CVE-2026-23781
Critical Severity
Description
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application ...
Related Vulnerabilities
- CVE-2026-1263: The Webling plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, MEDIUM
- CVE-2026-35598: Vikunja Missing Authorization on CalDAV Task Read MEDIUM
- CVE-2026-5144: The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions HIGH
- CVE-2026-25854: Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via th MEDIUM
- CVE-2026-5525: A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handl MEDIUM
Related Coverage
Threat Actors