PatchSiren

PatchSiren public CVE debriefs

Critical CVEs organized by vendor.

PatchSiren public pages turn official CVE, NVD, CISA, and vendor evidence into defensive debriefs for operators who need fast context without losing source links.

Relying on luck is not a patch strategy.

Total CVEs
36,413

published debriefs

New Daily Average
183/day

last 30 days

Covered Vendors
5,963

public vendor sections

Latest 2026 critical and known-exploited CVEs

CRITICAL ladela CVE published 2026-09-25

CVE-2026-93399

The Bookly plugin for WordPress has a critical vulnerability, CVE-2026-93399, with a CVSS score of 9.1. This Insecure Direct Object Reference vulnerability affects versions up to and including 28.2. It allows unauthenticated attackers to enumerate sequential order IDs, disclose other customers' order tokens, retrieve calendar/appointment information, and permanently delete arbitrary non-completed bookings.

CRITICAL ivole CVE published 2026-09-25

CVE-2026-89055

The Customer Reviews for WooCommerce plugin for WordPress has a critical vulnerability allowing unauthorized deletion of Media Library attachments. This issue, tracked as CVE-2026-89055, affects all versions up to and including 5.120.0. Exploitation requires a public review-form link, exposing a nonce for deleting arbitrary attachments, including administrator-owned images and documents.

CRITICAL 101gen CVE published 2026-09-25

CVE-2026-14281

CVE-2026-14281 debrief based on the supplied source corpus. The CVE record was published on 2026-09-25T07:16:53.540Z and has not been modified since then. The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/sign [truncated]

Known exploited WordPress CVE published 2026-09-25

CVE-2026-87902

CVE-2026-87902 is a remote file inclusion vulnerability in WordPress Core with known exploitation in the wild. The vulnerability allows attackers to include remote files, potentially leading to remote code execution. System administrators and security teams should prioritize patching, especially for internet-exposed installations. The scope of exploitation and impact require verification from official sou [truncated]

CRITICAL Botslab CVE published 2026-09-24

CVE-2026-81630

The CVE-2026-81630 vulnerability affects the Botslab G980H dash camera firmware, which does not properly verify the authenticity of firmware updates. This allows an attacker to intercept and modify firmware updates, potentially leading to unauthorized code execution on the device. The vulnerability has a CVSS score of 9.2 and is considered critical. Defenders responsible for managing and securing IoT devi [truncated]

CRITICAL Termix-SSH CVE published 2026-09-24

CVE-2026-79766

CVE-2026-79766 is a critical vulnerability in Termix, a web-based server management platform. An authenticated administrator can store malicious domain and email values, which can be interpolated into a certbot shell command, allowing execution of arbitrary operating-system commands as the Termix backend process. This issue is fixed in version 2.5.1.

CRITICAL Linux CVE published 2026-09-24

CVE-2026-93228

A vulnerability in the Linux kernel's svcrdma has been resolved. The vulnerability involves rejecting Write/Reply chunks with segcount 0. A peer can send a Write or Reply chunk with a zero segcount field, which was not properly rejected. This could lead to potential issues with the parsed chunk lists. The fix ensures that such malformed frames are rejected at the decode boundary.

CRITICAL Linux CVE published 2026-09-24

CVE-2026-93207

A critical vulnerability has been resolved in the Linux kernel, specifically in the SUNRPC (Sun Remote Procedure Call) implementation. The vulnerability arises from the improper handling of the rpc_gss_wire_cred structure in the svcauth_gss_decode_credbody() function. This function is responsible for decoding credentials in the RPC service. The issue occurs when the function fails to zero out the rpc_gss_ [truncated]

CRITICAL ludocode CVE published 2026-09-24

CVE-2026-88351

An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specially crafted MessagePack array32 or map32 object with an excessively large element count, the page allocation size calculation in mpack_tree_parse_children() can overflow size_t and produce an undersized allocation. Subsequent parsing writes mpack_node_data_t records beyond the allocated [truncated]

CRITICAL geelen CVE published 2026-09-24

CVE-2026-51994

A critical vulnerability was found in mcp-remote versions 0.1.32 through 0.1.38, which are susceptible to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header. This issue has a CVSS score of 9.1 and is considered critical. The vulnerability allows attackers to make unauthorized requests, potentially leading to significant operational [truncated]

CRITICAL Red Hat CVE published 2026-09-23

CVE-2026-84719

A flaw in the Ansible Automation Platform automation-controller allows a user with organization workflow-admin permission to copy a WorkflowJobTemplate and launch jobs pinned to instance groups they are not authorized to use, bypassing the InstanceGroup use_role boundary. This could lead to attacker-influenced automation running in the control-plane execution context.

