The Week in Security
Other had 38 vulnerabilities this week including Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9).
We tracked 38 vulnerabilities this week. 33 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.
Other Had a Rough Week
38 vulnerabilities across Other products this week. The worst: CVE-2025-62718 (CVSS 9.9) lets attackers run code on your systems. Patch now if you run Other.
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2026-8985: Maxicharger Single Charger Firmware OS Command Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-8985: Maxicharger Single Charger Firmware OS Command Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-8985: Maxicharger Single Charger Firmware OS Command Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-8984: Maxicharger Single Charger Firmware Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-8984: Maxicharger Single Charger Firmware Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-8984: Maxicharger Single Charger Firmware Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-8983: Maxicharger Single Charger Firmware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-8983: Maxicharger Single Charger Firmware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-49875: Cxf Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-29167: Http Server Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-28780: Http Server Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-16232: Multi-Domain Security Management Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-16232: Multi-Domain Security Management Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-16232: Multi-Domain Security Management Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-14537: Mcp Toolbox For Databases Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2025-9242: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2025-9242: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2025-9242: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2025-14733: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2025-14733: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2025-14733: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2025-14733: Fireware Security (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2024-23692: Http File Server Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2024-23692: Http File Server Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2024-23692: Http File Server Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
- CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
- CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
- CVE-2026-8037: Connection Manager For Objectscale Security (CVSS 9.6 CRITICAL) (CVSS 9.6)
- CVE-2026-65767: Teams Security (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2026-24072: Http Server Security (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2025-71390: Surrealdb Security (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2025-71390: Surrealdb Security (CVSS 8.8 HIGH) (CVSS 8.8)
- CVE-2024-1086: H300S Firmware Security (CVSS 7.8 HIGH) (CVSS 7.8)
By the Numbers
| Total CVEs analyzed | 38 |
| Critical (9.0+) | 33 |
| High (7.0-8.9) | 5 |
| Remote code execution | 38 |
| Authentication bypass | 0 |
| Cross-site scripting | 0 |
| SQL injection | 0 |
What To Do This Week
One action item per vendor. Start at the top and work down.
- Other: Update immediately. 33 critical-severity issues patched this week.