What's hitting the radar right now. Mallory ranks every CVE by velocity across vendor advisories, researcher write-ups, social chatter, and the underground, then surfaces the ones worth your morning.
Ranked by Mallory's mention-velocity model across sources.
CVE-2026-107406
CVE-2026-107406 is a memory overflow vulnerability in SAML authentication processing in Citrix NetScaler ADC and NetScaler Gateway. Exploitation can permit remote execution of arbitrary code or denial of service. Exposure depends on the appliance build and its configured SAML role: specified newer affected builds require a SAML Identity Provider (IdP) configuration, while older affected builds are vulnerable as either a SAML Service Provider (SP) or IdP. Secure Private Access Hybrid deployments using affected NetScaler instances are also exposed. The specific vulnerable function and underlying buffer have not been publicly identified.
CVE-2026-21589
CVE-2026-21589 is a path traversal vulnerability in the shared atlassian-plugins-webresource component affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye self-managed deployments. Vulnerable resource routing converts double-colon sequences into forward slashes during request processing, allowing crafted resource paths to bypass path validation and retrieve normally protected files within the application's web root. Exploitation requires no authentication or user interaction, but the attacker must know the exact target filename and path. The vulnerability does not provide directory enumeration or unrestricted operating-system file access.
CVE-2026-88771
CVE-2026-88771 is an improper input validation vulnerability in Citrix NetScaler ADC and NetScaler Gateway that permits unauthenticated remote command execution as root. Attacker-controlled login fields and User-Agent headers are recorded in appliance logs and subsequently processed without adequate sanitization by the admautoregd daemon. Crafted log entries inject shell commands into the daemon's processing chain. Affected releases include ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, ADC 14.1-FIPS before 14.1-73.37 FIPS, and ADC 13.1-FIPS and 13.1-NDcPP before 13.1.37.279. Default configurations are vulnerable; no additional feature must be enabled. Exploitation was observed before disclosure on September 27, 2026.
CVE-2026-88779
CVE-2026-88779 is a memory-overflow vulnerability in SAML processing in customer-managed NetScaler ADC and NetScaler Gateway appliances configured as a SAML service provider or identity provider. Specially crafted unauthenticated network requests can crash authentication services or the appliance, causing denial of service. Affected releases are ADC and Gateway 14.1 before 14.1-73.41 and 13.1 before 13.1-64.28, ADC 14.1-FIPS before 14.1-73.41 FIPS, and ADC 13.1-FIPS and 13.1-NDcPP before 13.1-37.282. Relevant Secure Private Access Hybrid deployments are also affected. The vulnerability was exploited before fixes became available. Remote code execution has not been established; watchTowr's reproduction characterized the flaw as crash-only.
CVE-2015-3306
CVE-2015-3306 is a critical vulnerability in the mod_copy module of ProFTPD 1.3.5, which allows remote, unauthenticated attackers to read from and write to arbitrary files on the server using the SITE CPFR and SITE CPTO FTP commands. This flaw enables attackers to copy sensitive files (e.g., /etc/passwd) or inject malicious scripts into web-accessible directories, leading to potential privilege escalation or remote code execution.
CVE-2021-3199
A directory traversal vulnerability exists in ONLYOFFICE Document Server before version 5.6.3, specifically in the /upload endpoint when JWT authentication is enabled. The vulnerability is triggered by supplying a /.. sequence in an image upload parameter, allowing an attacker to traverse directories and potentially achieve remote code execution.
CVE-2016-3081
CVE-2016-3081 (S2-032) is an OGNL expression-injection vulnerability in Apache Struts 2 action invocation when Dynamic Method Invocation (DMI) is enabled. A user-controlled value accepted through the method: prefix can reach the action invocation path and be evaluated as an OGNL expression rather than being treated solely as an action-method identifier. The vulnerable flow evaluates an expression derived from the supplied method name, permitting a crafted chained expression to invoke attacker-selected Java functionality and execute arbitrary code. Vendor-listed affected releases are Struts 2.3.19 through 2.3.20.2, 2.3.21 through 2.3.24.1, and 2.3.25 through 2.3.28.
CVE-2015-5477
CVE-2015-5477 is a remotely triggerable denial-of-service vulnerability in the named daemon of ISC BIND, affecting BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3. Improper handling of a specially crafted TKEY query triggers a REQUIRE assertion failure and terminates the daemon. Both recursive and authoritative DNS servers are affected.
CVE-2026-88772
CVE-2026-88772 is a memory-overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway affecting appliances with Datagram Transport Layer Security (DTLS) enabled. The affected component is identified as the NSPPE DTLS handler, which is reachable over the network before authentication. Exploitation can cause remote code execution or denial of service. DTLS is enabled by default on VPN virtual servers. Affected releases include standard ADC and Gateway builds before 14.1-73.37 or 13.1-64.23, ADC 14.1-FIPS builds before 14.1-73.37 FIPS, and ADC 13.1-FIPS and 13.1-NDcPP builds before 13.1-37.279. The vulnerability has been actively exploited, including before public patch availability.
CVE-2023-22894
Strapi through version 4.5.5 permits authenticated administrative-panel users to use query filters against private or sensitive user-model fields. Response behavior can be used as an oracle to infer values held in those fields, despite the fields not being intended for disclosure. A super administrator can infer password hashes and password-reset tokens for administrative and API users. An administrator with access to lower-privileged API-user usernames and email addresses can infer sensitive data for those API users, but not for other administrative accounts.