CRITICAL moquette-io CVE published 2026-09-23

CVE-2026-85724

A critical vulnerability in Moquette, a lightweight Java MQTT broker, allows unauthorized access to MQTT topics due to improper handling of pattern-based ACL rules. This issue, fixed in version 0.18.1, enables clients to broaden their access and potentially disrupt session processing. The vulnerability arises from the AuthorizationsCollector.canDoOperation method directly substituting client ID and userna [truncated]

Vendor directory

Linux

3180 published CVE debriefs, 246 critical or known-exploited

Microsoft

2221 published CVE debriefs, 489 critical or known-exploited

siemens

1957 published CVE debriefs, 110 critical or known-exploited

Google

1605 published CVE debriefs, 230 critical or known-exploited

Oracle Corporation

1339 published CVE debriefs, 253 critical or known-exploited

Oracle

780 published CVE debriefs, 162 critical or known-exploited

Red Hat

588 published CVE debriefs, 47 critical or known-exploited

IBM

588 published CVE debriefs, 73 critical or known-exploited

Adobe

537 published CVE debriefs, 129 critical or known-exploited

Apple

533 published CVE debriefs, 116 critical or known-exploited

Cisco

320 published CVE debriefs, 120 critical or known-exploited

Mozilla

305 published CVE debriefs, 129 critical or known-exploited

Apache Software Foundation

291 published CVE debriefs, 58 critical or known-exploited

Dell

234 published CVE debriefs, 20 critical or known-exploited

Apache

186 published CVE debriefs, 64 critical or known-exploited

Schneider Electric

151 published CVE debriefs, 15 critical or known-exploited

Rockwell Automation

140 published CVE debriefs, 19 critical or known-exploited

Festo Didactic SE

138 published CVE debriefs, 22 critical or known-exploited

Spring

136 published CVE debriefs, 6 critical or known-exploited

OpenClaw

127 published CVE debriefs, 3 critical or known-exploited

SourceCodester

109 published CVE debriefs, 2 critical or known-exploited

open-webui

107 published CVE debriefs, 1 critical or known-exploited

WWBN

100 published CVE debriefs, 13 critical or known-exploited

D-Link

97 published CVE debriefs, 31 critical or known-exploited

JetBrains

92 published CVE debriefs, 12 critical or known-exploited

Concrete CMS

91 published CVE debriefs, 0 critical or known-exploited

NVIDIA

87 published CVE debriefs, 4 critical or known-exploited

getgrav

87 published CVE debriefs, 14 critical or known-exploited

Palo Alto Networks

84 published CVE debriefs, 18 critical or known-exploited

ImageMagick

83 published CVE debriefs, 4 critical or known-exploited

Elastic

78 published CVE debriefs, 3 critical or known-exploited

Hitachi Energy

78 published CVE debriefs, 6 critical or known-exploited

Drupal

78 published CVE debriefs, 12 critical or known-exploited

ABB

77 published CVE debriefs, 15 critical or known-exploited

itsourcecode

73 published CVE debriefs, 0 critical or known-exploited

Jenkins Project

72 published CVE debriefs, 0 critical or known-exploited

MongoDB

72 published CVE debriefs, 3 critical or known-exploited

siyuan-note

71 published CVE debriefs, 25 critical or known-exploited

cPanel

69 published CVE debriefs, 6 critical or known-exploited

grokability

67 published CVE debriefs, 0 critical or known-exploited

Hewlett Packard Enterprise (HPE)

67 published CVE debriefs, 13 critical or known-exploited

Tenda

67 published CVE debriefs, 17 critical or known-exploited

CODESYS

66 published CVE debriefs, 1 critical or known-exploited

code-projects

65 published CVE debriefs, 1 critical or known-exploited

n8n-io

65 published CVE debriefs, 1 critical or known-exploited

F5

64 published CVE debriefs, 12 critical or known-exploited

FreeRDP

64 published CVE debriefs, 8 critical or known-exploited

misp

63 published CVE debriefs, 5 critical or known-exploited

Methodology and editorial approach

PatchSiren debriefs organize stored public vulnerability evidence for defensive review. Source-specific dates and claims should remain tied to their source, unresolved conflicts should remain visible, and readers should verify remediation against the linked primary advisory before changing production systems.