Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

IONIX THREAT CENTER

A free, curated feed of CVEs that can be remotely exploited by an unauthenticated attacker, verified and published the moment they emerge. No noise, no triage backlog. Just the exploitable vulnerabilities that actually demand your attention, delivered in real time.

Be the first to know when new zero-days emerge:

Created Date
Source IONIX Threat Lab
CVE-2026-68771 – Unauthenticated RCE via Pickle Deserialization – ComfyUI ≤ v0.23.0

CVE-2026-68771 is a critical unauthenticated remote code execution (RCE) vulnerability affecting ComfyUI v0.23.0 and all earlier versions, stemming from unsafe pickle deserialization in the LoadTrainingDataset built-in node (CWE-502). With a CVSS 4.0 score of 9.3 (CRITICAL) and no authentication, user interaction, or special conditions required, any attacker with network access to an exposed ComfyUI instance can achieve full arbitrary code execution on the host server.

Created Date
Source IONIX Threat Lab
CVE-2026-14930 – Unauthenticated File Upload to Arbitrary Support Tickets – JS Help Desk WordPres…

CVE-2026-14930 is a Missing Authorization (CWE-862) vulnerability in the JS Help Desk WordPress plugin (all versions before 3.1.4), rated High severity with a CVSS v3.1 score of 7.5. The plugin's front-end request dispatcher performs no authorization check, nonce validation, or ticket ownership verification, enabling fully unauthenticated remote attackers to upload files and attach them to any user's support ticket on an affected site. With over 7,000 active installations, the potential scope of exposure is meaningful for organizations relying on the plugin for customer support operations.

Created Date
Source IONIX Threat Lab
CVE-2026-28814 – Unauthenticated Sensitive Data Disclosure – Apache JSPWiki up to 2.12.3

CVE-2026-28814 is a high-severity information disclosure vulnerability in Apache JSPWiki affecting all versions up to and including 2.12.3. Due to missing authentication on critical wiki markup rendering functionality (CWE-306), unauthenticated remote attackers can render arbitrary wiki markup and obtain sensitive data stored in JSPWiki variables. The vulnerability carries a CVSS v3.1 score of 7.5 (HIGH) and requires no credentials or user interaction to exploit.

Created Date
Source IONIX Threat Lab
CVE-2026-12251 – Unauthenticated Privilege Escalation – Ultimate Member WordPress Plugin before 2…

CVE-2026-12251 is a high-severity improper privilege management vulnerability (CWE-269) in the Ultimate Member WordPress plugin, affecting all versions prior to 2.12.1. The flaw allows unauthenticated remote attackers to register on a vulnerable site using a custom role that carries administrator-level capabilities, resulting in full administrative takeover of the affected WordPress installation. With over 200,000 active installs, this vulnerability represents significant exposure across the WordPress ecosystem.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-56671 – Unauthenticated Path Traversal / Arbitrary File Read – ComfyUI before 0.28.0

CVE-2026-56671 is an unauthenticated path traversal vulnerability in ComfyUI, the modular diffusion-model GUI, API, and backend from Comfy-Org. The flaw resides in the get_model_preview function and allows a remote attacker to read arbitrary image-decodable files and enumerate host paths without authentication. It affects all ComfyUI versions prior to 0.28.0 and is rated High (CVSS 7.5).

Created Date
Source IONIX Threat Lab
CVE-2026-28812 – Privilege Escalation via User Impersonation – Apache JSPWiki up to 2.12.3

CVE-2026-28812 is a critical privilege escalation vulnerability in Apache JSPWiki affecting all versions up to and including 2.12.3. The flaw resides in the UserManager component, which fails to sanity-check the user database at application startup — classified as CWE-290 (Authentication Bypass by Spoofing) — enabling unauthenticated network attackers to impersonate legitimate users and escalate their privileges. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and requires no credentials or user interaction to exploit.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-43832 – Unauthenticated Remote Code Execution – Advantech ADAM-3600 EdgeLink versions prior

CVE-2026-43832 is a stack-based buffer overflow in the Advantech ADAM-3600 EdgeLink remote terminal unit that allows an unauthenticated attacker to execute arbitrary code. The flaw resides in the device's HTTP Cookie parsing routines and is reachable over the network when the SafeEnhancement feature is enabled. It affects EdgeLink versions prior to 2.8.5.1 and is rated critical severity.

