Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

IONIX THREAT CENTER

A free, curated feed of CVEs that can be remotely exploited by an unauthenticated attacker, verified and published the moment they emerge. No noise, no triage backlog. Just the exploitable vulnerabilities that actually demand your attention, delivered in real time.

Be the first to know when new zero-days emerge:

Created Date
Source IONIX Threat Lab
CVE-2026-9586 – Unauthenticated SQL Injection Leading to RCE – Sangoma Switchvox SMB Edition 8.3

CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (build 104997), scored 9.3 (Critical) under CVSS 4.0. The flaw allows a remote, unauthenticated attacker to execute arbitrary SQL statements — and escalate to remote code execution — against the backend PostgreSQL database via a single crafted HTTP request. Sangoma released version 8.4.0.2 on July 14, 2026, three days before this CVE was published; systems still running 8.3 (build 104997) remain vulnerable.

Created Date
Source IONIX Threat Lab
CVE-2026-9198 – Unauthenticated RCE – IBM Langflow OSS 1.0.0–1.10.0

CVE-2026-9198 is a critical unauthenticated remote code execution (RCE) vulnerability affecting IBM Langflow OSS versions 1.0.0 through 1.10.0. By chaining two API endpoints — an authentication bypass in /api/v1/auto_login and arbitrary Python code execution in /api/v1/validate/code — an unauthenticated network attacker can achieve full RCE on any default-configured Langflow deployment. IBM has assigned a CVSS v3.1 base score of 9.8 (Critical) and recommends immediate upgrade to version 1.10.1.

Created Date
Source IONIX Threat Lab
CVE-2026-8505 – Unauthenticated Webhook Auth Bypass Leading to RCE – IBM Langflow OSS 1.0.0–1.10.0

CVE-2026-8505 is a critical authentication bypass vulnerability (CWE-306: Missing Authentication for Critical Function) in IBM Langflow OSS versions 1.0.0 through 1.10.0, carrying a CVSS v3.1 score of 9.8 (Critical). A flaw in the webhook authentication logic allows any unauthenticated remote attacker who knows a flow's UUID to trigger execution of that flow with owner-level privileges, potentially resulting in Remote Code Execution (RCE). The vulnerability is present in the vast majority of Langflow deployments because the vulnerable condition — WEBHOOK_AUTH_ENABLE set to False — is the default configuration shipped with the…

Created Date
Source IONIX Threat Lab
CVE-2026-9103 – Authentication Bypass – IBM Langflow OSS 1.0.0 through 1.10.0

CVE-2026-9103 is a critical authentication bypass vulnerability (CVSS 9.8) in IBM Langflow OSS versions 1.0.0 through 1.10.0. The flaw resides in the /api/v1/login/auto_login endpoint, which issues long-lived superuser bearer tokens to any unauthenticated network caller when the AUTO_LOGIN configuration is enabled — a setting that is on by default. Classified under CWE-306 (Missing Authentication for Critical Function), this vulnerability enables unauthenticated remote attackers to gain full administrative control over any affected Langflow instance without any credentials or user interaction.

Created Date
Source IONIX Threat Lab
CVE-2026-63305 – Unauthenticated OS Command Injection (RCE) – WWBN AVideo through 29.0

CVE-2026-63305 is a critical OS command injection vulnerability (CWE-78) in WWBN AVideo affecting all versions through 29.0. The flaw resides in the ffmpeg.json.php endpoint, where the notifyCode and callback parameters are concatenated directly into a shell command without sanitization, enabling unauthenticated remote attackers who can craft a valid encrypted payload to execute arbitrary OS commands as the web-server user. The vulnerability carries a CVSS v4.0 score of 9.2 (Critical) and a CVSS v3.1 score of 8.1 (High).

Created Date
Source IONIX Threat Lab
CVE-2026-62386 – JWT Admin Token Leakage via URL Parameter – Grav API Plugin before 1.0.0-rc.16

CVE-2026-62386 is a high-severity vulnerability (CVSS 8.2) classified as CWE-598 (Use of GET Request Method With Sensitive Query Strings), affecting the Grav CMS API plugin (getgrav/grav-plugin-api) in all versions before 1.0.0-rc.16. The plugin's JwtAuthenticator::extractBearerToken() method accepts JWT admin access tokens via the ?token= URL query parameter across every API route, causing valid tokens to be persistently logged and leaked through multiple channels. An attacker who obtains a leaked token gains full unauthorized administrative API access to the affected Grav installation.

