Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

IONIX THREAT CENTER

A free, curated feed of CVEs that can be remotely exploited by an unauthenticated attacker, verified and published the moment they emerge. No noise, no triage backlog. Just the exploitable vulnerabilities that actually demand your attention, delivered in real time.

Be the first to know when new zero-days emerge:

Created Date
Source IONIX Agentic Threat Center
CVE-2026-94293 – Unauthenticated Remote Read/Write (RCE-level Data Manipulation) – Murrelektronik So

CVE-2026-94293 is a critical Missing Authentication for Critical Function (CWE-306) vulnerability affecting the Murrelektronik Software AAS Edge Client, an open-source Asset Administration Shell (AAS) reference client originally built as a trade-fair demonstrator. The client's REST API binds to all network interfaces on TCP port 18000, performs no authentication, and accepts cross-origin requests from any origin, allowing any unauthenticated network attacker to read and modify AAS submodel data. The vulnerability affects all released versions of the product and carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105484 – Unauthenticated OS Command Injection (RCE) – TOTOLINK X6000R 9.4.0cu.652_B20230116

CVE-2026-105484 is a critical, unauthenticated OS command injection vulnerability in the firmware upload handler of the TOTOLINK X6000R wireless router. The flaw resides in the firmware_check function of the UploadFirmwareFile handler, reachable via /cgi-bin/cstecgi.cgi, and allows a remote attacker to execute arbitrary operating system commands on the device without any authentication. The issue is rated CRITICAL with a maximum CVSS v3.1 base score of 10.0.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105762 – Unauthenticated SSRF – Dify prior to 1.13.0

CVE-2026-105762 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in Dify, the open-source LLM application development platform by LangGenius. The flaw resides in the /console/api/remote-files/upload endpoint, which fetches attacker-supplied URLs on the server's behalf without any authentication or destination validation. The issue carries a CVSS v3.1 base score of 8.3 (High) and affects all Dify deployments running a version prior to 1.13.0.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-104852 – Prototype Pollution / Denial of Service – GraphQL Tools (@graphql-tools/utils) ≤ 1

CVE-2026-104852 is a prototype pollution vulnerability (CWE-1321) in the mergeDeep utility function shipped in @graphql-tools/utils, part of the widely used GraphQL Tools (ardatan/graphql-tools) library. An unauthenticated remote attacker can craft a GraphQL query that causes mergeDeep to merge attacker-controlled keys such as __proto__, constructor, or prototype into Object.prototype/Function.prototype, corrupting shared JavaScript runtime state. The issue carries a CVSS v4.0 base score of 8.2 (High) and results in a denial-of-service condition affecting the whole process, not just the originating request.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-21589 – Unauthenticated Path Traversal / Arbitrary File Read – Atlassian Bamboo (All Versio

CVE-2026-21589 is a critical path traversal vulnerability affecting Atlassian Bamboo Data Center and Server (along with several other Atlassian Data Center/Server products). An unauthenticated remote attacker who knows the exact name and path of a target file can retrieve files from within the web application root directory. Atlassian rates this vulnerability as Critical with a CVSS score of 9.3.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-77226 – Unauthenticated Admin Account Creation / Authorization Bypass – Camunda 7 (7.24.0 –

CVE-2026-77226 is a critical incorrect-authorization vulnerability (CWE-863) affecting the Admin web application of Camunda 7. The flaw resides in the SetupResource first-run setup endpoint, which miscalculates whether an administrator already exists in the system, allowing an unauthenticated remote attacker to create a new administrator account under certain conditions. The issue carries a CVSS v4.0 base score of 9.2 (Critical) and can lead to full account takeover.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-94201 – Denial of Service (Atom Table Exhaustion) – Ash Framework 3.5.1 through 3.34.2