Created Date
Source IONIX Threat Lab
CVE-2026-63223 – RCE via File Upload Validation Bypass – CodeIgniter4 < 4.7.4

CVE-2026-63223 is a critical Remote Code Execution (RCE) vulnerability in CodeIgniter4, a PHP full-stack web framework, affecting all versions prior to 4.7.4. The flaw resides in the is_image and mime_in upload validation rules, which classify uploaded files solely by content-derived MIME type without independently verifying the client-supplied filename extension. An unauthenticated remote attacker who can upload files to a vulnerable application may achieve arbitrary code execution on the underlying server.

Created Date
Source IONIX Threat Lab
CVE-2026-63222 – Path Traversal to Arbitrary File Write / RCE – CodeIgniter4 prior to v4.7.4

CVE-2026-63222 is a high-severity path traversal vulnerability in CodeIgniter4, a widely-used PHP full-stack web framework. The flaw resides in the UploadedFile::move() method, which — when invoked without a second argument — passes the client-supplied filename directly to the filesystem without sanitization, allowing a remote unauthenticated attacker to write uploaded content to arbitrary locations on the server. With a CVSS v3.1 base score of 7.5 (High), the vulnerability is exploitable over the network with no authentication or user interaction required, and can result in remote code execution (RCE) if a malicious…

Created Date
Source IONIX Threat Lab
CVE-2026-63221 – SQL Injection in Query Builder deleteBatch() – CodeIgniter4 4.3.0–4.7.3

CVE-2026-63221 is a critical SQL injection vulnerability (CVSS 9.4) in the Query Builder deleteBatch() method of the CodeIgniter4 PHP web framework, affecting all versions from 4.3.0 through 4.7.3. The flaw arises because deleteBatch() substitutes bound values from where() conditions directly into generated SQL while ignoring their escape flags, allowing user-controlled input to be interpreted as raw SQL. The issue was addressed in CodeIgniter4 version 4.7.4, released July 7, 2026.

Created Date
Source IONIX Threat Lab
CVE-2026-14541 – Authentication Bypass – Google MCP Toolbox for Databases v1.4.0

CVE-2026-14541 is an authentication bypass and audience confusion vulnerability in the Google OAuth provider component of Google MCP Toolbox for Databases version 1.4.0. When the Google authService is configured with mcpEnabled: true but no explicit audience or clientId is defined, the token validation pipeline skips audience verification entirely, allowing any valid Google OAuth access token — regardless of its intended audience or application — to be accepted by the server. This vulnerability carries a CVSS 4.0 score of 8.0 (High) and is exploitable remotely with no privileges required.

Created Date
Source IONIX Threat Lab
CVE-2026-14540 – SSRF – Google MCP Toolbox for Databases versions 0.3.0 through 1.4.0

CVE-2026-14540 is a Server-Side Request Forgery (SSRF) vulnerability in Google MCP Toolbox for Databases affecting versions 0.3.0 through 1.4.0. The flaw resides in the toolbox's generic HTTP source and tool components, where the internal HTTP client is initialized without redirect controls or target IP validation, allowing an unauthenticated remote attacker to coerce the server into issuing unauthorized HTTP requests to internal network resources or cloud metadata services. This vulnerability carries a CVSS 4.0 score of 8.0 (High) and requires no privileges or user interaction to exploit.

