Search the CVE or product
Use lookup or product groups to find whether the advisory touches your CMS, plugin, server, package, or appliance.
Open CVE LookupFree CVE lookup
Search a CVE ID, or browse by product. Each report lists the affected version, the CVSS score, and a defensive self-check. No subscription and no exploit writeup. Search by CVE ID.
Use lookup or product groups to find whether the advisory touches your CMS, plugin, server, package, or appliance.
Open CVE LookupCheck version, exposure, enabled modules, logs, users, files, and vendor patch notes. The guides avoid payloads and unauthorized testing.
See latest guidesUse the WordPress, cPanel, or NGINX check on a site you own. Ping7 does not sell a CVE watch list.
Open the free toolsUpdated coverage
Newest Ping7 coverage from the current CVE feed. Open a card to check affected versions, exposure, patch status, and signs of compromise.
Microsoft SharePoint
SharePoint - code injection review
SharePoint CVE-2026-65660 self-checkWordPress
WordPress core - template file inclusion review
WordPress core CVE-2026-87902 self-checkAdobe Commerce / Magento
Adobe Commerce and Magento - authorization review
Magento CVE-2026-71362 self-checkAcronis Backup
Acronis Backup cPanel plugin - permission review
Acronis cPanel CVE-2026-87886 self-checkGitLab
GitLab - commits API file access review
GitLab CVE-2026-85706 self-checkAdobe Commerce / Magento
Adobe Commerce and Magento - template input review
Magento CVE-2026-75650 self-checkWordPress core - template file inclusion review
CVE-2026-87902 was added to CISA KEV on 2026-09-25. Confirm the WordPress version against the vendor advisory, update core, and review theme files plus administrator accounts on sites you own.
SharePoint - code injection review
CVE-2026-65660 was added to CISA KEV on 2026-09-25. Match the farm build to the Microsoft fix, restrict unneeded access, and review site-collection administrators and newly added solution files.
Adobe Commerce and Magento - authorization review
CVE-2026-71362 was added to CISA KEV on 2026-09-24. Apply the Adobe fix, then review administrator roles, integration tokens, and unexpected order or configuration changes.
Acronis Backup cPanel plugin - permission review
CVE-2026-87886 was added to CISA KEV on 2026-09-16. Update the Acronis cPanel/WHM plugin or Plesk extension, then review file permissions, WHM users, and backup jobs on servers you administer.
GitLab - commits API file access review
CVE-2026-85706 was added to CISA KEV on 2026-09-11. Upgrade the GitLab instance to the fixed release and review whether public projects exposed files that should have stayed private.
Adobe Commerce and Magento - template input review
CVE-2026-75650 was added to CISA KEV on 2026-09-08. Patch the store, then review CMS and email templates plus administrator accounts for changes you did not make.
PaperCut NG and MF - configuration review
CVE-2026-82078 was added to CISA KEV on 2026-08-31. PaperCut fixed it on 2026-08-27 in NG and MF 26.0.5, 25.0.13, and 24.1.10. Confirm the version on servers you own.
PaperCut NG and MF - admin access review
CVE-2026-81578 was added to CISA KEV on 2026-08-31 and is fixed in the same PaperCut NG and MF releases as CVE-2026-82078: 26.0.5, 25.0.13, and 24.1.10.
Apache Tomcat - version review
CVE-2026-34486 was added to CISA KEV on 2026-08-04. Apache says it affects only Tomcat 11.0.20, 10.1.53, and 9.0.116, fixed in 11.0.21, 10.1.54, and 9.0.117.
WordPress core - SQL injection review
CVE-2026-60137 was added to CISA KEV on 2026-07-21. WordPress fixed it on 2026-07-17 in 7.0.2, 6.9.5, and 6.8.6. Confirm the core version, then review administrator accounts and unexpected PHP files on sites you own.
WordPress core - REST route review
CVE-2026-63030 was added to CISA KEV on 2026-07-21 and is fixed in WordPress 7.0.2 and 6.9.5. WordPress says the 6.8 line is not affected by this one. Confirm the core version on sites you own.