CVE-2026-94201 is a denial-of-service vulnerability in the Ash Framework, a data layer and application framework for Elixir, caused by uncontrolled atom creation when filtering on :atom-typed resource attributes. An unauthenticated or low-privileged remote actor who can supply filter values to a public, filterable atom attribute can force the application to permanently exhaust the BEAM virtual machine's finite atom table, crashing the node. The issue carries a CVSS score of 8.2 (High) and affects Ash versions 3.5.1 through 3.34.2.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-103352 – Unauthenticated Blind SQL Injection – WP BASE Booking WordPress Plugin (≤ 6.4.0)

CVE-2026-103352 is a critical, unauthenticated blind SQL injection vulnerability in the WP BASE Booking plugin for WordPress (wp-base-booking-of-appointments-services-and-events), affecting all versions up to and including 6.4.0. The flaw stems from improper neutralization of special elements used in SQL commands (CWE-89), allowing a remote attacker to inject SQL statements without any authentication or user interaction. It carries a CVSS v3.1 base score of 9.3 (Critical) and was fixed in version 6.5.0.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105638 – Authentication Bypass via Magic-Code Brute Force – Plane < 1.4.0

CVE-2026-105638 is a critical authentication vulnerability in Plane, the open-source project management platform, affecting versions prior to 1.4.0. The magic-code (email OTP) sign-in and sign-up verification endpoints lacked any per-code failed-attempt tracking and bypassed Django REST Framework's built-in rate throttling, allowing an unauthenticated attacker who knows a victim's email address to brute-force the six-digit login code within its validity window and take over the account. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105639 – Pre-Auth Workspace Invitation Hijack – Plane ≤ 1.3.1

CVE-2026-105639 is a critical authentication and authorization bypass vulnerability in Plane, the open-source project management platform maintained by makeplane. An unauthenticated attacker who knows a target's email address can hijack a pending workspace invitation intended for that victim, gaining unauthorized membership in the workspace at the invited role level — up to full Admin control. The flaw carries a CVSS v3.1 base score of 9.8 (Critical) and affects all versions up to and including 1.3.1.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105641 – Unauthenticated Remote Takeover via Hardcoded Secret Keys – Plane (Community Deplo

CVE-2026-105641 is a critical use of hard-coded credentials (CWE-798) vulnerability affecting Plane, an open-source project management platform maintained by makeplane. Community (self-hosted) deployment manifests for versions prior to 1.4.0 shipped with fixed, publicly known default values for the Django SECRET_KEY and the LIVE_SERVER_SECRET_KEY, which remained active unless an operator manually overrode them. Because these keys underpin session signing and live-collaboration authentication, their disclosure allows a remote, unauthenticated attacker to forge valid sessions and bypass authentication entirely.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105640 – Authentication Bypass / Account Takeover – Plane < 1.4.0

CVE-2026-105640 is a critical authentication bypass vulnerability in Plane, the open-source project management platform by makeplane, affecting all versions prior to 1.4.0. The flaw stems from Plane trusting email addresses returned by Gitea OAuth and by self-managed GitLab OAuth without verifying that the provider confirmed ownership of that email, allowing an attacker to take over an existing victim account. The issue carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-104970 – Admin Bootstrap Race Condition – Plane < 1.4.0

CVE-2026-104970 is a time-of-check-to-time-of-use (TOCTOU) race condition in Plane, the open-source project management tool, that allows an unauthenticated attacker to become an instance administrator alongside the legitimate operator during the initial admin bootstrap process. The flaw resides in the InstanceAdminSignUpEndpoint, which checks for an existing admin and creates new admin accounts without any locking or uniqueness enforcement. It affects Plane versions 0.13 through 1.3.1 and carries a CVSS v3.1 base score of 8.1 (High).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-102428 – Unauthenticated SQL Injection – OrdaSoft Joomla CCK extension (versions 1.0.0–8.3.

