An improper authentication flaw in FortiWeb’s remote RADIUS admin group handling lets an unauthenticated attacker log in to the appliance’s management interface and take administrative control.
An incorrect authorization flaw in Adobe Commerce and Magento Open Source lets an unauthenticated attacker switch a customer session to another account, exposing the victim’s personal data.
A type confusion flaw in n8n’s Send Email node lets crafted workflow input reach the mail library as a file path or URL, exposing local files and enabling SSRF.
A flaw in the Remote Access SSL VPN service of Cisco ASA and FTD software lets an unauthenticated attacker reload the device, knocking firewalls and VPN gateways offline.
An authentication bypass in PicketLink Federation lets an unauthenticated attacker forge SAML assertions and sign in to JBoss EAP applications as any user, including administrators.
A memory corruption flaw in SAP NetWeaver Application Server ABAP lets an unauthenticated attacker crash the system or disclose sensitive system information through crafted DIAG protocol traffic.
A privilege escalation flaw in cPanel & WHM’s database management lets any authenticated hosting account execute database commands with full administrative privileges, exposing every database on the server.
A code injection flaw in Gitea’s diffpatch endpoint lets a user with repository write access install a Git hook and run arbitrary shell commands as the Gitea service account.
Apache Traffic Server’s July 2026 security release patches dozens of flaws across its plugin surface, with the most severe letting unauthenticated attackers crash proxy tiers and bypass access controls.
An out-of-bounds write in Samba’s internal DNS server lets an unauthenticated attacker crash a domain controller’s DNS process with a single crafted TSIG packet.