Created Date
Source IONIX Threat Lab
CVE-2026-14537 – Authorization Bypass – Google MCP Toolbox for Databases v1.3.0 and v1.4.0

CVE-2026-14537 is an Incorrect Authorization vulnerability (CWE-863) in Google MCP Toolbox for Databases versions v1.3.0 and v1.4.0. An unauthenticated remote attacker can invoke tools protected by the scopeRequired authorization feature by routing tool invocation requests through legacy HTTP endpoints when the –enable-api flag is active, completely bypassing the intended access controls. With a CVSS 4.0 score of 8.1 (High) and high impact on confidentiality, integrity, and availability, this flaw poses a direct risk to any database system connected to an exposed toolbox instance.

Created Date
Source IONIX Threat Lab
CVE-2026-66421 – Stored XSS / Session Token Theft – OpenClaw Dashboard v1.1.0 and later

CVE-2026-66421 is a stored cross-site scripting (XSS) vulnerability in OpenClaw Dashboard (openclaw-dashboard by tugcantopaloglu), a web-based monitoring and management interface for OpenClaw AI agents. An unauthenticated remote attacker can inject arbitrary HTML and JavaScript into agent transcript messages via the sessions API; the payload is stored server-side and executes automatically in the administrator's browser the next time the default dashboard landing page loads. The vulnerability carries a CVSS v3.1 score of 9.3 (Critical) and no vendor patch has been released as of the date of this advisory.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-68500 – Payment Status Forgery (Authorization Bypass) – Sylius Mollie Plugin < 2.2.8, 3.2.0

CVE-2026-68500 is an authorization bypass (payment status forgery) vulnerability in the Sylius Mollie Plugin. The plugin's payment webhook accepts attacker-controlled id and orderId parameters without verifying that the referenced Mollie payment belongs to the referenced Sylius order, allowing an unauthenticated attacker to mark arbitrary orders as paid. It carries a CVSS v3.1 base score of 7.5 (High).

Created Date
Source IONIX Threat Lab
CVE-2026-13395 – Unauthenticated SQL Injection – Bookly WordPress Plugin before 27.8

CVE-2026-13395 is a high-severity unauthenticated SQL injection vulnerability in the Bookly (Online Scheduling and Appointment Booking System) WordPress plugin, affecting all versions before 27.8. The flaw enables any anonymous, network-based attacker to inject malicious SQL via the public-facing booking form and extract sensitive data — including WordPress user password hashes — directly from the underlying database. With over 60,000 active installations, internet-exposed sites running the unpatched plugin represent a significant attack surface.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-13178 – Authorization Bypass (Unauthenticated Fraudulent Paid Orders) – Eventin WordPress P

CVE-2026-13178 is an authorization bypass (CWE-639, Authorization Bypass Through User-Controlled Key) in the Eventin (WP Event Solution) WordPress plugin. The plugin does not properly authorize order creation and accepts an attacker-supplied order status, allowing unauthenticated attackers to create orders marked as completed without paying. It affects all versions before 4.1.16 and is rated High severity (CVSS 7.5).

Created Date
Source IONIX Threat Lab
CVE-2026-12942 – Directory Traversal / Arbitrary File Read – IBM Langflow OSS 1.0.0–1.10.1

CVE-2026-12942 is a path traversal vulnerability (CWE-22) in IBM Langflow OSS versions 1.0.0 through 1.10.1, rated High severity (CVSS 7.5). An unauthenticated remote attacker can send specially crafted URL requests containing dot-dot sequences (/../) to unauthenticated API endpoints, enabling arbitrary file reads on the underlying server. IBM has released a patched version (1.10.2) and recommends immediate upgrade.

Created Date
Source IONIX Threat Lab
CVE-2026-12940 – Unauthenticated RCE – IBM Langflow OSS 1.0.0–1.10.1

CVE-2026-12940 is a critical unauthenticated remote code execution (RCE) vulnerability affecting IBM Langflow OSS versions 1.0.0 through 1.10.1. The flaw resides in the Model Context Protocol (MCP) stdio launcher, where an incomplete blocklist of dangerous environment variables allows a remote, unauthenticated attacker to inject OS commands and execute arbitrary code on the host. It carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-22620 – Authentication Bypass (SQL Injection) – Eaton Tripp Lite series PADM firmware versi

CVE-2026-22620 is an authentication bypass vulnerability, rooted in SQL injection (CWE-89), in Eaton's Tripp Lite series PowerAlert Device Manager (PADM) firmware. Improper input validation in the authentication component lets an unauthenticated remote attacker bypass authentication and obtain privileged user access to the device. It is rated HIGH severity (CVSS 8.6).