CVE-2026-102428 is a critical, unauthenticated SQL injection vulnerability in the OrdaSoft Joomla CCK extension (component com_os_cck) for Joomla. The flaw stems from improper validation of a user-supplied "order column" parameter used in record sorting, allowing attackers to inject arbitrary SQL without any authentication. The issue is rated 9.3 (Critical) and is remotely exploitable over the network.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-102775 – Authorization Bypass (IDOR) Exposing Customer Downloads – Phoca Cart for Joomla 5.

CVE-2026-102775 is a high-severity (CVSS 8.7) authorization bypass (Insecure Direct Object Reference) in the Phoca Cart extension for Joomla, affecting versions 5.0.0 through 6.1.8. The flaw resides in the order-file download endpoint, which fails to properly validate download and order tokens, allowing unauthenticated remote attackers to retrieve other customers' purchased digital goods.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-79820 – Authentication Bypass – HPE iLO 7 Firmware (v1.25.00 and earlier)

CVE-2026-79820 is a critical remote user validation (authentication) failure affecting HPE Integrated Lights-Out (iLO) 7 firmware, the out-of-band management controller embedded in HPE's current-generation ProLiant servers. The flaw is tracked under CWE-287 (Improper Authentication) and carries a CVSS v3.1 base score of 9.0 (Critical). Because iLO interfaces are frequently exposed to management networks and, in misconfigured environments, to the internet, successful exploitation could allow an attacker to bypass authentication controls and gain unauthorized access to the server management plane.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-92931 – Critical SSRF – Progress Sitefinity Next.js SDK (@progress/sitefinity-nextjs-sdk) 1

CVE-2026-92931 is a critical Server-Side Request Forgery (SSRF) vulnerability in Progress Software's @progress/sitefinity-nextjs-sdk npm package, the official SDK used to build Next.js-based front ends for Sitefinity CMS. The flaw allows a remote, unauthenticated attacker to force the server to issue requests to an attacker-controlled host, potentially exposing sensitive internal information. The issue carries the maximum CVSS v3.1 base score of 10.0 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105285 – Critical Unauthenticated RCE (Stack-Based Buffer Overflow) – TOTOLINK A3002MU 1.0.

CVE-2026-105285 is a critical stack-based buffer overflow in the QoS Rule Handler of TOTOLINK A3002MU routers running firmware 1.0.0-B20230403.1455. The flaw resides in the /boafrm/formIpQoS endpoint and can be triggered remotely over the network with no authentication, allowing an attacker to crash the device's management interface or potentially achieve arbitrary code execution as root. The issue has been assigned a maximum CVSS v3.1 base score of 10.0.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105284 – Pre-Authentication Bypass to Root RCE – TOTOLINK A3002MU 1.0.0-B20230403.1455

CVE-2026-105284 is a critical improper-authorization (CWE-285) vulnerability in the TOTOLINK A3002MU wireless router, firmware version 1.0.0-B20230403.1455. A flaw in the /bin/boa web server's authentication-check routine (sub_40FCFC) allows a remote, unauthenticated attacker to bypass session verification entirely and reach administrative and diagnostic request handlers. The issue carries the maximum CVSS score of 10.0 and is rated critical.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-103510 – Authentication Bypass / Unauthenticated RCE Risk – Perforce P4 Search prior to 202

CVE-2026-103510 is an authentication bypass vulnerability in Perforce P4 Search, the search component bundled with P4 (Helix Core). The component fails to fail securely when its service authentication token is left blank, allowing an unauthenticated, network-based attacker to obtain the highest application privilege within P4 Search. This can lead to full compromise of P4 Search and the connected P4 Server, and Perforce has rated the issue Critical (CVSS 9.5).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-100103 – Authentication Bypass / Potential RCE – Perforce P4Search (Helix Core) ≤ 2026.4.1

CVE-2026-100103 is a critical authentication bypass vulnerability affecting Perforce P4Search container images, a component of Perforce Helix Core (P4). Affected container images reset the service authentication token to a publicly documented default value, allowing an unauthenticated network attacker to obtain the highest application privilege within P4Search. This can potentially lead to arbitrary code execution and compromise of the connected P4 Server, and carries a maximum CVSS score of 10.0.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105212 – Authentication Bypass / Account Takeover – ZITADEL 3.x < 3.4.14 and 4.x < 4.16.2

