete Artifact Pin Propagation
CVE-2026-1006788.3—stoatchatstoatchatCWE-307stoatchat before 0.15.5 MFA Brute Force via Insufficient Rate Limiting
CVE-2026-1006858.3—budibaseserverCWE-863Budibase before 3.45.0 Information Disclosure via Chat Links
CVE-2026-1007038.3—kyvernokyvernoCWE-200Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib
CVE-2026-1007048.3—kyvernokyvernoCWE-863Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass
CVE-2026-1007058.3—kyvernokyvernoCWE-918Kyverno before 1.19.1 SSRF via legacy apiCall service executor
CVE-2026-1007078.3—kyvernokyvernoCWE-22Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path
CVE-2026-1006358.2—siyuan-notesiyuanCWE-319SiYuan before v3.8.4 Authentication Bypass via Plaintext Session Cookie
CVE-2026-1006528.2—vllm-projectvllmCWE-20vLLM 0.22.0 through 0.23.0 Denial of Service via stop_token_ids
CVE-2026-1007028.2—nodemailernodemailerCWE-674Nodemailer before 10.0.2 Stack Exhaustion via Nested Recipient Arrays
CVE-2026-1006107.7—FlowiseAIFlowiseCWE-639Flowise through 3.1.4 Missing Authorization via upsert-history
CVE-2026-1007097.7—froxlorfroxlorCWE-287Froxlor before 2.3.12 2FA Bypass via Namespace Confusion
CVE-2026-1006097.6—FlowiseAIFlowiseCWE-639Flowise through 3.1.4 Insecure Direct Object Reference via Credential
CVE-2026-1006057.5—FlowiseAIFlowiseCWE-862Flowise through 3.1.4 Missing Authorization via Chat Message Routes
CVE-2026-726687.3—ElasticKibanaCWE-441Unintended Proxy or Intermediary ('Confused Deputy') in Kibana Leading to Pri…
CVE-2026-1006277.2—Cap-gocapgo.appCWE-639Capgo bundle promotion API channel RBAC deny override bypass
CVE-2026-1006427.2—siyuan-notesiyuanCWE-346SiYuan v2.1.0 before v3.8.4 Cross-Site Request Forgery via CheckAuth
CVE-2026-1006027.1—openclawclawhubCWE-862ClawHub Changelog Preview Information Disclosure via Authorization Bypass
CVE-2026-1006117.1—Cap-gocapgo.appCWE-269Capgo apikey_manager Role Privilege Escalation via Incomplete Role Deny-list
CVE-2026-1006327.1—parse-communityparse-serverCWE-200Parse Server 9.0.0 before 9.10.1 Protected Fields Disclosure via LiveQuery
CVE-2026-1006507.1—vllm-projectvllmCWE-400vLLM before 0.29.0 Resource Exhaustion via Unbounded Media Materialization
CVE-2026-1006517.1—vllm-projectvllmCWE-400vllm before 0.29.0 Denial of Service via Decoder Prompt Length Bypass
CVE-2026-1006547.1—vllm-projectvllmCWE-129vLLM before 0.29.0 Denial of Service via out-of-range stop_token_ids
CVE-2026-1006687.1—getgravgravCWE-200Grav before 2.0.25 Sandbox Escape via array Filter
CVE-2026-1006757.1—stoatchatstoatchatCWE-248stoatchat before 0.15.5 Denial of Service via mass mentions
CVE-2026-1006797.1—stoatchatstoatchatCWE-639stoatchat before 0.15.5 MFA Bypass via Cross-Account Ticket
CVE-2026-1006887.1—budibaseserverCWE-639Budibase server before 3.45.0 Cross-Tenant Information Disclosure
CVE-2026-1007087.1—froxlorfroxlorCWE-200Froxlor before 2.3.13 Private Key Disclosure via Certificates API
CVE-2026-1007127.1—froxlorfroxlorCWE-352froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF
CVE-2026-1007137.1—froxlorfroxlorCWE-367Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync
CVE-2026-1007187.1—froxlorfroxlorCWE-276Froxlor before 2.3.12 Authentication Bypass via EmailSender.add
CVE-2026-1007197.1—froxlorfroxlorCWE-200Froxlor before 2.3.12 Credential Disclosure via DirProtections API
CVE-2026-1006167.0—Cap-gocapgo.appCWE-863capgo.app Authentication Bypass via PostgREST customer_id Mutation
CVE-2026-1006297.0—Cap-gocapgo.appCWE-863Capgo backend before 12.127.5 Privilege Escalation via role_bindings PATCH
CVE-2026-1006877.0—budibaseserverCWE-200Budibase Server before 3.45.0 Credential Exposure via External Table Broadcast
CVE-2026-1006006.9—openclawclawhubCWE-770ClawHub before 8c2de6c506 Quota Exhaustion via Anonymous API
CVE-2026-1006016.9—openclawclawhubCWE-918ClawHub SSRF via Unchecked DNS Resolution in Profile Image
CVE-2026-1006476.9—vllm-projectvllmCWE-20vLLM before 0.29.0 CPU Exhaustion via unbounded cache_salt
CVE-2026-1006486.9—vllm-projectvllmCWE-400vllm before 0.29.0 Uncontrolled Resource Consumption via Audio Decoding
CVE-2026-1006556.9—nettynettyCWE-770Netty before 4.1.138.Final Denial of Service via SpdySessionHandler
