Two unauthenticated flaws in IBM WebSphere Application Server traditional let remote attackers execute arbitrary code or escalate privileges through the administrative console.
A flaw in the chunked upload handler of WPForms Pro lets an unauthenticated attacker leave executable files on a WordPress server, opening a path to remote code execution.
A flaw in the Authentication Engine of Oracle Access Manager lets an unauthenticated attacker take over the single sign-on service that fronts an organization’s internal applications.
Oracle’s July 2026 Critical Patch Update fixes multiple flaws in WebLogic Server’s Core component, several letting an unauthenticated attacker fully take over the server over T3, IIOP, HTTP, and SOAP.
A PHP object injection flaw in PrestaShop’s ps_facetedsearch module lets an unauthenticated attacker smuggle a malicious object through a slider filter and achieve remote code execution on the storefront.
wp2shell chains a REST API batch-route confusion flaw with a SQL injection in WordPress core’s WP_Query, letting an unauthenticated attacker run code on a default install and take over the site.
A missing authentication flaw in on-premises Microsoft SharePoint Server lets an unauthenticated attacker escalate privileges over the network, a zero-day Microsoft confirms is already under active exploitation.
An unauthenticated file upload flaw in Balbooa Forms for Joomla lets any anonymous visitor drop a PHP file into a public folder, resulting in full remote code execution.
A blind SQL injection in Control Web Panel’s userRes parameter lets attackers with a guessable username gain MySQL root access, enabling full server takeover via a planted PHP webshell.
Two pre-authentication vulnerabilities in BeyondTrust Remote Support and Privileged Remote Access let attackers bypass authentication entirely and gain unauthorized, potentially privileged, access to affected appliances.