Created Date
Source IONIX Threat Lab
CVE-2026-63088 – SSRF via DNS Blocklist Bypass – StoatChat (revolt-january before 0.14.0)

CVE-2026-63088 is a Server-Side Request Forgery (SSRF) vulnerability in StoatChat's revolt-january backend component, affecting all versions prior to 0.14.0. The flaw allows unauthenticated, network-accessible attackers to bypass the platform's DNS-based IP blocklist and issue HTTP requests to internal-only hosts, including loopback and RFC1918 addresses. The vulnerability carries a CVSS v3.1 score of 8.6 (High).

Created Date
Source IONIX Threat Lab
CVE-2026-13446 – Hard-Coded Credentials Enabling Unauthorized Superuser Access – IBM Langflow OSS…

CVE-2026-13446 is a critical (CVSS 9.8) hard-coded credentials vulnerability (CWE-798) in IBM Langflow OSS, affecting all releases from version 1.0.0 through 1.10.1. The application enforces hardcoded default superuser credentials at startup regardless of any operator-supplied environment variable overrides, allowing a remote unauthenticated attacker with knowledge of those credentials to gain full superuser access to the platform. IBM has released a patch in version 1.10.2.

Created Date
Source IONIX Threat Lab
CVE-2026-12694 – Missing Authorization / ACL Bypass – Vimesoft Enterprise Video Platform 3.11.0.0…

CVE-2026-12694 is a critical Missing Authorization vulnerability (CWE-862) in Vimesoft Inc. Enterprise Video Platform, affecting all versions from 3.11.0.0 up to (but not including) 3.25.0. The flaw allows unauthenticated remote attackers to access protected functionality that is not properly constrained by access control lists (ACLs), with no authentication or user interaction required.

Created Date
Source IONIX Threat Lab
CVE-2026-12691 – Authentication Bypass – Vimesoft Enterprise Video Platform 3.11.0.0 to before 3….

CVE-2026-12691 is a high-severity Missing Authentication for Critical Function vulnerability (CWE-306) in Vimesoft Inc. Enterprise Video Platform, affecting all versions from 3.11.0.0 up to (but not including) 3.25.0. The flaw allows unauthenticated remote attackers to bypass authentication and access critical platform functions, resulting in full confidentiality compromise.

Created Date
Source IONIX Threat Lab
CVE-2026-53595 – Authentication Bypass / Account Takeover – FreeScout Help Desk prior to 1.8.224

CVE-2026-53595 is a critical authentication bypass vulnerability (CVSS 9.4) in FreeScout, an open-source PHP/Laravel-based help desk and shared inbox application. The flaw resides in the public user-setup endpoint and allows an unauthenticated remote attacker to overwrite the credentials of the lowest-ID activated FreeScout account — which may be an administrator — and immediately authenticate as that user. All versions of FreeScout prior to 1.8.224 are affected.

Created Date
Source IONIX Threat Lab
CVE-2026-63766 – Unauthenticated OS Command Injection / RCE – GPT-SoVITS through 20250606v2pro

CVE-2026-63766 is a critical OS command injection vulnerability (CWE-78) in GPT-SoVITS, an open-source AI voice cloning and text-to-speech application developed by RVC-Boss. Affecting all versions through 20250606v2pro, the flaw enables unauthenticated remote attackers to execute arbitrary operating system commands on the server by submitting malicious input through the application's Gradio web interface. The vulnerability carries a CVSS 4.0 score of 9.3 (Critical) and a CVSS 3.1 score of 9.8 (Critical).

Created Date
Source IONIX Threat Lab
CVE-2026-53591 – Unauthenticated Message Injection – FreeScout Help Desk prior to 1.8.223

CVE-2026-53591 is a high-severity improper authentication vulnerability (CWE-287) in FreeScout, the open-source PHP/Laravel help desk and shared inbox platform, affecting all versions prior to 1.8.223. An unauthenticated remote attacker can inject arbitrary messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted In-Reply-To header, requiring no credentials or prior access. The vulnerability carries a CVSS v3.1 base score of 8.6 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L).

Created Date
Source IONIX Threat Lab
CVE-2026-48812 – Unauthenticated Attachment Disclosure – FreeScout Help Desk prior to 1.8.221

CVE-2026-48812 is a high-severity unauthenticated information disclosure vulnerability affecting FreeScout, the self-hosted open-source PHP/Laravel help desk and shared inbox application, in all versions prior to 1.8.221. The vulnerability allows any remote, unauthenticated attacker to download attachments that were created by older versions of FreeScout without possessing a valid session or token, due to a missing authentication check in the attachment download route for legacy token types. It carries a CVSS v3.1 base score of 7.5 (High).

