CVE-2026-16365
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153, Thunderbird 153, Firefox ESR 140.15, and Th
CVSS
8.8
Alto
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Publicado: 21 jul 2026 · Última mod.: 1 sept 2026 · CWE-269 · CWE-284
0.3%EPSS · 30 días0.3%
2026-08-072026-09-04
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 153, Thunderbird 153, Firefox ESR 140.15, and Thunderbird 140.15.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2049149
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-68/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-71/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-84/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-87/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-86195——
———grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. A non-super user manager with api.access and api.users.write permissions can create an invitation with a dot-keyed super flag in the access payload that bypasses the guard and persists to the new account. Attackers can accept the invitation through the public endpoint without real invitee interaction to create a super-admin account and immediately receive a valid JWT for full site control.11hCVE-2026-815438.8 ALT—
——0The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capability checks and nonce verification on multiple AJAX actions including wcap_save_connector_settings, wcap_send_manual_email, wcap_abandoned_cart_info, and wcap_change_manual_email_data. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify SMTP connector settings to route administrator recovery emails through an attacker-controlled server and intercept auto-login links to gain full administrative access. The plugin's auto-login feature must be enabled, which is the default configuration.16hCVE-2026-751686.3 MED—
——0An issue in the ugw-editfile method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated user with the low-privileged Standard role to write arbitrary content to files within /uxx/config/ and /ugw/config/.1dCVE-2026-751609.1 CRÍ—
——0An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.1dCVE-2026-192749.6 CRÍ—
——0IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlled namespace to silently overwrite the shared `ClusterRoleBinding` or delete it outright and revoke the victim agent's cluster monitoring access.1dCVE-2026-91866.5 MED—
——0IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.).1d