Back to trending CVEs

Week of March 9, 2026

Trending* CVEs over the last 7 days (from March 2, 2026 to March 9, 2026)

1
CVE-2026-21385Qualcomm / 5G Fixed Wireless Access Platform
NewKEV
SYRN Score90
CVSS7.8
Activity53
Published03/02/2026
StatusHighly Active

Memory corruption while using alignments for memory allocation.

2
CVE-2026-22719Vmware / Aria Operations
KEV
SYRN Score88
CVSS8.1
Activity44
Published02/25/2026
StatusHighly Active

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-2026-22719, apply the patches listed in the 'Fixed Version' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001  Workarounds for CVE-2026-22719 are documented in the 'Workarounds' column of the ' Response Matrix https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947 ' in VMSA-2026-0001

3
CVE-2026-20127Cisco Systems / Catalyst Sd-Wan Manager
KEV
SYRN Score97
CVSS10.0
Activity33
Published02/25/2026
StatusHighly Active

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. 

4
CVE-2026-21902Juniper Networks / Junos Os Evolved
SYRN Score70
CVSS9.8
Activity19
Published02/25/2026
StatusActive

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required. This issue affects Junos OS Evolved on PTX Series: * 25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO. This issue does not affect Junos OS Evolved versions before 25.4R1-EVO. This issue does not affect Junos OS.

5
CVE-2026-20122Cisco Systems / Catalyst Sd-Wan Manager
SYRN Score19
CVSS5.4
Activity18
Published02/25/2026
StatusActive

A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access on the affected system. This vulnerability is due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

6
CVE-2026-20079Cisco Systems / Cisco Secure Firewall Management Center (Fmc)
New
SYRN Score75
CVSS10.0
Activity17
Published03/04/2026
StatusActive

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.

7
CVE-2026-0628Google / Google Chrome
SYRN Score65
CVSS8.8
Activity16
Published01/06/2026
StatusActive

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

8
CVE-2026-20128Cisco Systems / Catalyst Sd-Wan Manager
SYRN Score26
CVSS7.5
Activity15
Published02/25/2026
StatusActive

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain DCA user privileges on an affected system. To exploit this vulnerability, the attacker must have valid vmanage credentials on the affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by accessing the filesystem as a low-privileged user and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.

9
CVE-2026-21513Microsoft / Microsoft Windows
KEV
SYRN Score91
CVSS8.8
Activity15
Published02/10/2026
StatusActive

Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.

10
CVE-2026-20131Cisco Systems / Cisco Secure Firewall Management Center (Fmc)
New
SYRN Score84
CVSS10.0
Activity14
Published03/04/2026
StatusActive

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

* Trending is based on the number of sightings collected from SYRN's threat intelligence sources over the given period.

Monitor these vulnerabilities and get alerted when new threats target your stack.

Get Started Free