CVE-2026-105212 is an authentication bypass vulnerability in ZITADEL's hosted Login V1 and Login V2 UIs that allows an unauthenticated attacker to enroll a malicious passkey (or other authenticator) on an "identify-only" login session — one where the username has been submitted but no primary factor (password) has yet been verified. Knowing only a victim's login name, an attacker can register their own authenticator and fully take over the account, bypassing the victim's existing password and any configured MFA. The issue is rated HIGH severity (CVSS 8.7).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105210 – Authentication Bypass (Unauthenticated MFA Enrollment) – ZITADEL Login V1 UI, 3.x

CVE-2026-105210 is an authentication bypass vulnerability in ZITADEL's hosted Login V1 UI, rated HIGH severity (CVSS 8.8 / 8.2 depending on scoring version). The flaw allows an unauthenticated attacker who knows only a victim's login name to enroll attacker-controlled second-factor (MFA) credentials and overwrite the victim's verified phone number, without ever supplying a valid password or other primary authentication factor.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105215 – Authentication Bypass / Account Pre-Hijacking – ZITADEL 3.x before 3.4.14 and 4.x

CVE-2026-105215 is a critical authentication bypass (CWE-290, Authentication Bypass by Spoofing) affecting ZITADEL's hosted Login V1 UI. The registration endpoint used when an external identity is "not found" accepts client-supplied external identity fields (IdP config ID and external user ID) without requiring a completed, verified IdP callback, allowing an unauthenticated attacker to pre-create an account bound to a victim's external identity. The flaw carries a CVSS score of 9.3 and affects ZITADEL 3.x before 3.4.14 and 4.x before 4.16.2.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105207 – Unauthenticated Account Takeover via External IdP Linking – ZITADEL 3.0.0–3.4.15 a

CVE-2026-105207 is a critical missing-authentication vulnerability in ZITADEL, an open-source identity and access management platform. ZITADEL links user accounts to external identity providers (IdPs) without verifying a primary authentication factor or the caller's permission to make that link, both in "identify-only" Login V2 sessions and via the User Service V2 AddIDPLink API endpoint. An attacker who knows only a victim's login name can exploit this to bind their own external IdP identity to the victim's account and sign in as that victim, resulting in full account takeover.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105211 – Authentication Bypass / Account Takeover – ZITADEL 4.0.0–4.17.0

CVE-2026-105211 is an authentication bypass vulnerability in ZITADEL's Login V2 UI that allows an unauthenticated attacker who knows only a victim's login name to obtain a fully MFA-authenticated session. The flaw stems from the returnCode OTP delivery type returning one-time passcodes directly in the HTTP response instead of sending them out-of-band, letting the attacker complete both OTP factors without any credentials. Exploitation can lead to full account takeover, including compromise of administrator accounts and the underlying ZITADEL instance.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-103355 – Unauthenticated Blind SQL Injection – Unlimited Elements For Elementor ≤ 2.0.20

CVE-2026-103355 is a critical, unauthenticated blind SQL injection vulnerability in the Unlimited Elements For Elementor WordPress plugin (Free Widgets, Addons, Templates), affecting all versions up to and including 2.0.20. The flaw stems from insufficient sanitization of special characters in a database query, allowing a remote attacker to manipulate SQL statements without any credentials. It carries a CVSS v3.1 base score of 9.3 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105134 – OS Command Injection (RCE) – Ahsay AhsayCBS 10.3.0–10.3.2

