Skip to content

CVE Monitor

Today's Vulnerabilities, In Plain English

A CVE is a public ID assigned to one specific flaw in one specific piece of software — a serial number for a broken lock. Somebody found the flaw, the vendor confirmed it, and the ID lets everyone talk about the same problem without confusion.

Thousands are published every month, and almost none of them are about you. So this page sorts them by the kind of system a business owns: the browser on the front desk, the firewall in the closet, the box your backups land on. Find your shelf, skim it, and move on.

100 tracked right now58 critical42 high0 confirmed under attack6 with a LayerLogix guide

Records come from the NIST National Vulnerability Database and the CISA Known Exploited Vulnerabilities catalog. We write the explanation; we never write the facts. Every ID on this page is validated against the official CVE format and every link is rebuilt from that ID, so a row can only ever point at NVD's own record — check any line against the source yourself. Collection is automated and runs twice a day. Last refreshed Sep 21, 2026, 1:15 PM Central.

Business Software (2)

Accounting, CRM, HR, booking and other day-to-day business applications. If you recognise a name here, ask the vendor which version you are on.

  • CVE-2023-54399CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18

    Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categori…

  • CVE-2026-75878CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 18

    IBM Sterling File Gateway could allow a remote attacker to bypass authentication and obtain a fully authenticated sessi…

Websites & WordPress (16)

Your public website, its theme, and every plugin bolted onto it. Plugin flaws are the most common way a small-business site gets defaced.

  • CVE-2026-82187CVSS 9.8/10CVSS 9.8, critical severity.Act on thisPublished Sep 21

    The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded fil…

  • CVE-2026-84434CVSS 9.8/10CVSS 9.8, critical severity.Act on thisPublished Sep 18

    The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1…

  • CVE-2026-86591CVSS 9.8/10CVSS 9.8, critical severity.Act on thisPublished Sep 19

    The Botiga Pro WordPress plugin before 1.6.5 does not perform any authorisation checks on one of its REST routes, allow…

  • CVE-2026-88856CVSS 9.4/10CVSS 9.4, critical severity.Act on thisPublished Sep 20

    Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension…

  • CVE-2026-88857CVSS 9.4/10CVSS 9.4, critical severity.Act on thisPublished Sep 20

    Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaSoft Joomla Gallery extension…

  • CVE-2026-88854CVSS 9.3/10CVSS 9.3, critical severity.Act on thisPublished Sep 20

    Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla 6.2.7…

  • CVE-2026-89274CVSS 9.1/10CVSS 9.1, critical severity.Act on thisPublished Sep 18

    The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and incl…

  • CVE-2026-92229CVSS 9.1/10CVSS 9.1, critical severity.Act on thisPublished Sep 18

    The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbit…

  • CVE-2026-4327CVSS 8.8/10CVSS 8.8, high severity.Act on thisPublished Sep 19

    The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.…

  • CVE-2026-85680CVSS 8.8/10CVSS 8.8, high severity.Act on thisPublished Sep 19

    The Ultimate Member WordPress plugin before 2.13.1 does not escape a value derived from user supplied profile names bef…

  • CVE-2026-88824CVSS 8.8/10CVSS 8.8, high severity.Act on thisPublished Sep 19

    The Master Blocks WordPress plugin before 1.5.0 does not have authorisation on one of its REST routes, allowing unauthe…

  • CVE-2026-92807CVSS 8.8/10CVSS 8.8, high severity.Act on thisPublished Sep 18

    The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions…

  • CVE-2026-93031CVSS 8.8/10CVSS 8.8, high severity.Act on thisPublished Sep 18

    The WP Cloud Plugins Use-your-Drive, Out-of-the-Box, Share-one-Drive, and Lets-Box plugins for WordPress are vulnerable…

  • CVE-2026-88855CVSS 8.6/10CVSS 8.6, high severity.Act on thisPublished Sep 20

    Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joomla Gallery extension for Joom…

  • CVE-2026-88926CVSS 8.6/10CVSS 8.6, high severity.Act on thisPublished Sep 19

    The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape some of i…

  • CVE-2026-87067CVSS 8.5/10CVSS 8.5, high severity.Act on thisPublished Sep 20

    The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deser…

Network Gear, Firewalls & Cameras (8)

Routers, firewalls, VPN boxes, Wi-Fi access points and IP cameras. A flaw here is not "someone reads a file" — it is "someone is inside the network".