W3 Total Cache - file read exposure risk
CVE-2026-9282 affects W3 Total Cache <= 2.9.4. Preserve logs, confirm the deployed version, review manual minify settings, cache files, sensitive file access, and web logs, and keep public access restricted until patching and integrity checks are complete.
Genolve AI media plugin - settings authorization gap
CVE-2026-1359 affects Genolve AI image AI video generation vendor advisory. Preserve logs, confirm the deployed version, review plugin options, administrator changes, generated media, and access logs, and keep public access restricted until patching and integrity checks are complete.
Code Engine - shortcode code execution risk
CVE-2025-6784 affects Code Engine <= 0.3.5. Preserve logs, confirm the deployed version, review shortcodes, post content, administrator edits, and plugin files, and keep public access restricted until patching and integrity checks are complete.
Essential Addons for Elementor - account takeover review
CVE-2026-15155 affects Essential Addons for Elementor <= 6.6.10. Preserve logs, confirm the deployed version, review login/register flows, email changes, reset activity, and admin sessions, and keep public access restricted until patching and integrity checks are complete.
WP CTA - SQL injection exposure risk
CVE-2026-4661 affects WP CTA - Sticky CTA Builder <= 1.7.4. Preserve logs, confirm the deployed version, review CTA forms, database errors, query logs, and lead data access, and keep public access restricted until patching and integrity checks are complete.
SureCart - account takeover and role review
CVE-2026-7655 affects SureCart <= 4.2.3. Preserve logs, confirm the deployed version, review customer accounts, administrator users, orders, webhooks, and login history, and keep public access restricted until patching and integrity checks are complete.
Simple JWT Login - authentication bypass review
CVE-2026-14262 affects Simple JWT Login <= 3.6.6. Preserve logs, confirm the deployed version, review JWT settings, REST login events, new sessions, and administrator roles, and keep public access restricted until patching and integrity checks are complete.
Booking Package - booking-form SQL injection risk
CVE-2026-15335 affects Booking Package <= 1.7.20. Preserve logs, confirm the deployed version, review booking forms, database errors, customer records, and plugin logs, and keep public access restricted until patching and integrity checks are complete.
Swiss Toolkit For WP - file upload exposure risk
CVE-2026-2354 affects Swiss Toolkit For WP <= 1.4.2. Preserve logs, confirm the deployed version, review uploads, plugin extension files, executable files, and recent file changes, and keep public access restricted until patching and integrity checks are complete.
WP Ultimate CSV Importer - import workflow code execution risk
CVE-2026-13353 affects WP Ultimate CSV Importer <= 8.0.1. Preserve logs, confirm the deployed version, review CSV imports, add-on installs, administrator activity, and modified files, and keep public access restricted until patching and integrity checks are complete.
LA-Studio Element Kit for Elementor - template file inclusion risk
CVE-2026-15338 affects LA-Studio Element Kit for Elementor <= 1.6.1. Preserve logs, confirm the deployed version, review Elementor templates, theme files, PHP errors, and page-builder edits, and keep public access restricted until patching and integrity checks are complete.
WP Grid Builder - privilege escalation review
CVE-2026-13756 affects WP Grid Builder <= 2.3.3. Preserve logs, confirm the deployed version, review role changes, grid settings, user meta changes, and admin sessions, and keep public access restricted until patching and integrity checks are complete.
CorvusPay WooCommerce Gateway - stored script review
CVE-2026-6939 affects CorvusPay WooCommerce Payment Gateway <= 2.7.4. Preserve logs, confirm the deployed version, review payment callbacks, order notes, checkout fields, and WooCommerce logs, and keep public access restricted until patching and integrity checks are complete.
Look up an older CVE or use the product directory below. This page no longer repeats the full catalog.
Blocksy Companion Pro - unauthenticated code execution risk
CVE-2026-57624 affects Blocksy Companion Pro <= 2.1.46. Site owners should patch or disable the component, preserve logs, review plugin files, admin users, and server-side error logs, and clear caches only after evidence is saved.
Adobe Campaign Classic - incorrect authorization code execution risk
CVE-2026-48286 affects Adobe Campaign Classic <= 7.4.3 build 9396. Operators should confirm whether the platform is reachable, patch to the fixed version, review operator roles, workflow logs, and campaign job activity, and rotate secrets if execution or workflow integrity is uncertain.
