Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2026-84869
Known exploited
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
CVSS Score
9.9
EPSS Score
0.007
Published
2026-09-08
CVE-2026-85880
Known exploited
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.036
Published
2026-09-08
CVE-2026-81963
Known exploited
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.006
Published
2026-09-08
CVE-2026-75650
Known exploited
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS Score
10.0
EPSS Score
0.021
Published
2026-09-07
CVE-2026-86218
Known exploited
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
CVSS Score
10.0
EPSS Score
0.075
Published
2026-09-06
CVE-2026-67277
Known exploited
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CVSS Score
8.8
EPSS Score
0.009
Published
2026-09-05
CVE-2026-86060
Known exploited
RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
CVSS Score
9.2
EPSS Score
0.011
Published
2026-09-05
CVE-2026-85046
Known exploited
Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
EPSS Score
0.015
Published
2026-09-03
CVE-2026-83548
Known exploited
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CVSS Score
10.0
EPSS Score
0.047
Published
2026-09-01
CVE-2026-83549
Known exploited
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
CVSS Score
7.8
EPSS Score
0.085
Published
2026-09-01


Contact Us

Shodan ® - All rights reserved