CVE-2026-59506
: Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions
CVSS
9.3
Crítico
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Publicado: 13 ago 2026 · Última mod.: 28 ago 2026 · CWE-306
0.3%EPSS · 30 días0.4%
2026-08-132026-09-06
: Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-19397——
———Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session.
Refer to the '
Security Update for ASUS Control Center Express Agent ' section on the ASUS Security Advisory for more information.8hCVE-2026-865439.8 CRÍ—
———knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.12hCVE-2026-865065.9 MED—
———In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data18hCVE-2026-865028.4 ALT—
———In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts18hCVE-2026-864863.7 BAJ—
———In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank18hCVE-2026-864809.8 CRÍ—
———In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges18h