Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 18 February 2026
RSS331 vulnerabilities published on 18 February 2026
Severity:
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
CVE-2026-26960
GHSA-83g3-92jg-28cx
### Summary
`tar.extract()` in Node `tar` allows an attacker-controlled archive to create a hardlink inside the extraction directory that points to a file outside the extraction root, using default op...
7.1
OpenClaw: Malicious Sessions Can Send Fake User Instructions
GHSA-w5c7-9qqw-6645
Malicious sessions in OpenClaw can trick other sessions into performing actions by sending fake user instructions that look like they came from a real user. This can lead to unintended behavior in wor...
7.1
OpenClaw Browser Control Plane Exposed to Malicious Websites
CVE-2026-26317
GHSA-3fqr-4cg8-h96q
A vulnerability in OpenClaw and Clawdbot allows malicious websites to control a user's browser, potentially opening tabs, stopping the browser, or changing settings. This can happen if the browser con...
7.1
StorageGRID: Malicious requests can delete configuration data
CVE-2026-22048
StorageGRID versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and Azure AD configured as an identity provider are at risk. An attacker can delete important setup data or lock out ac...
7.1
Delinea Cloud Suite May Allow Hackers to Manipulate Requests
CVE-2025-12811
The Delinea Cloud Suite and Privileged Access Service have a security issue that allows hackers to manipulate HTTP requests, potentially leading to unauthorized access or actions. This issue is fixed ...
6.9
LibreDesk Webhooks Allows Attacker to Access Internal Network
CVE-2026-26957
GHSA-wgm6-9rvv-3438
A security vulnerability in LibreDesk's Webhooks module allows an authenticated administrator to access internal corporate networks or cloud infrastructure. This can happen by exploiting internal port...
6.9
OpenClaw Skill Download Writes Files Outside Intended Directory
CVE-2026-27008
GHSA-h7f7-89mm-pqh6
A bug in OpenClaw allowed a malicious skill to write files to any location on the system instead of a safe, designated area. This could lead to data corruption or unauthorized access. To fix this, the...
6.8
OpenClaw Browser Download Function Allows Uncontrolled File Placement
CVE-2026-26972
GHSA-xwjm-j929-xq7c
A security issue in OpenClaw's browser download feature allows an attacker with authenticated access to write files outside the intended download directory. This could lead to data loss or system comp...
6.7
LangGraph Redis Package Allows Unrestricted Access to Data
CVE-2026-27022
GHSA-5mx2-w598-339m
A security flaw in the LangGraph Redis package allows attackers to bypass access controls and see all data, not just what they're supposed to. This is because the package doesn't properly protect agai...
6.5
Rongzhitong Visual Integrated Command and Dispatch Platform: Unapproved Access to User Data
CVE-2026-2669
The Rongzhitong Visual Integrated Command and Dispatch Platform has a security weakness that allows unauthorized access to user information. This means that a hacker could potentially access sensitive...
6.9
GitHub Enterprise Server allows attackers to access internal services
CVE-2026-1999
An authenticated user with certain permissions can access internal services, potentially disrupting job processing or gaining access to sensitive data. This issue affects all versions of GitHub Enterp...
7.2
Unauthorized files can be uploaded to another user's GitHub repository
CVE-2026-1355
A security flaw in older versions of GitHub Enterprise Server allows an attacker with a valid login to upload files to another user's repository, potentially replacing their data with malicious files....
6.0
QEMU KVM Xen Guest Support Has a Security Flaw
CVE-2026-0665
A bug in QEMU's Xen support for virtual machines can cause a guest operating system to intentionally make QEMU's memory access incorrectly, potentially leading to a crash or data corruption. This issu...
6.5
PHPGurukul Hospital Management System v4.0 Exposes Patient Medical Records
CVE-2025-70063
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 allows unauthorized access to other patients' medical records. This is a concern because it means that users can see sensitiv...
6.5
PHPGurukul Hospital Management System allows attackers to create fake doctor accounts
CVE-2025-70062
A security flaw in the 'Add Doctor' module of PHPGurukul Hospital Management System allows hackers to trick authorized users into creating fake doctor accounts. This could lead to unauthorized access ...
6.5
Splunk Monitoring Console App Accessible to Low-Privileged Users
CVE-2026-20141
A user with limited access to a Splunk Enterprise system can access sensitive information by exploiting a permission error in the Monitoring Console App. This could let them see confidential data. To ...
6.5
Mayswind Ezbookkeeping versions 1.2.0 and earlier can crash from deep file uploads
CVE-2025-65519
Versions 1.2.0 and earlier of Mayswind Ezbookkeeping are vulnerable to crashing if a maliciously crafted file is uploaded, which can cause the service to run slowly, stop working, or become completely...
6.5
Graylog API 2.2.3: Authorized Users Can Access Other Users' Profiles
CVE-2026-1436
An authenticated user can access other users' profiles in Graylog 2.2.3, potentially revealing sensitive information like names, email addresses, and activity history. This happens because the API doe...
7.1
WordPress Plugin Allows Attackers to Access Sensitive Data
CVE-2026-1317
A security issue in the WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress allows attackers with subscriber-level access or higher to access sensitive data. This can happen when ...
6.5
Unauthorized users can delete Brevo plugin settings on WordPress sites
CVE-2025-14799
An attacker can delete Brevo plugin settings, disconnect the Brevo integration, and delete subscription forms on a WordPress site without being authorized. This can happen if the Brevo plugin is not u...
6.5
WP-DownloadManager plugin deletes arbitrary files on your server
CVE-2026-2426
The WP-DownloadManager plugin for WordPress allows attackers to delete any file on your server, including sensitive files like your WordPress configuration file. This can lead to a complete server tak...
6.5
Blog2Social for WordPress: Unauthorized Post Changes Possible
CVE-2026-1942
The Blog2Social plugin for WordPress allows unauthorized users to change post titles and contents. This is because the plugin doesn't correctly check if a user has permission to edit posts. We recomme...
6.5
PHP on Red Hat Systems: Unfixable Data Exposure Through Malicious Code
RHSA-2026:2799
A security issue has been found in PHP on Red Hat systems. If an attacker can inject malicious code, they may be able to access sensitive data. Update your systems to the latest version of PHP to prev...
6.5
Taskbuilder Plugin for WordPress Lets Attackers Steal Sensitive Data
CVE-2026-1639
The Taskbuilder plugin for WordPress contains a security flaw that allows an attacker with a subscriber-level account to access sensitive information in the database. This is a serious issue because i...
6.5
OpenClaw extension allows attackers to control HTTP requests to internal hosts
CVE-2026-28476
GHSA-pg2v-8xwh-qhcc
The OpenClaw extension for Urbit can be tricked into sending HTTP requests to any host, including internal ones, if an attacker can control the Urbit URL configuration. This affects deployments that u...
6.3