Created Date
Source IONIX Threat Lab
CVE-2026-11349 – Unauthenticated SQL Injection – Modern Events Calendar (Pro & Lite) before 7.34.0

CVE-2026-11349 is a high-severity unauthenticated SQL injection vulnerability affecting the Modern Events Calendar Pro and Modern Events Calendar Lite WordPress plugins in all versions prior to 7.34.0. The flaw allows any unauthenticated remote attacker to inject arbitrary SQL and extract sensitive data from the WordPress database, with no credentials or user interaction required. This vulnerability carries a CVSS v3.1 base score of 8.6 (HIGH) with scope change, reflecting the potential for database-wide data exfiltration.

Created Date
Source IONIX Threat Lab
CVE-2026-63429 – Unauthenticated File Upload – HeyForm prior to 3.0.0-rc.9

CVE-2026-63429 is a high-severity unauthenticated arbitrary file upload vulnerability in HeyForm, an open-source self-hosted form builder. Prior to version 3.0.0-rc.9, the POST /api/upload endpoint accepts file uploads from any anonymous internet user with no authentication or session validation, allowing attackers to store arbitrary files on an exposed HeyForm instance and obtain permanent public URLs hosted under the victim's domain. The vulnerability carries a CVSS v3.1 score of 8.6 (HIGH).

Created Date
Source IONIX Threat Lab
CVE-2026-35048 – Unauthenticated RCE via PHP Code Injection – Piwigo ≤ 16.3.0

CVE-2026-35048 is a critical unauthenticated remote code execution (RCE) vulnerability in the Piwigo open-source photo gallery application, affecting all versions up to and including 16.3.0. The flaw resides in Piwigo's installer endpoint (install.php), where attacker-controlled POST parameters are written directly into a PHP configuration file without adequate sanitization — a protection gap triggered by a PHP 8.0 compatibility regression. Piwigo has addressed the issue in version 16.4.0 and the vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Threat Lab
CVE-2026-54159 – Unauthenticated RCE via PHP Object Injection – PrestaShop ps_facetedsearch 3.0.0…

CVE-2026-54159 is a critical PHP object injection vulnerability in the PrestaShop ps_facetedsearch (Faceted Search) module, affecting versions 3.0.0 through 4.0.3. An unauthenticated attacker can exploit the flaw via a single crafted HTTP request to achieve full remote code execution on the underlying server. The vulnerability carries a CVSS v3.1 base score of 10.0 (Critical) and has been patched in version 4.0.4.

Created Date
Source IONIX Threat Lab
CVE-2026-46410 – Unauthenticated Information Disclosure – FileBrowser Quantum prior to 1.3.2-stab…

CVE-2026-46410 is a high-severity unauthenticated information disclosure vulnerability in FileBrowser Quantum, a free, self-hosted, web-based file manager maintained by gtsteffaniak. The flaw allows unauthenticated remote attackers to retrieve sensitive data — specifically file source and path information — through the application's share functionality, without any credentials or user interaction. It carries a CVSS 4.0 score of 8.7 (HIGH) and affects all versions prior to 1.3.2-stable and 1.4.1-beta.

Created Date
Source IONIX Threat Lab
CVE-2026-63030 – Pre-Auth RCE via REST API Route Confusion + SQL Injection – WordPress 6.8.x / 6….

CVE-2026-63030 ("wp2shell") is a pre-authentication Remote Code Execution vulnerability in WordPress Core, affecting versions 6.8.x (before 6.8.6), 6.9.x (before 6.9.5), and 7.0.x (before 7.0.2). It chains a route confusion flaw in the REST API batch endpoint with a SQL injection in WP_Query (CVE-2026-60137), enabling an unauthenticated attacker to execute arbitrary code on a default WordPress installation — no plugins, no special configuration, and no credentials required. Security patches were released on July 17, 2026, and WordPress.org has enabled forced automatic updates for affected installations.

Created Date
Source IONIX Threat Lab
CVE-2026-63094 – Open Redirect Enables Session Token Theft – SigNoz through 0.133.0

CVE-2026-63094 is a high-severity open redirect vulnerability (CWE-601) in SigNoz, an open-source, OpenTelemetry-native observability platform, affecting all versions through 0.133.0. The flaw resides in the SSO authentication flow and allows unauthenticated remote attackers to steal victims' access and refresh tokens by delivering a crafted login URL, enabling full account takeover on any instance configured with Google OAuth, SAML, or OIDC. The vulnerability carries a CVSS v3.1 score of 8.1 (HIGH).

