The National Vulnerability Database (NVD) published 14 CVEs rated Critical under CVSS v3 in the 26 hours to this report. Descriptions below are quoted directly from NVD. Scores are NVD or CNA base scores; always confirm against the vendor advisory before prioritizing.
Critical CVEs (NVD)
| CVE | CVSS | Description (NVD) |
|---|---|---|
| CVE-2026-104803 | 9.8 | The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability exists because the `login` function's social-login flow performs no nonce validation, no OAuth state verification, and no per-visitor namespace isolation in the session store… |
| CVE-2026-103889 | 9.8 | The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template with PHP execution e… |
| CVE-2026-94589 | 9.8 | The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload directory and a sa… |
| CVE-2026-104732 | 9.8 | The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed `user_id`; compounding this, an error… |
| CVE-2026-108107 | 9.8 | PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection. |
| CVE-2026-86405 | 9.8 | Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module allows Signature Spoofing by Improper Validation.
This issue affects PrestaShop Virtual POS Module: from 26.8.1 before 26.9.1. |
| CVE-2026-85531 | 9.8 | Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows Signature Spoofing by Improper Validation.
This issue affects OpenCart Virtual POS Module: from 26.8.2 before 26.9.1. |
| CVE-2026-104801 | 9.1 | The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp… |
| CVE-2026-97670 | 9.1 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value (via the notification email_message [field] placeholder and the {action_hook,…} dynamic-data token; the 3.16.1 trust… |
| CVE-2026-107645 | 9.1 | The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-registration nonce check (via add_filter('dokan_register_nonce_check', '__return_false')) and then trusting an attacker-supplied $_POST['role'] value when invoking wc_create_new_customer() and wc_set… |
| CVE-2026-108109 | 9.1 | PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account. |
| CVE-2026-82344 | 8.1 | IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size reassembly buffer, potentially resulting in denial of service or arbitrary code execution on the affected system. |
| CVE-2026-82335 | 8.1 | IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based buffer overflow in the MongoDB protocol parser. A remote attacker could send a specially crafted MongoDB SCRAM username containing an excessive length and cause memory corruption, potentially resulting in denial of service or arbitrary code execution. |
| CVE-2026-82334 | 8.1 | IBM Guardium Data Protection 12.0, 12.1, 12.2 is vulnerable to a heap-based out-of-bounds read in the TDS7 LOGIN7 protocol parser. A remote attacker could send a specially crafted TDS LOGIN7 packet containing invalid offset or length values, potentially causing information disclosure or denial of service. |
New advisories from CERTs and vendors
Debian
Canadian Centre for Cyber Security
- SmarterTools security advisory (AV26-1026)
- MongoDB security advisory (AV26-1024)
- HPE security advisory (AV26-1025)
- Citrix security advisory (AV26-1023)
Microsoft MSRC
- CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability
- CVE-2026-59127 Windows Installer Elevation of Privilege Vulnerability
- CVE-2026-72987 Windows DNS Remote Code Execution Vulnerability
- CVE-2026-69598 Windows iSCSI Remote Code Execution Vulnerability
- CVE-2026-69433 Windows Error Reporting Elevation of Privilege Vulnerability
- CVE-2026-69566 Windows NTFS Remote Code Execution Vulnerability
- CVE-2026-69693 Windows Device Association Broker Service Elevation of Privilege Vulnerability
- CVE-2026-69732 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
- CVE-2026-69337 Windows Registry Elevation of Privilege Vulnerability
- CVE-2026-69281 Windows License Manager Elevation of Privilege Vulnerability
- CVE-2026-68878 Windows Fast FAT Driver Elevation of Privilege Vulnerability
- CVE-2026-62876 Windows Win32k Elevation of Privilege Vulnerability
- CVE-2026-72979 Windows DHCP Server Remote Code Execution Vulnerability
- CVE-2026-69385 Windows TCP/IP Elevation of Privilege Vulnerability
- CVE-2026-72982 Windows Netlogon Remote Code Execution Vulnerability
- CVE-2026-69571 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability
- CVE-2026-69688 Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability
- CVE-2026-69277 Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability
- CVE-2026-73006 DirectWrite Remote Code Execution Vulnerability
- CVE-2026-69301 Windows Win32k Elevation of Privilege Vulnerability
- CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
- CVE-2026-69322 Microsoft Windows Search Component Elevation of Privilege Vulnerability
- CVE-2026-69324 Windows Performance Monitor Elevation of Privilege Vulnerability
- CVE-2026-62747 Windows Device Association Service Elevation of Privilege Vulnerability
- CVE-2026-69340 Windows NTFS Elevation of Privilege Vulnerability
Plus 8 more from Microsoft MSRC; see the source link below.
Canonical (Ubuntu)
CERT-FR
- Vulnérabilité dans les produits Tenable (09 octobre 2026)
- Multiples vulnérabilités dans les produits Nextcloud (09 octobre 2026)
- Multiples vulnérabilités dans le noyau Linux d'Ubuntu (09 octobre 2026)
- Multiples vulnérabilités dans les produits IBM (09 octobre 2026)
- Vulnérabilité dans Citrix NetScaler ADC et Gateway (09 octobre 2026)
- Multiples vulnérabilités dans le noyau Linux de Debian LTS (09 octobre 2026)
- Multiples vulnérabilités dans le noyau Linux de Red Hat (09 octobre 2026)
- Multiples vulnérabilités dans Apache Struts (09 octobre 2026)
- Multiples vulnérabilités dans le noyau Linux de SUSE (09 octobre 2026)
