CVE / Vulnerability Advisories
Tracked vulnerabilities with CVSS scores, affected products, patch status, and technical analysis.
| CVE ID | CVSS | Severity | Product / Vendor | Patch Status | Date | Summary |
|---|---|---|---|---|---|---|
| CVE-2026-48821 | 9.8 | CRITICAL | Nginx 1.26.x Nginx Inc. | Patched | 2026-09-22 | Heap overflow in HTTP/2 stack allows unauthenticated RCE. |
| CVE-2026-51033 | 9.8 | CRITICAL | Apache Struts 2.5.x / 6.0.x Apache | Patched | 2026-09-18 | Java deserialization flaw enables pre-auth RCE via OGNL. |
| CVE-2026-39104 | 8.1 | HIGH | OpenVPN 2.6.x OpenVPN Inc. | Patched | 2026-09-15 | TLS session resumption bypass allows unauthorised channel access. |
| CVE-2026-44212 | 7.5 | HIGH | GitLab CE/EE 17.x GitLab | Patched | 2026-09-10 | SSRF in import pipeline allows access to internal services. |
| CVE-2026-52017 | 6.5 | MEDIUM | WordPress WooCommerce 8.x Automattic | Patched | 2026-09-06 | Broken access control allows order data enumeration by unauthenticated users. |
| CVE-2026-47883 | 9 | CRITICAL | Fortinet FortiProxy 7.4.x Fortinet | Unpatched | 2026-09-03 | Auth bypass in web proxy allows admin panel access without credentials. |
| CVE-2026-40091 | 5.3 | MEDIUM | Elasticsearch 8.x Elastic | Mitigated | 2026-08-28 | Information disclosure via debug endpoint exposes internal cluster metadata. |
| CVE-2026-36612 | 8.8 | HIGH | Microsoft Exchange 2019 Microsoft | Patched | 2026-08-20 | ProxyRelay-class NTLM relay allows privilege escalation to Domain Admin. |
| CVE-2026-61902 | 9.6 | CRITICAL | Palo Alto PAN-OS 11.1 Palo Alto Networks | Patched | 2026-08-16 | Command injection vulnerability in management interface allows unauthenticated root code execution. |
| CVE-2026-55099 | 7.2 | HIGH | SonicWall SMA 1000 SonicWall | Patched | 2026-08-12 | Buffer overflow in SSL-VPN handler allows remote denial of service and potential code execution. |
CVE IDCVE-2026-48821
CVSS9.8
SeverityCRITICAL
ProductNginx 1.26.x
VendorNginx Inc.
Patch StatusPatched
Date
SummaryHeap overflow in HTTP/2 stack allows unauthenticated RCE.
CVE IDCVE-2026-51033
CVSS9.8
SeverityCRITICAL
ProductApache Struts 2.5.x / 6.0.x
VendorApache
Patch StatusPatched
Date
SummaryJava deserialization flaw enables pre-auth RCE via OGNL.
CVE IDCVE-2026-39104
CVSS8.1
SeverityHIGH
ProductOpenVPN 2.6.x
VendorOpenVPN Inc.
Patch StatusPatched
Date
SummaryTLS session resumption bypass allows unauthorised channel access.
CVE IDCVE-2026-44212
CVSS7.5
SeverityHIGH
ProductGitLab CE/EE 17.x
VendorGitLab
Patch StatusPatched
Date
SummarySSRF in import pipeline allows access to internal services.
CVE IDCVE-2026-52017
CVSS6.5
SeverityMEDIUM
ProductWordPress WooCommerce 8.x
VendorAutomattic
Patch StatusPatched
Date
SummaryBroken access control allows order data enumeration by unauthenticated users.
CVE IDCVE-2026-47883
CVSS9
SeverityCRITICAL
ProductFortinet FortiProxy 7.4.x
VendorFortinet
Patch StatusUnpatched
Date
SummaryAuth bypass in web proxy allows admin panel access without credentials.
CVE IDCVE-2026-40091
CVSS5.3
SeverityMEDIUM
ProductElasticsearch 8.x
VendorElastic
Patch StatusMitigated
Date
SummaryInformation disclosure via debug endpoint exposes internal cluster metadata.
CVE IDCVE-2026-36612
CVSS8.8
SeverityHIGH
ProductMicrosoft Exchange 2019
VendorMicrosoft
Patch StatusPatched
Date
SummaryProxyRelay-class NTLM relay allows privilege escalation to Domain Admin.
CVE IDCVE-2026-61902
CVSS9.6
SeverityCRITICAL
ProductPalo Alto PAN-OS 11.1
VendorPalo Alto Networks
Patch StatusPatched
Date
SummaryCommand injection vulnerability in management interface allows unauthenticated root code execution.
CVE IDCVE-2026-55099
CVSS7.2
SeverityHIGH
ProductSonicWall SMA 1000
VendorSonicWall
Patch StatusPatched
Date
SummaryBuffer overflow in SSL-VPN handler allows remote denial of service and potential code execution.