Servers & Operating Systems (2)

Linux, Windows Server and the virtualisation hosts your systems run on. Usually your IT provider’s job, but worth knowing so you can ask whether it is handled.

Security & Monitoring Tools (17)

The products meant to watch everything else — worth patching first when they are the thing that slipped.

  • CVE-2026-80442CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCer…

  • CVE-2026-84064CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to…

  • CVE-2026-84075CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authenti…

  • CVE-2026-84078CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet.

  • CVE-2026-61550CVSS 9.8/10CVSS 9.8, critical severity.Handled for youPublished Sep 18

    Icinga 2 is an open source monitoring system.

  • CVE-2026-80441CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the g…

  • CVE-2026-81657CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system…

  • CVE-2026-82340CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled ref…

  • CVE-2026-82967CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attac…

  • CVE-2026-84082CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutr…

  • CVE-2026-82832CVSS 9.6/10CVSS 9.6, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper…

  • CVE-2026-84073CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to…

  • CVE-2026-84031CVSS 9.0/10CVSS 9.0, critical severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper…

  • CVE-2026-84070CVSS 8.9/10CVSS 8.9, high severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper…

  • CVE-2026-84074CVSS 8.9/10CVSS 8.9, high severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper…

  • CVE-2026-84106CVSS 8.9/10CVSS 8.9, high severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper…

  • CVE-2026-84084CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 18

    IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site req…

Everything below this line sits inside other software rather than on anyone's desk — code libraries, databases, hosting plumbing. You do not install these and you cannot patch them directly. They reach you as an update from whoever built or hosts your software. They are listed because a monitor that hides things is not a monitor.

That used to make this the part you could skip. It is not any more — this is also the supply chain an AI coding assistant pulls into an application it writes for you. The panel below names the packages involved.

What your AI builds with

These are the packages we watch because an AI coding assistant reaches for them on its own. Ask a model for a small web service and an HTTP client, a web framework and a few utilities arrive with it. Ask for an AI feature and a model SDK and somewhere to keep embeddings arrive with that. If a generated application is running in your business, this is a fair description of what it is made of.

This is the watch-list itself, separate from today's advisories. A package appearing here does not mean it has a vulnerability. When one of them is actually the subject of an advisory, it shows up in the list below with its name on the row.

What an assistant writes into your app

Asked for an ordinary service, a model reaches for these without being told to.

What you build AI features with

The pieces that show up once the application itself has to call a model.

Nothing in this panel is being reported as vulnerable. It is the list of packages we watch. Today's actual advisories are the entries below, and any that involve one of these packages carry its name on the row.

Developer & Hosting Components (10)

Code libraries, databases and hosting plumbing. These reach you as an update from whoever built your software — you do not install them yourself.

  • CVE-2026-61781CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesOn our AI build watch-list, postgres.postgresPublished Sep 18

    pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID.

  • CVE-2026-93985CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 19

    OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template…

  • CVE-2025-66455CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesOn our AI build watch-list, lmdeploy.lmdeployPublished Sep 18

    LMDeploy is a toolkit for compressing, deploying, and serving large language models.

  • CVE-2026-58264CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 18

    FluidSynth is a software synthesizer based on the SoundFont 2 specifications.

  • CVE-2026-78030CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 19

    DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM.

  • CVE-2026-85751CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesOn our AI build watch-list, docker.dockerPublished Sep 21

    Mailu is a mail server distributed as a set of Docker images.

  • CVE-2026-93762CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesOn our AI build watch-list, mongoid.mongoidPublished Sep 18

    Mongoid contains an unsafe reflection weakness in the query path used for embedded documents.

  • CVE-2026-93839CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesOn our AI build watch-list, lightllm.lightllmPublished Sep 18

    LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allo…

  • CVE-2026-53940CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21

    Conda is a system-level binary package and environment manager that runs on major operating systems and platforms.

  • CVE-2026-16651CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21

    temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose content…

Everything Else (45)

Published this cycle, but not a clean fit for anything a business runs. Listed rather than dropped.

  • CVE-2026-94097CVSS 10.0/10CVSS 10.0, critical severity.Background noise for most businessesPublished Sep 20

    A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246.

  • CVE-2026-94095CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 20

    A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246.

  • CVE-2026-94096CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 20

    A vulnerability was found in Netcore NBR200V2 1.3.241127.071246.

  • CVE-2026-94099CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 20

    A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246.

  • CVE-2026-94100CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 20

    A weakness has been identified in Netcore NBR200V2 1.3.241127.071246.

