CVE-2026-21555
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges
CVSS
7.5
Alto
EPSS
0.4%
p34
KEV
—
Exploit Today
10
0-100
Publicado: 3 ago 2026 · Última mod.: 28 ago 2026 · CWE-20
0.4%EPSS · 30 días0.4%
2026-08-252026-09-23
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-95843——
——0Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} structure. A remote client can send a filter such as $share/grp without a topic-filter portion, causing a StringIndexOutOfBoundsException while calculating the share name. The exception terminates command handling on the shared session event loop and can deny service to other client sessions assigned to that loop. This issue is fixed in version 0.18.1.3hCVE-2026-629984.3 MED—
——0REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortable() registered the requested column. An authenticated backend user can make prepareQuery() add an escaped but unauthorized ORDER BY identifier, allowing error-based enumeration of columns in joined tables and ordering by unselected sensitive fields such as rex_user.password. This issue is fixed in version 5.21.2.3hCVE-2026-866838.1 ALT—
——0ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.3hCVE-2026-866797.1 ALT—
——0ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.3hCVE-2026-769807.4 ALT—
——0ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.3hCVE-2026-870715.3 MED—
——0The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply, and does not exclude the keys WordPress reserves for its own use, so unauthenticated visitors submitting a public form that collects post content can attach metadata of their choosing to the post their submission creates.3h