Monitor vulnerabilities that affect your stack.
Sign up free to get alerts when software you use is affected.
CVE Vulnerabilities - 1 September 2026
RSS753 vulnerabilities published on 1 September 2026
Severity:
SMA1000 Workplace Interface lets remote attacker access internal services
CVE-2026-83548
The SMA1000 appliance’s Workplace web page can be reached without logging in, and it can be tricked into contacting other parts of your network. An attacker outside your organization could use this to...
10.0
KEV
HPE Fabric Composer lets attackers take full control
CVE-2026-76658
The SSH service in HPE Networking Fabric Composer can be accessed without a password, allowing an outside attacker to log in as an administrator. Once inside, the attacker can run any command on the s...
10.0
HPE Fabric Composer API lets remote attacker gain admin access
CVE-2026-76657
The web interface that manages HPE Networking Fabric Composer can be tricked into granting full control without a valid login. An attacker could then take over the management server and change or disr...
10.0
Manacle ERP lets remote attacker run their own code
CVE-2026-84147
The Manacle ERP system can be tricked by anyone on the internet into accepting files it shouldn’t. Because the system doesn’t properly check who is uploading files or what type they are, an attacker c...
10.0
Cobham VSAT7090 Router allows remote command injection
CVE-2026-83772
The VSAT7090 maritime satellite router can be tricked into running unauthorized commands when it processes certain email reports. An attacker can send specially crafted data to gain control of the dev...
8.6
WWBN AVideo allows expired password reset links to work
CVE-2026-84480
GHSA-j9p7-hm85-9v77
The AVideo platform does not check whether a password reset link has expired, so a link that should no longer be valid can still be used to change a user's password. If someone obtains such a link, th...
9.3
Thunderbird calendar invites can run hidden programs
CVE-2026-84637
A crafted calendar invitation can cause Thunderbird on Windows to start a program from the user's computer or network, even though the attachment looks harmless. This lets an attacker run malicious co...
9.8
Proxmox VE 7‑8 lets attackers log in without password
CVE-2023-54391
Versions 7.0 through 8.0 of Proxmox Virtual Environment let an unauthenticated user skip the normal password check and log in as any enabled account, including the powerful root account. This happens ...
9.3
Predis PHP client may run injected commands and crash
CVE-2026-84372
GHSA-w6f5-v2h6-g786
The PHP library Predis, used to talk to Redis databases, mishandles batched commands in certain versions. An attacker who can supply specially crafted data could make the client execute unintended com...
9.8
AOS-CX service can let attackers run code remotely
CVE-2026-73749
A part of the AOS-CX system that handles network traffic can be confused by specially crafted data. An attacker who does not need to log in could send these data packets and cause the system to run th...
9.8
Fast Note Sync Service up to 2.13.7 enables admin takeover
CVE-2026-52111
Versions of Fast Note Sync Service up to 2.13.7 reveal a secret authentication key through the admin configuration page. A remote attacker who discovers this key can pretend to be an administrator and...
9.8
OpenAI Codex Desktop may run attacker code from Git repo
CVE-2026-19593
When a user opens a workspace, Codex Desktop reads the Git settings of any repository in that workspace. If those settings have been maliciously modified, the program can launch the attacker’s code wi...
9.8
Tenda A18 router can be hijacked remotely
CVE-2026-51934
The Tenda A18 Wi‑Fi router, version 15.13.07.09, contains a flaw that lets someone on the network run their own software on the device. This could give an attacker control of the router and the data f...
9.8
TOTOLINK T6 router lets anyone alter traffic settings
CVE-2026-51770
The TOTOLINK T6 firmware version 4.1.5 allows people without a login to send specially crafted messages that change quality‑of‑service settings on the device. This could let an attacker prioritize or ...
9.8
TOTOLINK T6 router can be forced to restart cloud update
CVE-2026-51769
The router model TOTOLINK T6 running version 4.1.5cu.748_B20211015 lets anyone send a specially crafted message to trigger a restart of its cloud update check. This could be used to disrupt update pro...
9.8
Pyramid NetStaX Ethernet/IP Stack can crash when overloaded
CVE-2026-78012
The NetStaX Ethernet/IP software used in some devices may lose track of large data requests, leading to corrupted memory or a crash. This can happen without the device reporting an error, potentially ...
9.3
TOTOLINK T6 router lets unauthenticated users alter mesh connections
CVE-2026-51765
The TOTOLINK T6 firmware version 4.1.5 allows anyone on the network to send a specially crafted MQTT message that changes the list of nearby mesh devices. This could let an attacker redirect traffic o...
9.8
TOTOLINK T6 router firmware can let outsiders replace cloud files
CVE-2026-51764
The TOTOLINK T6 router running version 4.1.5cu.748_B20211015 has a weakness that does not require a login before it accepts certain messages. An attacker could send a specially crafted message through...
9.8
TOTOLINK T6 routers let attackers force many firmware updates
CVE-2026-51760
The TOTOLINK T6 access point (firmware version 4.1.5cu.748_B20211015) does not properly verify who can request a firmware upgrade. An unauthenticated person can send a crafted MQTT message that makes ...
9.8
TOTOLINK T6 router lets strangers trigger firmware update
CVE-2026-51757
The T6 router version 4.1.5 allows anyone on the network to start a firmware download or flashing process on a connected device. This could let an attacker load malicious software or disrupt the devic...
9.8
TOTOLINK T6 firmware lets remote attackers delete devices and reboot
CVE-2026-51751
The current TOTOLINK T6 router software can be tricked into removing a mesh device and restarting the whole system without any login. This could let someone outside your network disrupt your Wi‑Fi cov...
9.8
TOTOLINK T6 router lets anyone change mesh channel
CVE-2026-51750
The router model TOTOLINK T6 (firmware version 4.1.5cu.748_B20211015) does not verify who is sending a command to change its primary mesh channel. An attacker on the same network could send a speciall...
9.8
TRtek Store could let attackers steal or alter data
CVE-2026-18210
The online store component of TRtek's products, up to version 030631b2, does not properly filter the information it receives. This allows a malicious user to insert harmful commands into the database,...
9.8
Klemsan KIO lets attackers run their own code
CVE-2026-18808
The Klemsan Internet Objects (KIO) software, versions before 1.9, can be tricked into executing code that an attacker supplies. This could let a malicious user take control of the system or steal data...
9.8
Firefox navigation can let sites bypass page isolation
CVE-2026-84129
A part of Firefox that separates different websites from each other could be tricked, allowing a malicious site to see or affect data from another site. This could lead to privacy or data leakage. Upd...
9.8