VulnSea

Daily digest · in progress

Wednesday 30 September 2026

A quiet day: only 35 new CVEs against a recent average of about 449 so far. Severity skewed high: 4 critical and 16 high, 57% of the total. WatchGuard was the most-affected vendor with 14.

35
New CVEs
4
Critical
0
KEV additions
10
Records changed

New this day, ranked by depth score

The 12 that matter most of the 35 published.

CVE-2026-86131Critical· 9.2
today

A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.

A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.

▾ MidnightWatchGuard · Fireware OSvia NVD
CVE-2026-103056Critical· 9.0
today

AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoin…

AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoin…

▾ Midnightbeenuar · AiSOCvia NVD
CVE-2026-102794Critical· 9.1
today

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0

A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the atta…

▾ MidnightZiroom · ZHOME A0101via NVD
CVE-2026-102793Critical· 9.1
today

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0

A flaw has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function set_time_zone of the file /api/ZRFirmware/set_time_zone. This manipulation of the argument hostname/zonename causes command injection. It is pos…

▾ MidnightZiroom · ZHOME A0101via NVD
CVE-2026-86104High· 8.7
today

An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.

An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.

▾ TwilightWatchGuard · Fireware OSvia NVD
CVE-2026-81433High· 8.7
today

A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a spec…

A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a spec…

▾ TwilightWatchGuard · Fireware OSvia NVD
CVE-2026-18145High· 8.6
today

A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending…

A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending…

▾ TwilightWatchGuard · Fireware OSvia NVD
CVE-2026-86133High· 8.2
today

An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, r…

An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, r…

▾ TwilightWatchGuard · Fireware OSvia NVD
CVE-2026-86132High· 8.2
today

An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher …

An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher …

▾ TwilightWatchGuard · Fireware OSvia NVD
CVE-2026-86128High· 8.2
today

A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.

A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.

▾ TwilightWatchGuard · Fireware OSvia NVD
CVE-2026-13224High· 8.2
today

A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.

A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.

▾ TwilightWatchGuard · Fireware OSvia NVD
CVE-2026-13046High· 7.5
today

A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code …

A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code …

▾ TwilightWatchGuard · Fireware OSvia NVD

Most-changed records

Existing CVEs whose severity, score, KEV or exploitation status moved.

  • CVE-2019-9901Envoy 1.9.0 and before does not normalize HTTP URL paths37
  • CVE-2025-71348Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config45
  • CVE-2014-6407Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.42
  • CVE-2026-100310GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks51
  • CVE-2026-63431Horilla is an HR and CRM software48
  • CVE-2026-100312A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be47
  • CVE-2026-86066Horilla is an HR and CRM software44
  • CVE-2026-100303TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories42

Most-affected vendors

By CVEs published in the period.