Skip to content

CVE / Vulnerability Advisories

Tracked vulnerabilities with CVSS scores, affected products, patch status, and technical analysis.

Sev:Patch:
CVE IDCVSSSeverityProduct / VendorPatch StatusDateSummary
CVE-2026-488219.8CRITICAL
Nginx 1.26.x
Nginx Inc.
Patched2026-09-22Heap overflow in HTTP/2 stack allows unauthenticated RCE.
CVE-2026-510339.8CRITICAL
Apache Struts 2.5.x / 6.0.x
Apache
Patched2026-09-18Java deserialization flaw enables pre-auth RCE via OGNL.
CVE-2026-391048.1HIGH
OpenVPN 2.6.x
OpenVPN Inc.
Patched2026-09-15TLS session resumption bypass allows unauthorised channel access.
CVE-2026-442127.5HIGH
GitLab CE/EE 17.x
GitLab
Patched2026-09-10SSRF in import pipeline allows access to internal services.
CVE-2026-520176.5MEDIUM
WordPress WooCommerce 8.x
Automattic
Patched2026-09-06Broken access control allows order data enumeration by unauthenticated users.
CVE-2026-478839CRITICAL
Fortinet FortiProxy 7.4.x
Fortinet
Unpatched2026-09-03Auth bypass in web proxy allows admin panel access without credentials.
CVE-2026-400915.3MEDIUM
Elasticsearch 8.x
Elastic
Mitigated2026-08-28Information disclosure via debug endpoint exposes internal cluster metadata.
CVE-2026-366128.8HIGH
Microsoft Exchange 2019
Microsoft
Patched2026-08-20ProxyRelay-class NTLM relay allows privilege escalation to Domain Admin.
CVE-2026-619029.6CRITICAL
Palo Alto PAN-OS 11.1
Palo Alto Networks
Patched2026-08-16Command injection vulnerability in management interface allows unauthenticated root code execution.
CVE-2026-550997.2HIGH
SonicWall SMA 1000
SonicWall
Patched2026-08-12Buffer overflow in SSL-VPN handler allows remote denial of service and potential code execution.
CVE IDCVE-2026-48821
CVSS9.8
SeverityCRITICAL
ProductNginx 1.26.x
VendorNginx Inc.
Patch StatusPatched
Date2026-09-22
SummaryHeap overflow in HTTP/2 stack allows unauthenticated RCE.
CVE IDCVE-2026-51033
CVSS9.8
SeverityCRITICAL
ProductApache Struts 2.5.x / 6.0.x
VendorApache
Patch StatusPatched
Date2026-09-18
SummaryJava deserialization flaw enables pre-auth RCE via OGNL.
CVE IDCVE-2026-39104
CVSS8.1
SeverityHIGH
ProductOpenVPN 2.6.x
VendorOpenVPN Inc.
Patch StatusPatched
Date2026-09-15
SummaryTLS session resumption bypass allows unauthorised channel access.
CVE IDCVE-2026-44212
CVSS7.5
SeverityHIGH
ProductGitLab CE/EE 17.x
VendorGitLab
Patch StatusPatched
Date2026-09-10
SummarySSRF in import pipeline allows access to internal services.
CVE IDCVE-2026-52017
CVSS6.5
SeverityMEDIUM
ProductWordPress WooCommerce 8.x
VendorAutomattic
Patch StatusPatched
Date2026-09-06
SummaryBroken access control allows order data enumeration by unauthenticated users.
CVE IDCVE-2026-47883
CVSS9
SeverityCRITICAL
ProductFortinet FortiProxy 7.4.x
VendorFortinet
Patch StatusUnpatched
Date2026-09-03
SummaryAuth bypass in web proxy allows admin panel access without credentials.
CVE IDCVE-2026-40091
CVSS5.3
SeverityMEDIUM
ProductElasticsearch 8.x
VendorElastic
Patch StatusMitigated
Date2026-08-28
SummaryInformation disclosure via debug endpoint exposes internal cluster metadata.
CVE IDCVE-2026-36612
CVSS8.8
SeverityHIGH
ProductMicrosoft Exchange 2019
VendorMicrosoft
Patch StatusPatched
Date2026-08-20
SummaryProxyRelay-class NTLM relay allows privilege escalation to Domain Admin.
CVE IDCVE-2026-61902
CVSS9.6
SeverityCRITICAL
ProductPalo Alto PAN-OS 11.1
VendorPalo Alto Networks
Patch StatusPatched
Date2026-08-16
SummaryCommand injection vulnerability in management interface allows unauthenticated root code execution.
CVE IDCVE-2026-55099
CVSS7.2
SeverityHIGH
ProductSonicWall SMA 1000
VendorSonicWall
Patch StatusPatched
Date2026-08-12
SummaryBuffer overflow in SSL-VPN handler allows remote denial of service and potential code execution.

Note: All CVE identifiers shown are fictional and used for demonstration purposes only. CVSS scores and technical details are illustrative.