Page Builder CK - unauthenticated file upload risk
CVE-2026-56290 affects the Page Builder CK Joomla extension. Joomla owners should patch the extension, restrict administrative access, preserve logs, and review uploaded files and extension state.
Kestra - authentication boundary risk
CVE-2026-53576 affects Kestra. Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public i... Patch the affected deployment and review workflow and admin logs.
Budibase - authentication boundary risk
CVE-2026-54350 affects Budibase. Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with... Patch the affected deployment and review workflow and admin logs.
Apache Kvrocks - security boundary risk
CVE-2026-46752 affects Apache Kvrocks. Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. Patch the affected deployment and review component presence.
Daan.Dev OMGF Pro - Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2026-57700 affects Daan.Dev OMGF Pro vendor-fixed release. Site owners should patch the component, preserve logs, and review files and uploads before closing the issue.
GeoVision GV-I/O Box 4E - DVRSearch stack overflow risk
CVE-2026-12485 affects GeoVision GV-I/O Box 4E devices covered by the June 2026 Talos advisories. Device owners should isolate management access, apply vendor firmware guidance, and review network or relay configuration changes.
GeoVision GV-I/O Box 4E - network configuration stack overflow risk
CVE-2026-12846 affects GeoVision GV-I/O Box 4E devices covered by the June 2026 Talos advisories. Device owners should isolate management access, apply vendor firmware guidance, and review network or relay configuration changes.
GeoVision GV-I/O Box 4E - gateway field stack overflow risk
CVE-2026-12847 affects GeoVision GV-I/O Box 4E devices covered by the June 2026 Talos advisories. Device owners should isolate management access, apply vendor firmware guidance, and review network or relay configuration changes.
GeoVision GV-I/O Box 4E - DNS field stack overflow risk
CVE-2026-12848 affects GeoVision GV-I/O Box 4E devices covered by the June 2026 Talos advisories. Device owners should isolate management access, apply vendor firmware guidance, and review network or relay configuration changes.
ProxySQL - MySQL frontend memory corruption risk
CVE-2026-48772 affects ProxySQL 2.0.0 through 3.0.8. Patch to 3.0.9 or newer, restrict exposed listeners, and review ProxySQL listeners, crashes, restarts, and frontend access.
Joomla SP Page Builder - unauthenticated file upload
CVE-2026-48908 affects Joomla SP Page Builder vendor advisory. Check whether the extension is installed, remove abandoned copies, and review uploads, executable files, and public builder routes.
Joomla iCagenda - file attachment upload risk
CVE-2026-48939 affects Joomla iCagenda vendor advisory. Check whether the extension is installed, remove abandoned copies, and review event attachments, uploads, and executable files.
mcp-pinot - unauthenticated MCP server exposure
CVE-2026-49257 affects mcp-pinot through 3.0.1. Review Pinot credentials, MCP access logs, and table/config changes, then apply the vendor fix or remove the risky exposure until patched.
WordPress and WooCommerce Scraper - unauthenticated arbitrary file upload
CVE-2025-69129 affects WordPress & WooCommerce Scraper Plugin, Import Data from Any Site through 1.0.7. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.
ACPT Pro - remote code execution
CVE-2026-25470 affects ACPT Pro - Custom Post Types Plugin for WordPress through 2.0.47. Confirm the installed version, patch or disable the component, and review changed files, cron jobs, users, and web server logs before closing the incident.
Android MmsSmsProvider - permission check information disclosure
CVE-2026-28587 affects Android MmsSmsProvider permission handling. Managed fleets should apply the Android security bulletin update and review devices that process sensitive messaging data.
GeekyBot - unauthenticated arbitrary file upload
CVE-2026-40772 affects GeekyBot through 1.2.2. WordPress sites should patch or disable the component, then review upload directories, new PHP files, and web access logs before closing the incident.
Easy Invoice - unauthenticated remote code execution
CVE-2026-48836 affects Easy Invoice through 2.1.19. WordPress sites should patch or disable the component, then review changed files, cron jobs, users, and web server logs before closing the incident.
