Security Risk Severity

Critical Security Risks — Page 4

Published vulnerability pages grouped by critical severity. Use this page to review risks that need similar prioritization.

288 published critical risks

Critical severity

Showing 109–144 of 288 published risks.

Clear
critical

CVE-2026-62392 in Apache Kylin

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Kylin. A backend API may bring job config parameters to OS command line. This issue affects Apache Kylin: from 4 through 5.0.3. Users are recommended to upgrade to version 5.0.4, which fixes the issue.

CVE-2026-62392javaapi-securityremote-code-execution

Updated Jul 15, 2026

critical

CVE-2026-58479 in Sustainable Irrigation Platform

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor', to achieve arbitrary command execution on the underlying host.

CVE-2026-58479industrial-controlremote-code-executioncsrf

Updated Jul 15, 2026

criticalCISA KEV

CVE-2026-56155 in Active Directory Federation Services

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

CVE-2026-56155windowsmicrosoftauthorization-bypassprivilege-escalation

Updated Jul 15, 2026

criticalCISA KEV

CVE-2026-56164 in Microsoft SharePoint Server

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56164microsoftweb-applicationauthentication-bypassprivilege-escalation

Updated Jul 15, 2026

critical

CVE-2026-13001 in Podlove Podcast Publisher

The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2026-13001wordpressremote-code-executioninput-validationfile-upload

Updated Jul 15, 2026

criticalCISA KEV

CVE-2026-15409 in SonicWall SMA 1000 Series

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

CVE-2026-15409network-securityssrf

Updated Jul 15, 2026

criticalCISA KEV

CVE-2026-15410 in SonicWall SMA 1000 Series

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

CVE-2026-15410network-securityremote-code-execution

Updated Jul 15, 2026

criticalEPSS 0.006

CVE-2026-50160 in Hoppscotch

Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and earlier, the unauthenticated POST /v1/onboarding/config endpoint is vulnerable to mass assignment. The global NestJS ValidationPipe is configured without whitelist: true, so extra properties on the request body that are not declared in SaveOnboardingConfigRequest are not stripped and are iterated in the service layer as if they were legitimate InfraConfig entries. Because keys such as JWT_SECRET and SESSION_SECRET are valid InfraConfigEnum values and are not explicitly rejected during validation, an unauthenticated attacker who can reach a fresh instance before onboarding completes (or when no users exist) can overwrite these values in the database. Overwriting JWT_SECRET gives the attacker control of the JWT signing key, allowing them to forge tokens for any user, including administrators, and results in full server compromise. The issue is fixed in hoppscotch 2026.5.0.

CVE-2026-50160api-securityweb-applicationauthentication-bypassprivilege-escalation

Updated Jul 15, 2026

criticalEPSS 0.003

CVE-2026-14382 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14382browserremote-code-executioninput-validation

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14387 in Google Chrome Skia

Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14387browserremote-code-executioninput-validation

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14390 in Google Chrome ANGLE

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14390browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14392 in Google Chrome Tint

Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14392browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14397 in Google Chrome ANGLE

Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14397browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14398 in Google Chrome ANGLE

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14398browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14405 in Google Chrome V8

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14405browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14411 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14411browserremote-code-executioninput-validation

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14416 in Google Chrome Dawn

Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14416browserremote-code-executioninformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14417 in Google Chrome Dawn

Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14417browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14419 in Google Chrome Skia

Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14419browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14420 in Google Chrome Dawn

Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14420browserremote-code-executioninformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14423 in Google Chrome Tint

Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14423browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14424 in Google Chrome Dawn

Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14424browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14425 in Google Chrome ANGLE

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14425browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.009

CVE-2026-50746 in UniFi Connect Application

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.

CVE-2026-50746network-securityremote-code-executionauthorization-bypass

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-50747 in UniFi Talk Application

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.

CVE-2026-50747network-securitysql-injectionprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.009

CVE-2026-50748 in UniFi Access Application

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

CVE-2026-50748network-securityremote-code-executioninput-validationprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-54400 in UniFi Access Application

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.

CVE-2026-54400network-securityauthorization-bypassprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.009

CVE-2026-54402 in UniFi OS Server

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.

CVE-2026-54402network-securityremote-code-executioninput-validationprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-55115 in UniFi Protect Application

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.

CVE-2026-55115network-securityssrfprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-55116 in UniFi OS Devices

A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.

CVE-2026-55116network-securityauthorization-bypass

Updated Jul 14, 2026

criticalEPSS 0.006

CVE-2026-44935 in SUSE Rancher Fleet

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and 0.12 before 0.12.15 could be used by owners of one tenant to access fleet credentials of other tenants.

CVE-2026-44935cloud-securitydevopsauthorization-bypassinformation-disclosure

Updated Jul 14, 2026

criticalEPSS 0.004

CVE-2026-38968 ntopng Vulnerability

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.

CVE-2026-38968network-securityauthentication-bypass

Updated Jul 14, 2026

criticalEPSS 0.005

CVE-2026-38971 ArduPilot ArduPlane Vulnerability

ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control().

CVE-2026-38971industrial-controlinformation-disclosure

Updated Jul 14, 2026

criticalEPSS 0.005

CVE-2026-41106 Microsoft 365 Copilot Vulnerability

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-41106microsoftcloud-securityopen-redirect

Updated Jul 14, 2026

criticalEPSS 0.006

CVE-2026-45499 Azure OpenAI Vulnerability

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

CVE-2026-45499microsoftcloud-securityssrf

Updated Jul 14, 2026

criticalEPSS 0.006

CVE-2026-57100 Microsoft Entra Provisioning Service Vulnerability

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

CVE-2026-57100microsoftcloud-securityssrf

Updated Jul 14, 2026