  • CVE-2026-94098CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 20

    A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246.

  • CVE-2026-94003CVSS 10.0/10CVSS 10.0, critical severity.Background noise for most businessesPublished Sep 20

    A vulnerability has been found in Comfast CF-N1-S 2.6.0.1.

  • CVE-2026-94101CVSS 9.9/10CVSS 9.9, critical severity.Background noise for most businessesPublished Sep 20

    A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246.

  • CVE-2026-90817CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 20

    An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import proc…

  • CVE-2026-94301CVSS 9.8/10CVSS 9.8, critical severity.Background noise for most businessesPublished Sep 21

    The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.re…

  • CVE-2026-94083CVSS 9.4/10CVSS 9.4, critical severity.Background noise for most businessesPublished Sep 19

    Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 stat…

  • CVE-2026-94084CVSS 9.4/10CVSS 9.4, critical severity.Background noise for most businessesPublished Sep 19

    Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.…

  • CVE-2026-63647CVSS 9.3/10CVSS 9.3, critical severity.Background noise for most businessesPublished Sep 18

    CordysCRM is an open source AI-powered customer relationship management system that supports private deployment.

  • CVE-2026-75885CVSS 9.3/10CVSS 9.3, critical severity.Background noise for most businessesPublished Sep 18

    A flaw was found in the OpenShift console.

  • CVE-2025-12999CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 21

    UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forw…

  • CVE-2026-59163CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 18

    Mnemosyne is a memory layer for artificial intelligence agents.

  • CVE-2026-92701CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 18

    Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments.

  • CVE-2026-92702CVSS 9.1/10CVSS 9.1, critical severity.Background noise for most businessesPublished Sep 18

    Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments.

  • CVE-2026-55563CVSS 8.9/10CVSS 8.9, high severity.Background noise for most businessesPublished Sep 21

    Feast is the open source feature store for AI and machine learning.

  • CVE-2026-88807CVSS 8.9/10CVSS 8.9, high severity.Background noise for most businessesPublished Sep 21

    A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject co…

  • CVE-2026-62371CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21

    KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at…

  • CVE-2026-63116CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21

    deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale.

  • CVE-2026-82412CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21

    ntopng is a web-based network traffic monitoring application.

  • CVE-2026-84285CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21

    An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacke…

  • CVE-2026-84990CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21

    ntopng is a web-based network traffic monitoring application.

  • CVE-2026-86553CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 19

    SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process.

  • CVE-2026-92574CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21

    A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container…

  • CVE-2026-93922CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 18

    SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stor…

  • CVE-2026-93923CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 18

    SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing s…

  • CVE-2026-93993CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 19

    Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that execute…

  • CVE-2026-94104CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 20

    NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails…

  • CVE-2026-94106CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 20

    getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames…

  • CVE-2026-94109CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 20

    openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation d…

  • CVE-2026-94128CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 20

    A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500.

  • CVE-2026-94129CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 20

    A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800.

  • CVE-2026-94142CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21

    A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200.

  • CVE-2026-94146CVSS 8.8/10CVSS 8.8, high severity.Background noise for most businessesPublished Sep 21

    A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3.

  • CVE-2026-65651CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21

    temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstr…

  • CVE-2026-65652CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21

    github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames.

  • CVE-2026-65653CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21

    github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-pre…

  • CVE-2026-65654CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21

    github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's l…

  • CVE-2026-89139CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21

    Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compu…

  • CVE-2026-94381CVSS 8.7/10CVSS 8.7, high severity.Background noise for most businessesPublished Sep 21

    MISP has a security issue that can let a user gain more access than their API key is supposed to allow.

  • CVE-2026-68928CVSS 8.6/10CVSS 8.6, high severity.Background noise for most businessesPublished Sep 18

    Acode is a powerful text and code editor for Android.

  • CVE-2026-94383CVSS 8.6/10CVSS 8.6, high severity.Background noise for most businessesPublished Sep 21

    The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file ex…

Reading this list is the easy part

Knowing a flaw exists is not the same as knowing whether it is yours. The real questions come next: do you run the affected version, on which machines, who installed it, is anything else depending on it, and did last month's patch quietly break the one application your billing runs on? None of that is in a CVE record.

Those answers come out of an inventory — a current list of what you run and where — and most small offices have never had one. Building it is the first half of a vulnerability assessment; the second half is deciding, with you, which findings are worth a Tuesday and which are noise. 20+ years of doing it, 100% Texas-based support.

Call NowBook a Call