WooCommerce PDF Invoice Builder - remote code inclusion risk
CVE-2026-52704 affects WooCommerce PDF Invoice Builder through 2.0.8. Stores should disable or patch the plugin, review generated invoice files and templates, and check administrator activity before reopening payments.
vm2 - sandbox escape via host TypeError exposure
CVE-2026-47131 affects vm2 before 3.11.4. Services that run untrusted JavaScript should upgrade, isolate sandbox workers, and review logs for unexpected outbound access or worker failures.
vm2 - NodeVM require guard bypass
CVE-2026-47137 affects vm2 before 3.11.4. Services that run untrusted JavaScript should upgrade, isolate sandbox workers, and review logs for unexpected outbound access or worker failures.
vm2 - dangerous builtin denylist gap
CVE-2026-47140 affects vm2 before 3.11.4. Services that run untrusted JavaScript should upgrade, isolate sandbox workers, and review logs for unexpected outbound access or worker failures.
Zegen theme - subscriber file upload risk
CVE-2026-27419 affects Zegen theme <= 1.1.9. Site owners should patch or disable the component, preserve logs, review uploads, theme files, and subscriber activity, and clear caches only after evidence is saved.
Paid Videochat Turnkey Site - performer file deletion risk
CVE-2026-57331 affects Paid Videochat Turnkey Site <= 7.4.8. Site owners should patch the component, preserve logs, and review files and performer accounts before closing the issue.
Gitea act_runner - Docker backend container hardening bypass
CVE-2026-58053 affects Gitea act_runner deployments that use the Docker backend through act 0.262.0. Owners should restrict who can run workflows, review Docker runner configuration, isolate runners from production hosts, and apply vendor hardening guidance.
OpenProject - security boundary risk
CVE-2026-46386 affects OpenProject Docker deployments that inherited an unsafe default application secret configuration. Patch the affected deployment and review workflow and admin logs.
Booster for WooCommerce - Customer Arbitrary File Upload
CVE-2026-56027 affects Booster for WooCommerce <= 8.0.1. Site owners should patch the component, preserve logs, and review files and uploads before closing the issue.
Quform - Subscriber Arbitrary File Upload
CVE-2026-56058 affects Quform <= 2.23.0. Site owners should patch the component, preserve logs, and review files and uploads before closing the issue.
Travel Booking - Subscriber Arbitrary File Upload
CVE-2026-56059 affects Travel Booking <= 2.2.5. Site owners should patch the component, preserve logs, and review files and uploads before closing the issue.
Widget Options - Contributor Remote Code Execution (remote code execution)
CVE-2026-54823 affects Widget Options <= 4.2.3. Site owners should patch the component, preserve logs, and review logs and users before closing the issue.
Appsmith - bundled Caddy admin API takeover risk
CVE-2026-55454 affects Appsmith before 2.1. Review Caddy configuration changes, SSRF exposure, and low-privilege user activity after upgrading.
Flowise - Custom MCP Server command injection risk
CVE-2026-56274 affects Flowise before 3.1.2 through Custom MCP Server validation bypasses. Patch, restrict Flowise accounts and API keys, and review chatflow and MCP tool changes.
Grip theme - subscriber arbitrary file upload
CVE-2024-52488 affects Grip through 1.0.9. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.
PT Luxa Addons - subscriber arbitrary file upload
CVE-2025-60218 affects PT Luxa Addons through 1.2.2. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.
Restaurt theme - subscriber arbitrary file upload
CVE-2026-22327 affects Restaurt through 1.0.4. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.
WishList Member X - subscriber arbitrary file upload
CVE-2026-25446 affects WishList Member X through 3.29.0. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.
Unlimited Elements for Elementor Premium - contributor arbitrary file upload
CVE-2026-27041 affects Unlimited Elements for Elementor (Premium) through 2.0.6. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.
Webenvo theme - subscriber arbitrary file upload
CVE-2026-39589 affects Webenvo through 0.0.6. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.
Restaurant Zone theme - subscriber arbitrary file upload
CVE-2026-40746 affects Restaurant Zone through 0.7.8. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.
Ecommerce Zone theme - subscriber arbitrary file upload
CVE-2026-40747 affects Ecommerce Zone through 0.9.7. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.
