View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Silverstripe UserForms flaw enables code execution via email subject

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

๐Ÿ”“ CVEs & KEV

  • CVE-2026-76943 โ€” CVSS 9.3 โ€” Xiiaozet LK100W Authentication Bypass Using an Alternate Path or ChannelXiiao...

  • CVE-2026-78239 โ€” CVSS 9.3 โ€” Xiiaozet LK100W Missing Authentication for Critical FunctionXiiaozet LK100W e...

  • CVE-2026-5706 โ€” CVSS 8.9 โ€” Buffer overflow in Bluetooth Mesh SDK when handling extended advertisementsIn...

  • CVE-2026-78037 โ€” CVSS 8.7 โ€” Xiiaozet LK100W OS Command InjectionXiiaozet LK100W is vulnerable to OS comma...

  • CVE-2026-77358 โ€” CVSS 8.2 โ€” cpp-httplib: Use-after-free of TLS session in WebSocketClient::shutdown_and_c...

  • CVE-2026-54083 โ€” CVSS 8.1 โ€” Wazuh: Path traversal in ip-customblock active response allows arbitrary file...

  • CVE-2026-54085 โ€” CVSS 7.1 โ€” Wazuh: Missing input validation in multiple active response scripts allows ar...

  • CVE-2026-61783 โ€” CVSS 7.0 โ€” Wazuh: RBAC permission-effect check in mask_sensitive_config allows low-privi...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check