CVE-2026-1006586.9—nettynettyCWE-770Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler
CVE-2026-1006596.9—nettynettyCWE-444Netty 4.2.0 through 4.2.18 HTTP/3 Request Routing Bypass
CVE-2026-1006666.9—nettynettyCWE-444Netty 4.2.0 through 4.2.17 Response Desynchronization via HttpServerCodec
CVE-2026-1006676.9—getgravgravCWE-304grav-plugin-login 3.8.7 through 3.9.6 Two-Factor Authentication Bypass
CVE-2026-1006776.9—stoatchatstoatchatCWE-209stoatchat before 0.15.5 Account Enumeration via Error Location
CVE-2026-1006966.9—vranaadminerCWE-918Adminer before 6.0.2 Unauthenticated SSRF via Elasticsearch Driver
CVE-2026-1006986.9—vranaadminerCWE-918Adminer before 6.0.2 Privileged-Port SSRF via host_port Regex
CVE-2026-1006996.9—nodemailernodemailerCWE-20Nodemailer before 10.0.9 Malformed Envelope Recipient via RFC 5322 Comment
CVE-2026-1007106.9—froxlorfroxlorCWE-200Froxlor before 2.3.12 DKIM Private Key Disclosure via API
CVE-2026-785826.5—ElasticKibanaCWE-862Missing Authorization in Kibana Leading to Unauthorized Deletion of Data
CVE-2026-822946.5—ElasticElasticsearchCWE-400Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-823006.5—ElasticElasticsearchCWE-400Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-943966.5—ElasticElasticsearchCWE-400Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
CVE-2026-943976.5—ElasticElasticsearchCWE-400Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
CVE-2026-943986.5—ElasticElasticsearchCWE-400Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
CVE-2026-943996.5—ElasticElasticsearchCWE-400Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
CVE-2026-944006.5—ElasticKibanaCWE-400Uncontrolled Resource Consumption in Kibana Leading to denial of service
CVE-2026-726626.3—ElasticKibanaCWE-639Authorization Bypass Through User-Controlled Key in Kibana Leading to Unautho…
CVE-2026-1006496.3—vllm-projectvllmCWE-770vLLM before 0.29.0 Resource Limit Bypass via Sampler Subclass
CVE-2026-1006816.3—budibaseserverCWE-918Budibase before 3.45.0 SSRF and OAuth Token Exfiltration via Teams Webhook
CVE-2026-1006136.0—Cap-gocapgo.appCWE-863capgo.app Authorization Bypass via Stale Channel Permission Overrides
CVE-2026-1007016.0—nodemailernodemailerCWE-295Nodemailer 5.0.0 through 10.0.1 TLS servername Cache Confusion
CVE-2026-1003145.5—mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project updatedetailsfromstudent.php sql inje…
CVE-2026-1003155.5—mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project mydetailsfaculty.php sql injection
CVE-2026-1007395.5—mathurvishalCloudClassroom-PHP-ProjectCWE-74mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection
CVE-2026-1006045.3—openclawclawhubCWE-863ClawHub Authentication Bypass via Former Publisher Skill Control
CVE-2026-1006215.3—Cap-gocapgo.appCWE-284capgo.app Content-Lock Bypass via r2-direct Bundle Mutation
CVE-2026-1006245.3—Cap-gocapgo.appCWE-613Capgo.app before 12.264.5 Upload Expiry Bypass via build upload
CVE-2026-1006265.3—Cap-gocapgo.appCWE-639capgo through 12.128.2 IDOR via PUT /app icon endpoint
CVE-2026-1006345.3—siyuan-notesiyuanCWE-862SiYuan before v3.8.4 Missing Authorization via siyuan-send-windows
CVE-2026-1006745.3—stoatchatstoatchatCWE-180stoatchat before 0.15.5 Username Validation Bypass via Unicode Sanitization
CVE-2026-1006955.3—vranaadminerCWE-79Adminer before 6.0.2 XSS via CONNECTION_ID escalating to RCE
CVE-2026-1006975.3—vranaadminerCWE-918Adminer 6.0.0 Server-Side Request Forgery via ClickHouse driver
CVE-2026-1006205.1—Cap-go@capgo/cliCWE-269Capgo CLI through 7.98.2 Excessive Permissions via Overpermissioned Play Cons…
CVE-2026-1006305.1—WWBNAVideoCWE-79AVideo Stored XSS via HTML Entity Bypass in trailer1 Field
CVE-2026-1006915.1—gohugoiohugoCWE-79Hugo before 0.166.0 Stored XSS via lineAnchors code block option
CVE-2026-1006945.1—gohugoiohugoCWE-79Hugo before 0.166.0 Cross-Site Scripting via text/org
CVE-2026-944084.9—ElasticElasticsearchCWE-400Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service
CVE-2026-1003132.1—mathurvishalCloudClassroom-PHP-ProjectCWE-79mathurvishal CloudClassroom-PHP-Project updatequery.php cross site scripting

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-09-26 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.