Kids Gift Shop theme - subscriber arbitrary file upload
CVE-2026-40748 affects Kids Gift Shop through 0.5.4. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.
Charity Zone theme - subscriber arbitrary file upload
CVE-2026-40749 affects Charity Zone through 1.1.1. Confirm the installed version, patch or disable the component, and review upload directories, new PHP files, and web access logs before closing the incident.
Blocksy Companion Pro - contributor remote code execution
CVE-2026-40783 affects Blocksy Companion Pro through 2.1.37. Confirm the installed version, patch or disable the component, and review changed files, cron jobs, users, and web server logs before closing the incident.
MySQL Shell for VS Code - June 2026 Oracle CPU critical issue
CVE-2026-46850 affects MySQL Shell for VS Code 2026.2.0+9.6.1. Database teams should patch developer tooling and review saved connection profiles and extension access.
WordPress Kids Online Store theme - dangerous file upload
CVE-2026-40750 affects the WordPress Kids Online Store theme through 0.8.9. Site owners should patch or replace the theme, block script execution from uploads, and review recent files and admin users.
RD Station - Remote code execution
CVE-2026-49774 affects RD Station through 5.6.0. Confirm the installed version, patch or disable the plugin, and review changed files, cron jobs, users, and web server logs before closing the incident.
Appsmith - bundled supervisord XML-RPC exposure
CVE-2026-50189 affects Appsmith before 2.1. Review supervisord exposure, administrator activity, container process history, and environment access.
n8n - Source Control Pull SQL injection
CVE-2026-44792 affects n8n instances using PostgreSQL and Source Control. Patch and review connected repositories, admin pulls, and Data Table import activity.
PaperCut NG and MF - admin access review
CVE-2026-81578 was added to CISA KEV on 2026-08-31 and is fixed in the same PaperCut NG and MF releases as CVE-2026-82078: 26.0.5, 25.0.13, and 24.1.10.
Acronis Backup cPanel plugin - permission review
CVE-2026-87886 was added to CISA KEV on 2026-09-16. Update the Acronis cPanel/WHM plugin or Plesk extension, then review file permissions, WHM users, and backup jobs on servers you administer.
Genolve AI media plugin - settings authorization gap
CVE-2026-1359 affects Genolve AI image AI video generation vendor advisory. Preserve logs, confirm the deployed version, review plugin options, administrator changes, generated media, and access logs, and keep public access restricted until patching and integrity checks are complete.
Code Engine - shortcode code execution risk
CVE-2025-6784 affects Code Engine <= 0.3.5. Preserve logs, confirm the deployed version, review shortcodes, post content, administrator edits, and plugin files, and keep public access restricted until patching and integrity checks are complete.
Essential Addons for Elementor - account takeover review
CVE-2026-15155 affects Essential Addons for Elementor <= 6.6.10. Preserve logs, confirm the deployed version, review login/register flows, email changes, reset activity, and admin sessions, and keep public access restricted until patching and integrity checks are complete.
Simple JWT Login - authentication bypass review
CVE-2026-14262 affects Simple JWT Login <= 3.6.6. Preserve logs, confirm the deployed version, review JWT settings, REST login events, new sessions, and administrator roles, and keep public access restricted until patching and integrity checks are complete.
Swiss Toolkit For WP - file upload exposure risk
CVE-2026-2354 affects Swiss Toolkit For WP <= 1.4.2. Preserve logs, confirm the deployed version, review uploads, plugin extension files, executable files, and recent file changes, and keep public access restricted until patching and integrity checks are complete.
WP Ultimate CSV Importer - import workflow code execution risk
CVE-2026-13353 affects WP Ultimate CSV Importer <= 8.0.1. Preserve logs, confirm the deployed version, review CSV imports, add-on installs, administrator activity, and modified files, and keep public access restricted until patching and integrity checks are complete.
WP Grid Builder - privilege escalation review
CVE-2026-13756 affects WP Grid Builder <= 2.3.3. Preserve logs, confirm the deployed version, review role changes, grid settings, user meta changes, and admin sessions, and keep public access restricted until patching and integrity checks are complete.
