← Back to trending CVEs

Week of September 28, 2026

Trending* CVEs over the last 7 days (from September 21, 2026 to September 28, 2026)

1
CVE-2026-87902Wordpress / Wordpress
NewKEV
SYRN Score92
CVSS8.1
Activity150
Published09/22/2026
StatusHighly Active

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

2
CVE-2026-94127F5 / Big-Ip Access Policy Manager
NewKEV
SYRN Score91
CVSS9.3
Activity133
Published09/22/2026
StatusHighly Active

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

3
CVE-2026-88771Citrix / Netscaler
NewKEV
SYRN Score92
CVSS9.5
Activity98
Published09/27/2026
StatusHighly Active

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

4
CVE-2026-93616Checkpoint / Multi-Domain Security Management
NewKEV
SYRN Score92
CVSS9.8
Activity70
Published09/22/2026
StatusHighly Active

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

5
CVE-2026-88772Citrix / Netscaler
NewKEV
SYRN Score92
CVSS9.5
Activity69
Published09/27/2026
StatusHighly Active

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

6
CVE-2026-65660Microsoft / Microsoft SharePoint
KEV
SYRN Score91
CVSS8.8
Activity62
Published08/11/2026
StatusHighly Active

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

7
CVE-2026-48842Roundcube / Webmail
SYRN Score90
CVSS8.1
Activity41
Published05/25/2026
StatusHighly Active

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

8
CVE-2026-93952Arista / Velocloud Orchestrator
NewKEV
SYRN Score87
CVSS9.5
Activity38
Published09/22/2026
StatusHighly Active

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

9
CVE-2026-35273Oracle / Peoplesoft
KEVRansomware
SYRN Score95
CVSS9.8
Activity35
Published06/11/2026
StatusHighly Active

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

10
CVE-2026-85102Checkpoint / Gaia Embedded
KEV
SYRN Score89
CVSS9.8
Activity35
Published09/09/2026
StatusHighly Active

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

* Trending is based on the number of sightings collected from SYRN's threat intelligence sources over the given period.

Monitor these vulnerabilities and get alerted when new threats target your stack.

Get Started Free