CVE-2026-105134 is a critical, unauthenticated OS command injection vulnerability in Ahsay AhsayCBS, a backup management console used by managed service providers to administer Ahsay backup environments. The flaw resides in the Replication Receiver component and allows a remote attacker to execute arbitrary operating system commands on the underlying server without credentials or user interaction. The issue carries a maximum CVSS v3.1 base score of 10.0 and affects AhsayCBS versions up to 10.3.2.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105135 – Unauthenticated Remote Code Execution – InternLM MindSearch 0.1.0

CVE-2026-105135 is a critical code injection vulnerability in InternLM MindSearch version 0.1.0, affecting the ExecutionAction.run function in the Planner Agent component (mindsearch/agent/graph.py). Manipulation of input arguments allows an attacker to inject and execute arbitrary code, and the flaw can be triggered remotely over the network with no authentication or user interaction required. The vulnerability carries the maximum CVSS v3.1 base score of 10.0 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-88779 – Denial of Service (Memory Overflow) – NetScaler ADC and Gateway 14.1/13.1

CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway that can be exploited remotely, without authentication, to cause a denial of service. The flaw carries a CVSS score of 8.7 (High) and affects multiple 14.1 and 13.1 release branches, including FIPS builds. Citrix has published fixed builds for all affected branches under advisory CTX697174.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-91078 – Unauthenticated Privileged Account Takeover – TillKit WordPress Plugin < 1.0.5

CVE-2026-91078 is an Improper Authentication (CWE-287) vulnerability in the TillKit WordPress plugin, affecting all versions prior to 1.0.5. The plugin provisions a privileged Point-of-Sale (POS) "manager" account at activation time with a hard-coded, publicly known default PIN that site owners are never required to change. Because the public-facing POS login endpoint validates access solely on this static PIN with no identity or capability checks, any unauthenticated remote attacker can log in as the privileged POS account.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-89236 – Unauthenticated SQL Injection – SaveTo Wishlist Lite WordPress Plugin < 1.1.5

CVE-2026-89236 is an unauthenticated SQL injection vulnerability in the SaveTo Wishlist Lite WordPress plugin, caused by insufficient sanitization and escaping of parameters used in the ORDER BY clause of a SQL query. The flaw affects all plugin versions prior to 1.1.5 and carries a CVSS v3.1 base score of 8.6 (High), allowing remote, unauthenticated attackers to extract sensitive information from the site's database.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-103065 – Broken Access Control – Kirki (WordPress Plugin) ≤ 6.3.1

CVE-2026-103065 is a broken access control vulnerability in the Kirki WordPress plugin (developed by Themeum), caused by improper validation of specified input quantities that allows unauthenticated attackers to reach functionality that should be restricted by access control lists (ACLs). The issue affects Kirki versions through 6.3.1 and carries a CVSS v3.1 base score of 8.2 (High). It was fixed in version 6.3.2.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-105115 – Unauthenticated Arbitrary Class Instantiation / Potential RCE – OpenAM ≤ 16.1.2

CVE-2026-105115 is a missing authentication vulnerability in OpenAM's legacy JAX-RPC SOAP interface (/jaxrpc/*) that allows an unauthenticated, network-based attacker to load and instantiate arbitrary Java classes available on the server's classpath. The flaw affects all OpenAM versions through 16.1.2 and carries a High/Critical severity rating given its unauthenticated, network-exploitable nature and potential for server crashes, classpath enumeration, or code execution.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-92084 – Unauthenticated Arbitrary Shortcode Execution – Beaver Builder Page Builder (Lite)

CVE-2026-92084 is a critical unauthenticated arbitrary shortcode execution vulnerability (CWE-94, Improper Control of Generation of Code) affecting the Beaver Builder Page Builder plugin for WordPress, including its free "Lite" edition. The plugin fails to properly validate input before passing it to WordPress's do_shortcode function when rendering a Sidebar module, allowing unauthenticated attackers to execute arbitrary shortcodes on the site. The issue carries a CVSS v3.1 base score of 9.1 (Critical).

WATCH A SHORT IONIX DEMO

See how easy it is to implement a CTEM program with IONIX. Find and fix exploits fast.

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge