Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation.
The vulnerability, tracked as CVE-2026-20245, carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the following deployment types -
On-Prem Deployment
Cisco SD-WAN Cloud-Pro
Cisco SD-WAN Cloud (Cisco Managed)
Cisco SD-WAN for Government (FedRAMP)
"A
Currently trending CVE - Hype Score: 1 - A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code ...
A vulnerability marked as problematic has been reported in shopperlabs shopper up to 2.7.x. The affected element is an unknown function of the component Sub-form Livewire. Performing a manipulation results in missing authorization.
This vulnerability is cataloged as CVE-2026-47742. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability identified as problematic has been detected in shopperlabs shopper up to 2.7.x. This issue affects some unknown processing of the component PaymentMethods. This manipulation causes missing authorization.
This vulnerability is tracked as CVE-2026-47745. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability labeled as critical has been found in Altium Enterprise Server and 365 up to 8.1.0. This affects an unknown part of the component GraphQL Service. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-11424. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
A vulnerability classified as critical was found in twigphp Twig up to 2.16.x/3.25.x. Affected by this issue is some unknown functionality. Executing a manipulation can lead to protection mechanism failure.
This vulnerability is tracked as CVE-2026-24425. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in Bugsink up to 2.1.x. This vulnerability affects unknown code. Performing a manipulation results in authorization bypass.
This vulnerability is cataloged as CVE-2026-47716. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability identified as problematic has been detected in Bugsink up to 2.1.x. Affected by this vulnerability is an unknown functionality. The manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2026-47715. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability was found in Altium Enterprise Server and 365 up to 8.1.0. It has been declared as critical. This impacts an unknown function of the component Projects Service Download Endpoint. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2026-11431. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in jxxghp MoviePilot up to 2.13.3. Impacted is an unknown function of the component Remote Cloud Storage API. The manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-11416. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Bugsink up to 2.1.x. This issue affects some unknown processing. Executing a manipulation can lead to missing authorization.
This vulnerability is registered as CVE-2026-47728. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.