Created Date
Source IONIX Threat Lab
CVE-2026-63101 – Authentication Bypass / Unauthenticated Member Roster Disclosure – Open Event Se…

CVE-2026-63101 is a high-severity missing authentication vulnerability (CWE-306) affecting Open Event Server (fossasia/open-event-server) through version 1.19.1. The flaw allows unauthenticated remote attackers to export the complete member roster — including email addresses, names, join dates, and roles — for any group hosted on the platform, with no credentials required at any step. The vulnerability carries a CVSS v4.0 score of 8.7 (HIGH) and a CVSS v3.1 score of 7.5 (HIGH).

Created Date
Source IONIX Threat Lab
CVE-2026-9585 – Unauthenticated Reflected XSS – Sangoma Switchvox SMB Edition 8.3 through 8.4.0.1

CVE-2026-9585 is an unauthenticated reflected cross-site scripting (XSS) vulnerability in Sangoma Switchvox SMB Edition, affecting versions 8.3 (build 104997) through 8.4.0.1. The flaw resides in the invalid_browser and invalid_browser_login handlers — pre-authentication browser-compatibility screens reachable without any credentials — where the portal parameter is reflected unsanitized into server-generated JavaScript, enabling attacker-controlled script execution in a victim's browser. The vulnerability carries a CVSS 4.0 score of 8.6 (High) and was patched in version 8.4.0.2, released July 14, 2026.

Created Date
Source IONIX Threat Lab
CVE-2026-12692 – Authentication Bypass via Unverified Password Change – Vimesoft Enterprise Video…

CVE-2026-12692 is a critical Unverified Password Change vulnerability (CWE-620) in Vimesoft Inc. Enterprise Video Platform, affecting all versions from 3.11.0.0 up to (but not including) 3.25.0. The flaw allows an unauthenticated remote attacker to change any user's account password without knowledge of the original credentials, resulting in full account takeover.

Created Date
Source IONIX Threat Lab
CVE-2026-47865 – Authentication Bypass – VMware Avi Load Balancer 22.1.1–31.2.2

CVE-2026-47865 is a critical authentication bypass vulnerability (CWE-287: Improper Authentication) in VMware Avi Load Balancer, assigned a CVSS v3.1 base score of 9.8. A malicious actor with network access can bypass the Avi Controller's authentication mechanism and gain unauthorized access to the Avi Control Plane without any credentials or user interaction. Broadcom has confirmed that no workarounds exist — patching is the only remediation.

Created Date
Source IONIX Threat Lab
CVE-2026-50528 – Authorization Bypass (Security Feature Bypass) – Microsoft .NET 8 / 9 / 10 (SslS…

CVE-2026-50528 is a Security Feature Bypass vulnerability (CWE-863: Incorrect Authorization) in the SslStream TLS/SSL implementation of Microsoft .NET, affecting .NET 8, .NET 9, and .NET 10. An unauthenticated remote attacker can exploit this flaw to bypass authorization checks performed during encrypted TLS communications, resulting in a high integrity impact. With a CVSS v3.1 base score of 8.2 (High), this vulnerability was patched by Microsoft on July 14, 2026 as part of the July 2026 Patch Tuesday release.

Created Date
Source IONIX Threat Lab
CVE-2026-48062 – Unrestricted File Upload leading to RCE – CodeIgniter4 prior to 4.7.3

CVE-2026-48062 is a critical unrestricted file upload vulnerability (CWE-434) in the CodeIgniter4 PHP web framework affecting all versions prior to 4.7.3. The flaw resides in the ext_in upload validation rule, which incorrectly inspects the MIME-derived file extension rather than the client-supplied filename extension, allowing an attacker to bypass file type restrictions and upload a server-executable file that can lead to Remote Code Execution (RCE). The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) with no authentication or user interaction required.

Created Date
Source IONIX Threat Lab
CVE-2026-13448 – Unauthenticated RCE via Incomplete Denylist – IBM Langflow OSS 1.0.0–1.10.1

CVE-2026-13448 is a high-severity unauthenticated remote code execution (RCE) vulnerability affecting IBM Langflow OSS versions 1.0.0 through 1.10.1. The flaw exists in the public flow build endpoint and allows a network-based attacker with no credentials to execute arbitrary code on the server. IBM has assigned a CVSS v3.1 base score of 8.1 (High) and recommends immediate upgrade to version 1.10.2.

