Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 21 February 2026
RSS59 vulnerabilities published on 21 February 2026
Severity:
Apache HTTP Server Unauthenticated File Access in Certain Directories
ECHO-32c7-8a8f-5df3
An attacker can access files on your server without a password if Apache is configured a certain way. This could allow them to steal sensitive information or disrupt your site. Update your Apache serv...
WordPress: Unchecked User Input in Admin Panel Allows Unauthorized Actions
CVE-2026-27534
A security issue in WordPress's admin panel allows unauthorized users to perform actions they shouldn't be able to. This can happen if a website owner doesn't properly restrict user permissions. To fi...
Adobe Reader: Malicious Links Can Execute Arbitrary Code
CVE-2026-27533
Adobe Reader has a weakness that can allow hackers to trick users into opening malicious links, which can then execute code on the user's computer. This could allow attackers to steal sensitive inform...
WordPress Users Affected by Missing Configuration Check
CVE-2026-27532
If not properly configured, WordPress users may be vulnerable to unauthorized actions. This occurs when the plugin or theme does not check a user's permissions before allowing certain actions. To prev...
WordPress Allows Unauthorized Access to Website Content
CVE-2026-27531
A vulnerability in WordPress allows attackers to access website content without permission. This can lead to sensitive information being accessed or modified. To protect your site, update WordPress to...
WordPress Plugin Rejected User Input Not Sanitized
CVE-2026-27530
A security update is needed for a popular WordPress plugin that doesn't properly filter user input, which means an attacker could inject malicious code. This could allow them to take control of a webs...
WordPress Plugin 'WP User Manager' Allows Unauthenticated Access
CVE-2026-27529
A security weakness in the 'WP User Manager' plugin for WordPress allows unauthorized users to access and manage other users' information. This could enable hackers to view and modify sensitive data. ...
Apache HTTP Server: Unauthenticated Access to Sensitive Files
CVE-2026-27528
An issue in the Apache HTTP Server allows attackers to access sensitive files without a password. This could lead to unauthorized access to sensitive data or system configuration. To protect your serv...
WordPress Plugin Rejected User Feedback Not Displayed
CVE-2026-27527
A vulnerability in a WordPress plugin allows an attacker to manipulate user feedback on an installation. This could lead to fake reviews and ratings being displayed, potentially damaging the reputatio...