FrontAccounting - attachment upload path traversal
CVE-2026-40521 affects FrontAccounting before 2.4.20. Owners should patch supported deployments, remove unsupported public exposure, preserve logs, and review attachment uploads and web-root file changes.
Eagle Booking - Unauthenticated Cross Site Request Forgery (CSRF)
CVE-2025-68052 affects Eagle Booking <= 1.3.4.3. Site owners should patch the component, preserve logs, and review users and access before closing the issue.
Fusion Builder - Contributor Privilege Escalation
CVE-2026-56008 affects Fusion Builder <= 3.15.4. Site owners should patch the component, preserve logs, and review users and access before closing the issue.
Abandoned Cart Pro for WooCommerce - Subscriber Privilege Escalation
CVE-2026-56010 affects Abandoned Cart Pro for WooCommerce <= 10.4.0. Site owners should patch the component, preserve logs, and review users and access before closing the issue.
Frisbii Pay - Contributor Privilege Escalation
CVE-2026-56038 affects Frisbii Pay <= 1.8.2. Site owners should patch the component, preserve logs, and review users and access before closing the issue.
RealHomes - Subscriber PHP Object Injection
CVE-2026-56055 affects RealHomes <= 4.5.3. Site owners should patch the component, preserve logs, and review logs and users before closing the issue.
Pagekit CMS - privilege escalation risk
CVE-2026-57518 affects Pagekit CMS. Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate privileges by assigning arbitrary custom roles to themselves due to mi... Patch the affected deployment and review web and app logs.
Paid Memberships Pro - Add Member From Admin - Unauthenticated Cross Site Request Forgery (CSRF)
CVE-2026-57659 affects Paid Memberships Pro - Add Member From Admin <= 0.7.2. Site owners should patch the component, preserve logs, and review users and access before closing the issue.
EventPrime - Subscriber PHP Object Injection
CVE-2026-56053 affects EventPrime <= 4.3.4.1. Site owners should patch the component, preserve logs, and review logs and users before closing the issue.
Rapid7 InsightConnect Sed Plugin - command execution risk in Linux workflow action
CVE-2026-9155 affects the Rapid7 InsightConnect Sed Plugin on Linux. Review workflow runs, connector permissions, input sources, generated artifacts, and runner logs before re-enabling affected automation.
Unraid - FileUpload command execution risk
CVE-2026-9772 affects Unraid web administration paths where authenticated access can reach command execution risk. Restrict admin access, patch, and review plugin, upload, and process activity.
Unraid - ToggleState command execution risk
CVE-2026-9773 affects Unraid web administration paths where authenticated access can reach command execution risk. Restrict admin access, patch, and review plugin, upload, and process activity.
Jenkins Script Security Plugin - sandbox constructor bypass
CVE-2026-57280 affects a Jenkins plugin covered by the 2026-06-24 advisory. Patch the plugin, review permissions, and preserve controller logs before cleanup.
WordPress core - template file inclusion review
CVE-2026-87902 was added to CISA KEV on 2026-09-25. Confirm the WordPress version against the vendor advisory, update core, and review theme files plus administrator accounts on sites you own.
SharePoint - code injection review
CVE-2026-65660 was added to CISA KEV on 2026-09-25. Match the farm build to the Microsoft fix, restrict unneeded access, and review site-collection administrators and newly added solution files.
Adobe Commerce and Magento - authorization review
CVE-2026-71362 was added to CISA KEV on 2026-09-24. Apply the Adobe fix, then review administrator roles, integration tokens, and unexpected order or configuration changes.
Acronis Backup cPanel plugin - permission review
CVE-2026-87886 was added to CISA KEV on 2026-09-16. Update the Acronis cPanel/WHM plugin or Plesk extension, then review file permissions, WHM users, and backup jobs on servers you administer.
GitLab - commits API file access review
CVE-2026-85706 was added to CISA KEV on 2026-09-11. Upgrade the GitLab instance to the fixed release and review whether public projects exposed files that should have stayed private.
Adobe Commerce and Magento - template input review
CVE-2026-75650 was added to CISA KEV on 2026-09-08. Patch the store, then review CMS and email templates plus administrator accounts for changes you did not make.
