Mohamed ElHawary

DCR / 2026-09-01

Daily CVE Report

2026-08-31 to 2026-09-01 / generated Sep 1, 2026, 07:54 AM UTC

Priority window

50 advisories50 critical / 0 high / 0 KEV
50visible
50critical
0CISA KEV
1633eligible before cap
50max results

Threat queue

Priority advisories

50 of 50
#1CVE-2026-78319CVE-2026-78319TargetNot specifiedPatchedUnknownCVSS 9.3critical

CVE-2026-78319

A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this race condition to bypass intended security controls. This may result in the execution of unauthorized code.

CVSS 9.3
Software Type
Not specified
Software Slug
Not specified
Patched?
Unknown
Remediation
Review the linked source details and apply mitigations based on your organization's risk tolerance.
Published Sep 1, 2026, 07:16 AM UTCModified Sep 1, 2026, 07:16 AM UTC
#2CVE-2026-75865The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode...TargetNot specifiedPatchedUnknownCVSS 9.8critical

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode...

The WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints in all versions up to, and including, 4.4.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS 9.8
Software Type
Not specified
Software Slug
Not specified
Patched?
Unknown
Remediation
Review the linked source details and apply mitigations based on your organization's risk tolerance.
Published Sep 1, 2026, 03:16 AM UTCModified Sep 1, 2026, 03:31 AM UTC
#3CVE-2026-67394A critical local privilege escalation via OS command injection vulnerability has been discovered...Targetaffecting all versions from 18.0.34 < 18.0.79.9PatchedNo known patchCVSS 9critical

A critical local privilege escalation via OS command injection vulnerability has been discovered...

A critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions from 18.0.34 before 18.0.79.9 and 18.0.80.5. The vulnerability allows a customer or reseller with shell access (or allowed to change their own shell access) to elevate privileges to the root account on the hosting server.

CVSS 9
Software Type
Application
Software Slug
affecting all versions from 18.0.34 < 18.0.79.9
Patched?
No known patch
Remediation
No known patch available in the source data. Review the vulnerability details in depth and apply mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Published Sep 1, 2026, 03:16 AM UTCModified Sep 1, 2026, 03:31 AM UTC
#4CVE-2026-82971A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown...TargetNot specifiedPatchedUnknownCVSS 9.3critical

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown...

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects products that are no longer supported by the maintainer.

CVSS 9.3
Software Type
Not specified
Software Slug
Not specified
Patched?
Unknown
Remediation
Review the linked source details and apply mitigations based on your organization's risk tolerance.
Published Aug 31, 2026, 11:16 PM UTCModified Sep 1, 2026, 12:31 AM UTC
#5CVE-2026-82226Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.TargetUnauthenticated PHP Object Injection in Tickera <= 3.6.0.2PatchedNo known patchCVSS 9.8critical

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

CVSS 9.8
Software Type
Application
Software Slug
Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2
Patched?
No known patch
Remediation
No known patch available in the source data. Review the vulnerability details in depth and apply mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Published Aug 31, 2026, 09:17 PM UTCModified Aug 31, 2026, 09:32 PM UTC
#6CVE-2026-81780Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.TargetUnauthenticated Arbitrary File Upload in Hash Form <= 1.4.2PatchedNo known patchCVSS 10critical

Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

CVSS 10
Software Type
Application
Software Slug
Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2
Patched?
No known patch
Remediation
No known patch available in the source data. Review the vulnerability details in depth and apply mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Published Aug 31, 2026, 09:17 PM UTCModified Aug 31, 2026, 09:32 PM UTC
#7CVE-2026-81779Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X...Targetin Silk Themes Newspapers X <= 1.0.48.PatchedNo known patchCVSS 10critical

Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X...

Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.

CVSS 10
Software Type
Application
Software Slug
in Silk Themes Newspapers X <= 1.0.48.
Patched?
No known patch
Remediation
No known patch available in the source data. Review the vulnerability details in depth and apply mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Published Aug 31, 2026, 09:17 PM UTCModified Aug 31, 2026, 09:32 PM UTC
#8CVE-2026-81763Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.TargetUnauthenticated SQL Injection in Throws SPAM Away <= 3.8.2PatchedNo known patchCVSS 9.3critical

Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

CVSS 9.3
Software Type
Application
Software Slug
Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2
Patched?
No known patch
Remediation
No known patch available in the source data. Review the vulnerability details in depth and apply mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Published Aug 31, 2026, 09:17 PM UTCModified Aug 31, 2026, 09:32 PM UTC
#9CVE-2026-81756Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.TargetUnauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24PatchedNo known patchCVSS 9.3critical

Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

CVSS 9.3
Software Type
Application
Software Slug
Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24
Patched?
No known patch
Remediation
No known patch available in the source data. Review the vulnerability details in depth and apply mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Published Aug 31, 2026, 09:17 PM UTCModified Aug 31, 2026, 09:32 PM UTC
#10CVE-2026-81293Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.TargetUnauthenticated SQL Injection in WP Data Access <= 5.5.81PatchedNo known patchCVSS 9.3critical

Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

CVSS 9.3
Software Type
Application
Software Slug
Unauthenticated SQL Injection in WP Data Access <= 5.5.81
Patched?
No known patch
Remediation
No known patch available in the source data. Review the vulnerability details in depth and apply mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Published Aug 31, 2026, 09:17 PM UTCModified Aug 31, 2026, 09:32 PM UTC
Showing 10 of 50
Load more
Daily CVE Report 2026-09-01 | Mohawary