← Back to the live CVE advisory feed

CVE-2026-101263: ZHOME A0101

Severity
8.5 (HIGH)
Vendor
ZIROOM
Affected versions
1.0.1.0
Patch status
Unknown
Published
2026-09-29T00:17:01.540
Modified
2026-09-29T00:17:01.540

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Treat internet-facing systems as higher priority.

Technical summary

A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 29, 2026 08:00 AM UTC
308 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-82377
Apache Roller PATCH
Reporter: SECURITY
9.9
CRITICAL
VIEW RECORD
CVE-2026-85526
LXD
Reporter: SECURITY
9.9
CRITICAL
VIEW RECORD
CVE-2026-87799
Product identification pending PATCH
Reporter: SECURITY
9.9
CRITICAL
VIEW RECORD
CVE-2026-82384
Apache Roller PATCH
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-90924
Product identification pending PATCH
Reporter: ILETISIM
9.8
CRITICAL
VIEW RECORD
CVE-2026-85185
Product identification pending PATCH
Reporter: SECURITY
9.6
CRITICAL
VIEW RECORD
CVE-2026-12342
IdentityIQ
Reporter: PSIRT
9.6
CRITICAL
VIEW RECORD
CVE-2026-88804
Product identification pending PATCH
Reporter: MEISSNER
9.6
CRITICAL
VIEW RECORD
CVE-2026-19759
Application Integration PATCH
Reporter: F45CBF4E-4146-4068-B7E1-655FFC2C548C
9.4
CRITICAL
VIEW RECORD
CVE-2026-81867
Application Integration PATCH
Reporter: F45CBF4E-4146-4068-B7E1-655FFC2C548C
9.4
CRITICAL
VIEW RECORD
CVE-2026-101039
FAC1900R
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-101072
NR289-GE
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-73640
Payroll
Reporter: CVD
9.3
CRITICAL
VIEW RECORD
CVE-2026-101075
NR289-GE
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-101076
NR289-GE
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-101077
NR289-GE
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-101891
WatchGuard AP
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
9.3
CRITICAL
VIEW RECORD
CVE-2026-86102
WatchGuard AP
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
9.3
CRITICAL
VIEW RECORD
CVE-2026-100752
Real Estate Manager (Free) extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-101108
Vehicle Manager (Free) extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-101110
Book Library (Free) extension for Joomla
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-102361
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-102240
NAP930
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-73642
Payroll
Reporter: CVD
9.2
CRITICAL
VIEW RECORD
CVE-2026-102422
shell-quote PATCH
Reporter: 7FFCEE3D-2C14-4C3E-B844-86C6A321A158
9.2
CRITICAL
VIEW RECORD
CVE-2026-101894
decompress PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-49994
bluehood PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-102268
pyjwt PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-102334
nginx-proxy-manager
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-82378
Apache Roller PATCH
Reporter: SECURITY
9
CRITICAL
VIEW RECORD
CVE-2026-101074
NR289-GE
Reporter: CNA
8.9
HIGH
VIEW RECORD
CVE-2026-85134
Product identification pending PATCH
Reporter: ILETISIM
8.8
HIGH
VIEW RECORD
CVE-2026-12268
DDI Central
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-12269
DDI Central
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-12264
Product identification pending PATCH
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-78424
Product identification pending PATCH
Reporter: MEISSNER
8.8
HIGH
VIEW RECORD
CVE-2026-12265
Product identification pending PATCH
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
8.8
HIGH
VIEW RECORD
CVE-2026-86595
Product identification pending PATCH
Reporter: ILETISIM
8.8
HIGH
VIEW RECORD
CVE-2026-90926
Product identification pending PATCH
Reporter: ILETISIM
8.8
HIGH
VIEW RECORD
CVE-2026-88808
Product identification pending PATCH
Reporter: MEISSNER
8.8
HIGH
VIEW RECORD
CVE-2026-86950
Product identification pending PATCH
Reporter: PRODUCT-SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-87741
ConvertPlus
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-95104
WSR-300HP
Reporter: VULTURES
8.7
HIGH
VIEW RECORD
CVE-2026-96538
Product identification pending PATCH
Reporter: 20BE33E2-BF35-4D13-8FAD-18BD2F3E3659
8.7
HIGH
VIEW RECORD
CVE-2026-48100
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-54675
security-reporting PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-100371
InvoicePlane PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-86530
