The Week in Security
Other had 10 vulnerabilities this week including Traefik Path Traversal (CVSS 10.0 CRITICAL) (CVSS 10.0). Mozilla Firefox had 4 vulnerabilities this week including Mozilla Firefox and Thunderbird Memory Safety (CVSS 9.8 CRITICAL) (CVSS 9.8). Apache got hit with a CVSS 9.6 for Apache Camel / Undertow Improper Input Validation (CVSS 9.6 CRITICAL).
We tracked 17 vulnerabilities this week. 16 scored 9.0 or above. If you only have time for one thing today, scroll to "What To Do This Week" at the bottom.
Other Had a Rough Week
10 vulnerabilities across Other products this week. The worst: CVE-2026-48020 (CVSS 10.0) lets attackers run code on your systems. Patch now if you run Other.
- CVE-2026-48020: Traefik Path Traversal (CVSS 10.0 CRITICAL) (CVSS 10.0)
- CVE-2025-15379: MLflow OS Command Injection (CVSS 10.0 CRITICAL) (CVSS 10.0)
- CVE-2026-72765: N8N Code Injection (CVSS 9.9 CRITICAL) (CVSS 9.9)
- CVE-2026-9698: Perl DBI Buffer Overflow (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-9586: Switchvox SQL Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-73487: Flowise Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-73373: Joomla! Unrestricted File Upload (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-41242: protobufjs Code Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-19586: TP-Link Omada Gateway OS Command Injection (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-59822: LiteLLM Authentication Bypass (CVSS 8.2 HIGH) (CVSS 8.2)
Mozilla Firefox: 4 Critical Flaws at Once
4 vulnerabilities across Mozilla Firefox products this week. The worst: CVE-2026-84143 (CVSS 9.8) lets attackers run code on your systems. Patch now if you run Mozilla Firefox.
- CVE-2026-84143: Mozilla Firefox and Thunderbird Memory Safety (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-84142: Mozilla Firefox Memory Safety (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-84141: Mozilla Firefox Integer Overflow (CVSS 9.8 CRITICAL) (CVSS 9.8)
- CVE-2026-84135: Mozilla Firefox Mobile Improper Input Validation (CVSS 9.8 CRITICAL) (CVSS 9.8)
Apache Hit With CVSS 9.6
CVE-2025-12543 scores a 9.6. Apache lets attackers run code on your systems.
- CVE-2025-12543: Apache Camel / Undertow Improper Input Validation (CVSS 9.6 CRITICAL) (CVSS 9.6)
GitLab Hit With CVSS 9.4
CVE-2026-19478 scores a 9.4. GitLab lets attackers run code on your systems.
- CVE-2026-19478: GitLab Code Injection (CVSS 9.4 CRITICAL) (CVSS 9.4)
Microsoft Hit With CVSS 9.1
CVE-2025-13872 scores a 9.1. Microsoft lets attackers run code on your systems.
- CVE-2025-13872: ObjectPlanet Opinio Server-Side Request Forgery (CVSS 9.1 CRITICAL) (CVSS 9.1)
By the Numbers
| Total CVEs analyzed | 17 |
| Critical (9.0+) | 16 |
| High (7.0-8.9) | 1 |
| Remote code execution | 17 |
| Authentication bypass | 0 |
| Cross-site scripting | 0 |
| SQL injection | 0 |
What To Do This Week
One action item per vendor. Start at the top and work down.
- Other: Update immediately. 9 critical-severity issues patched this week.
- Mozilla Firefox: Update immediately. 4 critical-severity issues patched this week.
- Apache: Update immediately. 1 critical-severity issues patched this week.
- GitLab: Update immediately. 1 critical-severity issues patched this week.
- Microsoft: Update immediately. 1 critical-severity issues patched this week.