PaperCut NG and MF - configuration review
CVE-2026-82078 was added to CISA KEV on 2026-08-31. PaperCut fixed it on 2026-08-27 in NG and MF 26.0.5, 25.0.13, and 24.1.10. Confirm the version on servers you own.
PaperCut NG and MF - admin access review
CVE-2026-81578 was added to CISA KEV on 2026-08-31 and is fixed in the same PaperCut NG and MF releases as CVE-2026-82078: 26.0.5, 25.0.13, and 24.1.10.
Apache Tomcat - version review
CVE-2026-34486 was added to CISA KEV on 2026-08-04. Apache says it affects only Tomcat 11.0.20, 10.1.53, and 9.0.116, fixed in 11.0.21, 10.1.54, and 9.0.117.
WordPress core - SQL injection review
CVE-2026-60137 was added to CISA KEV on 2026-07-21. WordPress fixed it on 2026-07-17 in 7.0.2, 6.9.5, and 6.8.6. Confirm the core version, then review administrator accounts and unexpected PHP files on sites you own.
WordPress core - REST route review
CVE-2026-63030 was added to CISA KEV on 2026-07-21 and is fixed in WordPress 7.0.2 and 6.9.5. WordPress says the 6.8 line is not affected by this one. Confirm the core version on sites you own.
Cisco Catalyst SD-WAN Manager - authenticated arbitrary file write
CVE-2026-20262 affects Cisco Catalyst SD-WAN Manager web UI upload handling. The reported path requires valid low-privilege credentials but can create or overwrite files, so exposed management planes need patching and account review.
LiteSpeed cPanel Plugin - shared hosting privilege escalation risk
CVE-2026-54420 affects LiteSpeed cPanel user-end plugin deployments before 2.4.8, including bundled WHM Plugin deployments before the fixed 5.3.2.1 line. Shared hosts using CloudLinux/CageFS should patch and review cPanel logs because the vendor reported active exploitation.
Ivanti Sentry - unauthenticated root-level command injection
CVE-2026-10520 affects Ivanti Sentry and was added to CISA KEV on 2026-06-11. Confirm version state, restrict management access, patch, and review appliance logs and unexpected accounts.
Check Point - deprecated IKEv1 VPN authentication bypass
CVE-2026-50751 affects Check Point Remote Access VPN and Mobile Access deployments that still accept deprecated IKEv1. Check Point reported exploitation in the wild; operators should patch, disable or restrict IKEv1, and review VPN logs from 2026-05-07 onward.
Open XDMoD - unauthenticated remote code execution
CVE-2026-45777 affects Open XDMoD 9.5.0 through 11.0.2. HPC portals should upgrade to 11.0.3 or newer, restrict web access, and review web-server process activity and application logs.
Kirki Page Builder — Unauthenticated Admin Account Takeover via Password Reset
Kirki 6.0.0–6.0.6 password reset endpoint sends reset link to attacker-supplied email instead of account owner. One unauthenticated request hijacks any admin. 500K+ installs, Wordfence blocking 222+ attacks/day.
Nx Console VS Code Extension — Supply Chain Attack (Actively Exploited)
Malicious Nx Console version 18.95.0 was published to VS Code Marketplace for ~18 minutes and OpenVSX for ~36 minutes on May 19, 2026. The compromised extension contained embedded malicious code (CWE-506) that executed at activation. Auto-update users may have installed it. CISA has added this to the Known Exploited Vulnerabilities catalog.
cPanel/WHM Pre-Auth CRLF Injection → Root Access
Pre-authentication CRLF injection in cPanel & WHM session handling leading to root access. 44,000 IPs compromised, 7,135 hit by .sorry ransomware. Persistent Mr_Rot13 Filemanager backdoor survives the patch. Second emergency TSR on May 8.
Same checks, no invoice
Ping7 keeps this page as the industry desk. Income comes from ads on the free tools, not from a CVE subscription.
Sources verified against NVD, CISA KEV, Shadowserver, Censys, F5, Rapid7, watchTowr, cPanel, WordPress plugin advisories, and FreePBX security advisories. Last updated 2026-09-25.