CVE-2026-81159Low· 3.7▾ SunlitObservable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 16.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commerce CyberSource versions: from 0.0.0 to 1.10.0.
commerce_cybersource >= 8.x-1.0, < 8.x-1.10Upgrade past the affected range:
commerce_cybersource 8.x-1.10Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73475Critical· 9.1Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing
CVE-2026-77987Critical· 9.3A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server
CVE-2026-63132Critical· 9.2OpenBao is an open source identity-based secrets management system
CVE-2026-85725Medium· 5.9LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-88010Medium· 6.3Traefik is an open source HTTP reverse proxy and load balancer
CVE-2026-15432Medium· 5.9When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison