CVE-2026-23780
High Severity
Description
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attack...
Related Vulnerabilities
- CVE-2026-40189: goshs has a file-based ACL authorization bypass in goshs state-changing routes CRITICAL
- CVE-2026-5264: Heap buffer overflow in DTLS 1.3 ACK message processing. A remote attacker can send a crafted DTLS 1 HIGH
- CVE-2026-34942: Wasmtime: Panic when transcoding misaligned utf-16 strings MEDIUM
- CVE-2026-5501: wolfSSL_X509_verify_cert in the OpenSSL compatibility layer accepts a certificate chain in which the HIGH
- CVE-2026-29145: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled v MEDIUM
Related Coverage
Threat Actors