CVE-2026-23781
Critical Severity
Description
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application ...
Related Vulnerabilities
- CVE-2025-14545: The YML for Yandex Market WordPress plugin before 5.0.26 is vulnerable to Remote Code Execution via CRITICAL
- CVE-2026-40069: bsv-sdk ARC broadcaster treats INVALID/MALFORMED/ORPHAN responses as successful broadcasts MEDIUM
- CVE-2026-5053: NoMachine External Control of File Path Arbitrary File Deletion Vulnerability. This vulnerability al HIGH
- CVE-2026-35665: OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-32011 where the Feishu webhook han MEDIUM
- CVE-2026-35599: Vikunja has Algorithmic Complexity DoS in Repeating Task Handler MEDIUM
Related Coverage
Threat Actors