Created Date
Source IONIX Threat Lab
CVE-2026-28323 – Authentication Bypass – SolarWinds Web Help Desk 2026.1 and earlier

CVE-2026-28323 is a critical SAML authentication bypass vulnerability in SolarWinds Web Help Desk, affecting all versions up to and including 2026.1. Carrying a CVSS score of 9.8 (Critical), the flaw allows an unauthenticated, remote attacker to bypass authentication controls entirely — requiring no privileges and no user interaction — when the SAML 2.0 authentication method is enabled. SolarWinds has released a patched version and advises immediate upgrade.

Created Date
Source IONIX Threat Lab
CVE-2026-14300 – Authentication Bypass – miniOrange Social Login and Register WordPress Plugin be…

CVE-2026-14300 is a high-severity authentication bypass vulnerability (CWE-287) in the miniOrange Social Login and Register WordPress plugin (Discord, Google, Twitter, LinkedIn) affecting all versions before 7.8.0. An unauthenticated attacker can hijack any account on an affected site — including administrator accounts — by obtaining a one-time verification code for an email address they control and replaying it against a victim's email address, because the plugin fails to bind the code to the account for which it was issued. The CVSS v3.1 base score is 8.1 (HIGH).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-18363 – Password Reset Token Expiry Bypass / Account Takeover – osTicket before 1.17.8 and

CVE-2026-18363 is a weak password recovery vulnerability (CWE-640) in osTicket, the open-source support ticketing system by Enhancesoft. A logic flaw in the password reset token validation routine lets a remote, unauthenticated attacker bypass token expiry checks and perform unauthorized password resets, leading to account takeover. It carries a CVSS 4.0 base score of 9.1 (Critical).

Created Date
Source IONIX Threat Lab
CVE-2026-12687 – Unauthenticated Privilege Escalation to Administrator – ProfileGrid WordPress Pl…

CVE-2026-12687 is a high-severity improper privilege management vulnerability (CWE-269) in the ProfileGrid – User Profiles, Groups and Communities WordPress plugin, developed by Metagauss, affecting all versions before 5.9.9.8. The flaw allows unauthenticated remote attackers to register directly into any group — including groups configured with the WordPress Administrator role — through the plugin's front-end registration form, bypassing all group access restrictions. On sites where an Administrator-level group exists, this results in full unauthenticated privilege escalation to WordPress Administrator.

Created Date
Source IONIX Threat Lab
CVE-2026-58066 – Authentication Bypass – Rocket.Chat SAML SSO before 8.7.0

CVE-2026-58066 is a critical SAML XML Signature Wrapping (XSW) authentication bypass vulnerability in Rocket.Chat's SSO implementation, affecting all versions before 8.7.0 and multiple prior stable branches. With a CVSS score of 9.8 (Critical), an unauthenticated remote attacker can craft a malicious SAML document to forge identity attributes and authenticate as any arbitrary user — including administrators — without valid credentials. Rocket.Chat has released patched versions across all affected branches.

Created Date
Source IONIX Threat Lab
CVE-2026-59309 – Authentication Bypass – VMware vCenter Server 8.0, 9.0.x, 9.1.x

CVE-2026-59309 is a critical authentication bypass vulnerability in the VMware Directory Service component of VMware vCenter Server, disclosed by Broadcom on July 29, 2026 as part of advisory VMSA-2026-0006. With a CVSS score of 9.8, a malicious actor with only network access to vCenter can bypass authentication entirely and gain unauthorized access to the system — no credentials, no user interaction, and no elevated privileges required. Broadcom lists no workarounds; patching is the only remediation.

