Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 22 May 2026

RSS

379 vulnerabilities published on 22 May 2026

Severity:
Microsoft Entra ID Origin Validation Error
CVE-2026-42901
An error in Microsoft Entra ID's origin validation allows an unauthorized attacker to gain elevated network access. This means that an attacker could potentially access sensitive information or take c...
10.0
Go SSH Server Skips Security Checks for Wrong Authentication
GO-2026-5023 CVE-2026-46595
A security check is bypassed in Go SSH servers when using an incorrect authentication method. This allows unauthorized access to the server. To fix this, update your Go SSH server to the latest versio...
10.0
Unifi OS Command Injection through Malicious Network Access
CVE-2026-34910
Unifi OS devices can be compromised if an attacker is on the same network. This could allow the attacker to execute unauthorized system commands. To protect your network, ensure you keep UniFi OS soft...
10.0
UniFi OS: Malicious network access can access system files
CVE-2026-34909
UniFi OS devices have a security weakness that allows an attacker with network access to access sensitive files on the system. This could potentially be used to gain further access to the system. To p...
10.0
UniFi OS: Unauthorized changes to system configuration
CVE-2026-34908
This vulnerability affects UniFi OS devices. If left unpatched, a malicious actor with access to the network could make unauthorized changes to the system, potentially disrupting network operations. T...
10.0
Debian Linux: Unauthenticated Remote Code Execution
DEBIAN-CVE-2026-9277
A security issue affects Debian Linux systems, allowing an attacker to run unauthorized code on a vulnerable system without needing a password. This could potentially allow an attacker to take control...
9.9
Azure Resource Manager Privilege Elevation over Network
CVE-2026-47280
Azure Resource Manager's authentication system is flawed, allowing unauthorized users to gain higher levels of access to Azure resources over the network. This is a significant risk because it could a...
9.8
Azure Orbital Spatio Unrestricted File Upload
CVE-2026-40412
An attacker can upload malicious files to Azure Orbital Spatio, potentially allowing them to execute code remotely. This can lead to unauthorized access and control of the system. To mitigate this ris...
9.8
Azure Active Directory B2C Privilege Elevation Over Network
CVE-2026-33843
An attacker can bypass authentication in Azure Active Directory B2C, allowing them to access sensitive information or perform unauthorized actions. This is a serious issue because it can lead to data ...
9.8
Microsoft Power Pages Command Injection Risk
CVE-2026-23652
An unauthorized attacker can execute code over a network if they exploit a weakness in Microsoft Power Pages. This could lead to unauthorized access to sensitive information or system takeover. It's r...
9.8
YesWiki: Unauthenticated SQL Injection Allows Database Access
GHSA-jwvv-qr7q-cv8j CVE-2026-46670
YesWiki installations are vulnerable to SQL injection attacks, allowing attackers to access the entire database, including usernames, emails, and hashed passwords. This is a serious security risk that...
9.8
Apache HTTP Server Unauthenticated Remote Code Execution
BELL-CVE-2026-43501
Apache HTTP Server versions 2.4.52 and earlier have a vulnerability that allows attackers to execute arbitrary code on a server without needing a password. This could allow hackers to take control of ...
9.8
NGINX: Malicious requests can cause a system crash or code execution
ALPINE-CVE-2026-9256
A security issue in NGINX's rewrite module can be exploited by sending specially crafted HTTP requests. This may cause the system to crash or allow an attacker to execute malicious code. If you're usi...
9.4
Microsoft Copilot Command Injection Vulnerability
CVE-2026-41090
An attacker can inject malicious commands into Microsoft Copilot, potentially allowing them to access or modify sensitive data over a network. This vulnerability puts users' data at risk. To protect y...
9.3
FileBrowser Quantum: Path Traversal Allows File Ops Outside Shared Directory
GHSA-qqqm-5547-774x
A public share link can be used to move, copy, or rename files outside the intended shared directory. This can happen if the share owner allows others to modify the shared files. To fix this, update t...
9.3
Apache HTTP Server TCP Packet Length Overflow
CVE-2026-9054
Apache HTTP Server may crash if it receives certain types of network packets. This can cause the server to become unresponsive, leading to downtime and potential data loss. To protect against this, en...
9.2
FileBrowser Quantum: Malicious file operations via public share link
GHSA-qqqm-5547-774x
A public share link allows an attacker to move, copy, or rename files outside the intended shared directory. This can happen if the share link has 'AllowModify' enabled. To fix this, update FileBrowse...
9.1
Golang SSH Known Hosts Allows Bypassing Authentication
GO-2026-5021 CVE-2026-42508
A security issue in the Golang SSH known hosts package allows attackers to bypass authentication by exploiting a flaw in how revoked keys are checked. This could allow unauthorized access to systems t...
9.1
Go SSH Channel Write Can Hang with Large Data
GO-2026-5020 CVE-2026-39834
The Go SSH library can hang if you write large amounts of data at once. This happens because of a math error when checking the data size. To fix this, the library now uses a larger number type to avoi...
9.1
golang.org/x/crypto/ssh/agent: Unenforced key signing constraints
GO-2026-5005 CVE-2026-39833
The golang.org/x/crypto/ssh/agent library in Go did not enforce a security setting for signing keys. This meant that keys could be used to sign without requiring a confirmation prompt. The issue has b...
9.1
Go SSH Agent Key Forwarding Security Risk
GO-2026-5006 CVE-2026-39832
The Go SSH agent key forwarding feature had a security issue that could allow a key to be used on a remote host without restrictions. This has been fixed to ensure that key restrictions are properly e...
9.1
UniFi OS Devices: Command Injection via Malicious Network Access
CVE-2026-33000
High-privilege network access could allow an attacker to inject malicious commands on UniFi OS devices, potentially leading to unauthorized system modifications or data exposure. This vulnerability af...
9.1
Large Data Write on SSH Channel Can Cause Server Crash
UBUNTU-CVE-2026-39834
When writing large amounts of data over an SSH connection, it can cause the server to crash or become unresponsive. This is a concern for businesses that rely on remote access to their servers. To mit...
9.1
Apache Kafka Remote Agent Constraint Extension Vulnerability
UBUNTU-CVE-2026-39832
Apache Kafka's remote agent extension allows attackers to execute arbitrary code when adding a key to a constraint. This vulnerability affects systems using the remote agent extension, potentially lea...
9.1
FIDO/U2F Security Keys Have Verification Bypass
UBUNTU-CVE-2026-39831
FIDO/U2F security keys used in some applications may be vulnerable to verification bypass attacks. This means an attacker could potentially access the key without needing to know the correct PIN or ot...
9.1