CVE-2026-16823
CVE-2026-16823 is an improper-authentication vulnerability affecting IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3. A remote attacker could exploit the flaw to bypass security restrictions. The affected authentication function and specific bypass mechanism are not identified.
CVE-2026-47483
CVE-2026-47483 is an uncontrolled resource consumption vulnerability in NVIDIA DCGM Exporter's pprof diagnostic endpoints across all platforms. Missing rate limiting and access controls allow unauthenticated attackers to submit concurrent profiling requests that exhaust CPU, memory, and file descriptors. Exploitation can make the exporter unresponsive or crash it and may disclose internal profiling information.
CVE-2026-84244
CVE-2026-84244 is a stored cross-site scripting vulnerability in the Quick Search results grid of IBM Guardium Data Protection 12.2. An attacker who can influence monitored database traffic can inject malicious script that executes when an authenticated Guardium user views affected results. The attacker does not need to authenticate to Guardium.
CVE-2026-105134
CVE-2026-105134 is an operating system command injection vulnerability in the Replication Receiver component of AhsayCBS versions up to and including 10.3.2. The affected API inadequately sanitizes the random parameter before incorporating it into a system-level command. Remote attackers can submit a crafted HTTP request to execute arbitrary commands with the privileges of the AhsayCBS service account, without authentication or user interaction. Exploitation on Windows hosts has been reported to yield NT AUTHORITY/SYSTEM execution. Public exploit code is available, and AhsayCBS 10.3.4 fixes the vulnerability.
CVE-2026-16916
CVE-2026-16916 is a protection mechanism failure affecting IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3, including their Container variants. A remote authenticated attacker could exploit the failure to execute arbitrary code on an affected system. The vulnerable function and the specific protection mechanism are not identified.
CVE-2026-78406
CVE-2026-78406 is an untrusted-data deserialization vulnerability affecting IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3. Deserialization of attacker-controlled data could allow a remote, unauthenticated attacker to execute arbitrary code on the affected system. The specific vulnerable function is not identified.
CVE-2026-105133
CVE-2026-105133 is an improper authentication vulnerability in the checkSysPwd function of the AhsayCBS API component. Improper validation of the random argument allows remote attackers to bypass authentication controls and access protected API functionality. AhsayCBS versions through 10.3.2 are affected. Reports conflict on whether version 10.3.4 fixes the vulnerability. Public exploit code is available, and attackers have exploited the flaw in combination with CVE-2026-105134.
CVE-2026-84272
CVE-2026-84272 is a missing-authentication vulnerability in the edge-controller component of IBM Guardium Data Protection versions 12.1 and 12.2.2. An unauthenticated remote attacker can exploit the flaw to execute arbitrary container images and gain control of managed edge clusters.
CVE-2026-79842
CVE-2026-79842 is a remote authentication bypass vulnerability affecting HPE Intelligent Management Center (iMC) versions prior to 7.3 E0713. An unauthenticated attacker can bypass authentication without user interaction. The affected function and underlying implementation flaw have not been specified.
CVE-2026-88131
CVE-2026-88131 is an untrusted-data deserialization vulnerability in Microsoft Dataverse, an exclusively hosted service. It allows an unauthenticated attacker to execute code over a network without user interaction. The affected deserialization function and specific affected versions are not identified. Microsoft has completed service-side remediation.
CVE-2026-102255
CVE-2026-102255 is a pre-authentication server-side request forgery vulnerability in the SonicWall SMA1000 Appliance WorkPlace interface. An unintended alternate access path allows the appliance to act as a forward proxy, potentially enabling remote unauthenticated attackers to issue requests through it, reach protected internal functionality, and perform unauthorized operations. Affected models include SMA 6210, SMA 7210, and SMA 8200v running platform-hotfix 12.4.3-03526 or earlier in the 12.4.3 branch, or 12.5.0-02952 or earlier in the 12.5.0 branch. SonicWall firewall SSL-VPN functionality and SMA 100 Series products are unaffected.
CVE-2026-78401
CVE-2026-78401 is an untrusted-data deserialization vulnerability affecting IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3. A remote, unauthenticated attacker could exploit the vulnerability to execute arbitrary code on the affected system. The vulnerable function and specific input interface are not identified.
CVE-2026-9209
mJobTime through build 15.7.3.32 exposes administrative login handlers that execute caller-supplied SQL without server-side authentication. The runQueryButton postback and exportSqlQuery_Server PageMethod rely on a client-side sessionStorage flag and execute queries against the backing Sybase SQL Anywhere database with DBA/sysadmin privileges. An unauthenticated attacker can invoke xp_cmdshell and xp_read_file, enabling remote code execution as LocalSystem through a single HTTP request.
CVE-2026-19491
CVE-2026-19491 is an improper authentication vulnerability in IBM Security Verify Access versions 10.0 through 10.0.9.2 and IBM Verify Identity Access versions 11.0 through 11.0.3, including their Container variants. A remote attacker can bypass authentication without logging in. The specific vulnerable function, triggering input, and scope of access obtained through the bypass have not been disclosed.