Created Date
Source IONIX Threat Lab
CVE-2026-17543 – SQL Injection – PHP 8.2.x / 8.3.x / 8.4.x / 8.5.x (pgsql Extension)

CVE-2026-17543 is a high-severity SQL injection vulnerability in PHP's ext-pgsql extension, affecting PHP versions 8.2.x before 8.2.33, 8.3.x before 8.3.33, 8.4.x before 8.4.24, and 8.5.x before 8.5.9. The flaw resides in the PHP language runtime itself — not in application-level code — meaning applications that rely on PHP's built-in PostgreSQL escape functions as their primary SQL injection defense are silently exposed. With a CVSS 4.0 score of 8.1, this vulnerability is exploitable remotely without authentication, and the official advisory characterizes exploitation as trivial.

Created Date
Source IONIX Threat Lab
CVE-2026-17544 – Out-of-Bounds Write / Potential RCE – PHP BCMath Extension (8.4.x before 8.4.24,…

CVE-2026-17544 is a high-severity out-of-bounds write vulnerability (CWE-787 / CWE-121) in the BCMath extension of PHP, affecting versions 8.4.x before 8.4.24 and 8.5.x before 8.5.9. The flaw is reachable via the bccomp() function when supplied with attacker-controlled operands and a scale parameter, and can result in stack or heap memory corruption with potential for Remote Code Execution. It carries a CVSS v4.0 base score of 8.1 (HIGH) with no privileges or user interaction required.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-59243 – Authentication Bypass (JWT Signature Verification Disabled) – Apache Airflow FAB pr

CVE-2026-59243 is a critical authentication bypass in the Apache Airflow FAB (Flask-AppBuilder) authentication manager. In the Azure AD OAuth login path, JWT signature verification was disabled by default, allowing an unauthenticated attacker to present forged or unsigned ID tokens and impersonate arbitrary users, including administrators. It carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-16610 – Unauthenticated Remote Code Execution – Admin and Site Enhancements (ASE) Pro ≤ 8.9

CVE-2026-16610 is a critical unauthenticated remote code execution vulnerability in the Admin and Site Enhancements (ASE) Pro plugin for WordPress, affecting all versions up to and including 8.9.0. A publicly accessible save handler lacks authentication checks and passes attacker-controlled input into a PHP eval() call, allowing an unauthenticated attacker to execute arbitrary code. It carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-54735 – Server-Side Request Forgery (SSRF) – Prebid Server before v4.4.0

CVE-2026-54735 is a critical server-side request forgery (SSRF) vulnerability in Prebid Server, the open-source header-bidding server maintained by the Prebid project. Certain bidder adapters interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values, allowing an unauthenticated attacker to redirect server-initiated requests to unintended destinations. The issue carries a CVSS v3.1 base score of 10.0 (Critical).

Created Date
Source IONIX Threat Lab
CVE-2026-41939 – Hard-coded Credentials leading to RCE – Care Everywhere Gateway 14.x

CVE-2026-41939 is a critical hard-coded credentials vulnerability (CWE-1392) in Care Everywhere Gateway 14.3.10, a healthcare interoperability gateway product from Care Everywhere LLC. The flaw resides in the bundled WildFly 8.2.0.Final application server management interface, which ships with credentials that are identical across all product installations — enabling any unauthenticated remote attacker to log into the management console and achieve full remote code execution (RCE). The vulnerability carries a CVSS v3.1 score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-13423 – Unauthenticated Remote Code Execution – Streamit WordPress theme through 4.5.0

CVE-2026-13423 is a critical, unauthenticated code injection (CWE-94) vulnerability in the Streamit WordPress theme through version 4.5.0. An unprotected AJAX route invokes an attacker-supplied PHP function with attacker-controlled arguments, allowing remote, unauthenticated attackers to achieve privilege escalation and remote code execution. It carries a CVSS v3.1 base score of 9.8 (Critical).

WATCH A SHORT IONIX DEMO

See how easy it is to implement a CTEM program with IONIX. Find and fix exploits fast.

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge