The National Vulnerability Database (NVD) published 35 CVEs rated Critical under CVSS v3 in the 26 hours to this report. Descriptions below are quoted directly from NVD. Scores are NVD or CNA base scores; always confirm against the vendor advisory before prioritizing.
Critical CVEs (NVD)
| CVE | CVSS | Description (NVD) |
|---|---|---|
| CVE-2026-96207 | 10 | Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-94510 | 9.9 | Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-88131 | 9.8 | Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code over a network. |
| CVE-2026-77900 | 9.8 | Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network. |
| CVE-2026-84249 | 9.8 | IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function. |
| CVE-2026-75875 | 9.8 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to path traversal. |
| CVE-2026-80381 | 9.8 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute unauthorized SQL statements due to SQL injection. |
| CVE-2026-78401 | 9.8 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. |
| CVE-2026-78406 | 9.8 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data. |
| CVE-2026-107779 | 9.8 | Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers can POST GLUE_SHELL, GLUE_PYTHON, or GLUE_POWERSHELL jobs with attacker-supplied glueSource to /jobinfo/addAndStart, executing commands on the executor host or stopping and … |
| CVE-2026-107780 | 9.8 | Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single quote into format to break out of the PowerShell string and execute commands as the Skyeye service account on Windows. |
| CVE-2026-84272 | 9.8 | IBM Guardium Data Protection 12.1 and 12.2.2 are vulnerable to missing authentication in the edge-controller component. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary container images and gain control of managed edge clusters. |
| CVE-2026-104075 | 9.8 | TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript validation, to receive… |
| CVE-2026-107700 | 9.8 | dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach constructor.constructor to load child_process and run operating system commands in the Node.js process. |
| CVE-2026-107703 | 9.8 | @enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges. |
| CVE-2026-107704 | 9.8 | The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Attackers controlling the path, such as an uploaded file name, can append shell metacharacters like ';' that are executed via Ruby backticks with the Ruby process privileges. |
| CVE-2026-107699 | 9.8 | ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges. |
| CVE-2026-9209 | 9.8 | mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attackers can submit arbit… |
| CVE-2026-14992 | 9.8 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow. |
| CVE-2026-14502 | 9.8 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP authentication. |
| CVE-2026-14269 | 9.8 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote attacker could overflow the buffer and execute arbitrary code on the system. |
| CVE-2026-14991 | 9.8 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system. |
| CVE-2026-15762 | 9.8 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write. |
| CVE-2026-16340 | 9.8 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser. |
| CVE-2026-69435 | 9.6 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-107935 | 9.3 | A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system. |
| CVE-2026-84244 | 9.3 | IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute malicious script in the browser of an authenticated Guardium user. |
| CVE-2026-14990 | 9.3 | IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. |
| CVE-2026-19491 | 9.1 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication. |
| CVE-2026-16823 | 9.1 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication. |
| CVE-2026-16916 | 9.1 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary code due to a protection mechanism failure. |
| CVE-2026-104076 | 9.1 | TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing authentication vulnerability that allows remote unauthenticated attackers to read sensitive device information and modify device configuration via unprotected REST API endpoints on port 8288. Attackers can send unauthenticated GET requests to disclose network configuration, firmware details, and cloud service information,… |
| CVE-2026-107640 | 9.1 | Integrics Enswitch 3.13 through 4.4 contains an authentication bypass vulnerability in /api/json/user/password/update/ that allows unauthenticated attackers to change account passwords by omitting the reset parameter. Attackers can target accounts with no pending reset, whose empty reset_key matches the defaulted empty value, to take over administrator accounts after enumerating valid usernames. |
| CVE-2026-19218 | 9.1 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. MyRezzta allows Password Recovery Exploitation.
This issue affects MyRezzta: from 2.06.03 before 2.07.01. |
| CVE-2026-92555 | 9.1 | Insertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Panel allows Pull Data from System Resources.
This issue affects AKINSOFT WOLVOX Control Panel: from 26.02.25 before 26.02.26. |
New advisories from CERTs and vendors
Canonical (Ubuntu)
- USN-8887-3: Linux kernel vulnerabilities
- USN-8875-2: Linux kernel (NVIDIA) vulnerabilities
- USN-8903-2: Linux kernel vulnerabilities
- USN-8905-2: Linux kernel (GCP) vulnerabilities
- USN-8908-1: BlueZ vulnerabilities
- USN-8910-1: libxml2 vulnerabilities
- USN-8909-1: libde265 vulnerability
- USN-8907-1: libgit2 vulnerability
- USN-8902-1: libarchive vulnerability
- USN-8906-1: Linux kernel (IBM) vulnerabilities
- USN-8905-1: Linux kernel (GCP) vulnerabilities
- USN-8904-1: Linux kernel (Azure) vulnerabilities
- USN-8903-1: Linux kernel vulnerabilities
- USN-8888-2: Linux kernel (Azure) vulnerabilities
- USN-8887-2: Linux kernel (AWS) vulnerabilities
Canadian Centre for Cyber Security
- IBM security advisory (AV26-1022)
- Elastic security advisory (AV26-1021)
- Cisco security advisory (AV26-1020)
- HashiCorp security advisory (AV26-1019)
- Splunk security advisory (AV26-1018)
Microsoft MSRC
- CVE-2026-69581 Windows Device Association Service Elevation of Privilege Vulnerability
- CVE-2026-69270 Windows USB Audio Class driver (usbaudio.sys) Elevation of Privilege Vulnerability
- CVE-2026-77904 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability
- CVE-2026-50441 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
- CVE-2026-58528 Windows USB Audio Class Driver Information Disclosure Vulnerability
- CVE-2026-94510 Microsoft Bookings Elevation of Privilege Vulnerability
- CVE-2026-96207 Microsoft Partner Center Elevation of Privilege Vulnerability
- CVE-2026-88131 Microsoft Dataverse Remote Code Execution Vulnerability
- CVE-2026-83947 Azure Event Grid Spoofing Vulnerability
- CVE-2026-83943 Azure API Center Information Disclosure Vulnerability
- CVE-2026-77900 Azure App Service Remote Code Execution Vulnerability
- CVE-2026-69435 Azure SRE Agent Elevation of Privilege Vulnerability