WSR-300HP
Reporter: VULTURES
8.6
HIGH
VIEW RECORD
CVE-2026-101037
FAC1200R
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-101038
FAC1200R
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-93348
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-87969
WatchGuard AP
Reporter: 5D1C2695-1A31-4499-88AE-E847036FD7E3
8.6
HIGH
VIEW RECORD
CVE-2026-54674
security-reporting PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-54708
security-reporting PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-54710
security-reporting PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2026-75600
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.6
HIGH
VIEW RECORD
CVE-2024-42002
Product identification pending
Reporter: SECURITY
8.6
HIGH
VIEW RECORD
CVE-2026-101354
FAC1203R
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-101081
DI-8400
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-101187
ZHOME A0101
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-101260
ZHOME A0101
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-101261
ZHOME A0101
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-101262
ZHOME A0101
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-101263
ZHOME A0101
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-101264
ZHOME A0101
Reporter: CNA
8.5
HIGH
VIEW RECORD
CVE-2026-55157
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.4
HIGH
VIEW RECORD
CVE-2026-81375
Product identification pending PATCH
Reporter: F45CBF4E-4146-4068-B7E1-655FFC2C548C
8.3
HIGH
VIEW RECORD
CVE-2026-101909
axios PATCH
Reporter: SECURITY-ADVISORIES
8.3
HIGH
VIEW RECORD
CVE-2026-102296
Product identification pending PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-82383
Apache Roller PATCH
Reporter: SECURITY
8.2
HIGH
VIEW RECORD
CVE-2026-91043
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
8.2
HIGH
VIEW RECORD
CVE-2026-101292
Product identification pending PATCH
Reporter: SECALERT
8.2
HIGH
VIEW RECORD
CVE-2026-54160
nut PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-101901
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-101903
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-101906
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.2
HIGH
VIEW RECORD
CVE-2026-82380
Product identification pending PATCH
Reporter: SECURITY
8.1
HIGH
VIEW RECORD
CVE-2026-82323
Product identification pending
Reporter: ILETISIM
8.1
HIGH
VIEW RECORD
CVE-2026-88805
Product identification pending PATCH
Reporter: MEISSNER
8.1
HIGH
VIEW RECORD
CVE-2026-4556
Exam4
Reporter: 41C37E40-543D-43A2-B660-2FEE83EA851A
7.8
HIGH
VIEW RECORD
CVE-2026-102004
Product identification pending PATCH
Reporter: 0BF9931A-6EBF-4F48-BD14-39EE5E1D61F8
7.8
HIGH
VIEW RECORD
CVE-2026-16513
Product identification pending
Reporter: VULNERABILITIES
7.8
HIGH
VIEW RECORD
CVE-2026-18413
Product identification pending
Reporter: VULNERABILITIES
7.8
HIGH
VIEW RECORD
CVE-2026-18414
Product identification pending
Reporter: VULNERABILITIES
7.8
HIGH
VIEW RECORD
CVE-2026-82348
Product identification pending PATCH
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-82376
Product identification pending PATCH
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-82379
Product identification pending PATCH
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-82386
Product identification pending PATCH
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-82928
Product identification pending PATCH
Reporter: CVD
7.7
HIGH
VIEW RECORD
CVE-2026-97335
Product identification pending PATCH
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-45562
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.7
HIGH
VIEW RECORD
CVE-2026-101878
Product identification pending PATCH
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-86158
Progress® Telerik® Fiddler® Everywhere
Reporter: SECURITY
7.7
HIGH
VIEW RECORD
CVE-2026-101905
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-55160
stringer PATCH
Reporter: SECURITY-ADVISORIES
7.6
HIGH
VIEW RECORD
CVE-2026-93355
litellm
Reporter: DISCLOSURE
7.6
HIGH
VIEW RECORD
CVE-2026-102276
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-102278
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-102281
nest PATCH
Reporter: SECURITY-ADVISORIES
7.5
HIGH
VIEW RECORD
CVE-2026-82375
Product identification pending PATCH
Reporter: SECURITY
7.4
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.