Created Date
Source IONIX Threat Lab
CVE-2026-7872 – Arbitrary File Read / Authentication Bypass – IBM Langflow OSS 1.0.0–1.10.0

CVE-2026-7872 is a path traversal vulnerability (CWE-22) in IBM Langflow OSS versions 1.0.0 through 1.10.0, rated High (CVSS 7.5). By uploading a specially crafted tar archive, an attacker can read arbitrary files from the server — including the application's JWT signing key — enabling complete authentication bypass through forged tokens for any user, including administrators. IBM has released version 1.10.1 to remediate the flaw.

Created Date
Source IONIX Threat Lab
CVE-2026-9202 – Authentication Bypass Leading to RCE – Langflow OSS 1.0.0–1.10.0

CVE-2026-9202 is a critical authentication bypass and remote code execution vulnerability in IBM Langflow OSS versions 1.0.0 through 1.10.0. Unauthenticated attackers can exploit an open user registration endpoint to create arbitrary accounts; when the documented deployment option NEW_USER_IS_ACTIVE=true is configured, those accounts become immediately active and can be used to authenticate and reach RCE endpoints — bypassing any requirement for AUTO_LOGIN. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Threat Lab
CVE-2026-63306 – Unauthenticated SSRF – stoatchat (January proxy) before v0.13.5

CVE-2026-63306 is a critical, unauthenticated Server-Side Request Forgery (SSRF) vulnerability in stoatchat (formerly Revolt), an open-source self-hosted messaging platform. The flaw resides in the January metadata proxy service, whose /proxy and /embed endpoints accept arbitrary attacker-supplied URLs without DNS resolution filtering or private IP range validation, allowing any unauthenticated network attacker to pivot into the internal network of the host running stoatchat. The vulnerability carries a CVSS 4.0 score of 9.2 (Critical).

Created Date
Source IONIX Threat Lab
CVE-2026-46562 – Unauthenticated RCE via Unsandboxed JavaScript Engine – Yamcs Mission Control Fr…

CVE-2026-46562 is a critical (CVSS 9.8) unauthenticated Remote Code Execution vulnerability in Yamcs, an open-source mission control framework used for spacecraft command, control, and communication. The flaw resides in the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text, which was instantiated without a ClassFilter, allowing an attacker to invoke arbitrary Java classes and execute OS commands as the Yamcs process. In Yamcs's default configuration — where no security.yaml is present — the built-in guest user carries superuser=true privileges, making the vulnerability fully exploitable without any credentials.

Created Date
Source IONIX Threat Lab
CVE-2026-7488 – Sensitive Data Disclosure – IKAS Technology E-Commerce (through 03062026)

CVE-2026-7488 is a high-severity sensitive information disclosure vulnerability affecting IKAS Technology Inc.'s E-Commerce SaaS platform, classified under CWE-201 (Insertion of Sensitive Information Into Sent Data). With a CVSS v3.1 base score of 7.5 (HIGH), the flaw allows unauthenticated, remote attackers to retrieve embedded sensitive data from internet-exposed storefronts — requiring no privileges and no user interaction. The vulnerability was disclosed on July 17, 2026 via TR-CERT (Turkey's National Computer Emergency Response Center) under advisory TR-26-0572, and was discovered by security researcher Muhammed Taha YILMAZ.

Created Date
Source IONIX Threat Lab
CVE-2026-7189 – Unauthenticated Sensitive Data Disclosure and ACL Bypass – Proliz OBS before v3.6.0

CVE-2026-7189 is a high-severity vulnerability (CVSS 8.2) affecting Proliz Software Ltd. Co.'s OBS — a web-based Student Affairs Information System (Öğrenci Bilgi Sistemi) deployed across Turkish universities. The flaw involves the insertion of sensitive information into transmitted data (CWE-201), enabling unauthenticated remote attackers to access functionality not properly constrained by access control lists (ACLs).

Created Date
Source IONIX Threat Lab
CVE-2026-11961 – Unauthenticated Privilege Escalation – User Registration & Membership WordPress …

CVE-2026-11961 is a high-severity unauthenticated privilege escalation vulnerability in the User Registration & Membership WordPress plugin (by wpeverest), affecting all versions prior to 5.2.3. The flaw stems from missing server-side validation of the membership tier supplied at registration time, allowing any unauthenticated user to claim an arbitrary published membership role — including administrator — without restriction. With a CVSS v3.1 score of 8.1 (High), successful exploitation on a susceptible site can result in full WordPress site compromise.

WATCH A SHORT IONIX DEMO

See how easy it is to implement a CTEM program with IONIX. Find and fix exploits fast.

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge