← Back to the live CVE advisory feed

CVE-2026-106056: Product identification pending

Severity
7.7 (HIGH)
Vendor
RUNDECK BEFORE
Affected versions
Before 6.2.0
Fixed version
6.2.0
Patch status
Patched
Published
2026-10-07T12:17:08.520
Modified
2026-10-07T17:16:47.057

Why it matters

High-severity vulnerability requiring prioritized review.

Recommended admin actions

  • Review and patch based on exposure, asset criticality, and business impact.
  • Compare installed versions against the affected version range in the advisory.

Technical summary

Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows nodes by supplying crafted option values. Attackers can inject cmd.exe metacharacters such as && or | into free-text options, which CLIUtils.quoteWindowsCMDArg wraps in ineffective single quotes, running commands with node executor credential privileges.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: OCT 08, 2026 12:00 PM UTC
353 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-102255
SMA1000
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2025-70518
Product identification pending
Reporter: CVE
10
CRITICAL
VIEW RECORD
CVE-2026-76482
Cisco License On-Prem
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-12260
NetBoard CRM Demo Platform
Reporter: CVE-COORDINATION
10
CRITICAL
VIEW RECORD
CVE-2025-70521
Product identification pending
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-62252
homer PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-62253
homer PATCH
Reporter: SECURITY-ADVISORIES
9.8
CRITICAL
VIEW RECORD
CVE-2026-76455
Cisco NX-OS Software
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76465
Cisco NX-OS Software
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76471
Cisco NX-OS Software
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76480
Cisco License On-Prem
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76485
Cisco NX-OS Software
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76486
Cisco NX-OS Software
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76498
Cisco Application Policy Infrastructure Controller (APIC)
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76499
Cisco Application Policy Infrastructure Controller (APIC)
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76500
Cisco Application Policy Infrastructure Controller (APIC)
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76501
Cisco NX-OS Software
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-95606
The Events Calendar PATCH
Reporter: AUDIT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76268
Splunk Enterprise
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-103646
Ultimate Multisite PATCH
Reporter: CONTACT
9.8
CRITICAL
VIEW RECORD
CVE-2026-103692
Frontend Dashboard PATCH
Reporter: CONTACT
9.8
CRITICAL
VIEW RECORD
CVE-2026-85097
Bricksforge
Reporter: SECURITY
9.8
CRITICAL
VIEW RECORD
CVE-2026-76464
Cisco Campus Gateway Software
Reporter: PSIRT
9.6
CRITICAL
VIEW RECORD
CVE-2026-107282
async-http-client PATCH
Reporter: SECURITY-ADVISORIES
9.4
CRITICAL
VIEW RECORD
CVE-2026-107204
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-92414
Apache Jackrabbit PATCH
Reporter: SECURITY
9.3
CRITICAL
VIEW RECORD
CVE-2026-95605
WP Data Access PATCH
Reporter: AUDIT
9.3
CRITICAL
VIEW RECORD
CVE-2026-107459
SecuShare Pro
Reporter: TWCERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-105110
Innbox
Reporter: 309F9EA4-E3E9-4C6C-B79D-E8EB01244F2C
9.3
CRITICAL
VIEW RECORD
CVE-2026-107183
llama.cpp PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-107194
iSolarCloud PATCH
Reporter: CVE
9.2
CRITICAL
VIEW RECORD
CVE-2025-70516
Product identification pending
Reporter: CVE
9.1
CRITICAL
VIEW RECORD
CVE-2026-107202
h-ui
Reporter: CRET
9.1
CRITICAL
VIEW RECORD
CVE-2026-20328
Cisco License On-Prem
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-62176
PraisonAI PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-76454
Cisco License On-Prem
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-76483
Cisco License On-Prem
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-17609
Super Forms – Drag & Drop Form Builder
Reporter: SECURITY
9.1
CRITICAL
VIEW RECORD
CVE-2026-107510
NIOS
Reporter: F84CA5CE-FBE7-4668-8724-994599108A02
9.1
CRITICAL
VIEW RECORD
CVE-2026-106558
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-107205
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-107206
Product identification pending
Reporter: DISCLOSURE
8.8
HIGH
VIEW RECORD
CVE-2026-76453
Cisco NX-OS Software
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-76459
Cisco NX-OS Software
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-76463
Cisco Campus Gateway Software
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-76470
Cisco Campus Gateway Software
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-76472
Cisco Campus Gateway Software
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-76484
Cisco License On-Prem
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-95534
Unlimited Elements For Elementor (Free Widgets, Addons, Templates) PATCH
Reporter: AUDIT
8.8
HIGH
VIEW RECORD
CVE-2026-107279
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-17196
Super Forms – Drag & Drop Form Builder
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-106059
gitahead
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-107211
excelize
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-107213
excelize
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-97716
Product identification pending PATCH
Reporter: SECURITYRESPONSE
8.7
HIGH
VIEW RECORD
CVE-2026-107231
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-102488
Product identification pending
Reporter: SECURITY
8.7
HIGH
VIEW RECORD
CVE-2026-87684
Product identification pending PATCH
Reporter: SIRT
8.7
HIGH
VIEW RECORD
CVE-2026-85421
Product identification pending PATCH
Reporter: SIRT
8.7
HIGH
VIEW RECORD
CVE-2026-85489
Product identification pending PATCH
Reporter: SIRT
8.7
HIGH
VIEW RECORD
CVE-2026-107181
Product identification pending PATCH
Reporter: DISCLOSURE
8.6
HIGH
VIEW RECORD
CVE-2026-76456
Cisco NX-OS Software
Reporter: PSIRT
8.6
HIGH
VIEW RECORD
CVE-2026-76457
Cisco NX-OS Software
Reporter: PSIRT
8.6
HIGH
VIEW RECORD
CVE-2026-76458
Cisco NX-OS Software
Reporter: PSIRT
8.6
HIGH
VIEW RECORD
CVE-2026-87682
Product identification pending PATCH
Reporter: SIRT
8.6
HIGH
VIEW RECORD
CVE-2026-87683
Product identification pending PATCH
Reporter: SIRT
8.6
HIGH
VIEW RECORD
CVE-2026-87666
Product identification pending PATCH
Reporter: SIRT
8.6
HIGH
VIEW RECORD
CVE-2026-85423
Product identification pending PATCH
Reporter: SIRT
8.6
HIGH
VIEW RECORD
CVE-2026-85486
Product identification pending PATCH
Reporter: SIRT
8.6
HIGH
VIEW RECORD
CVE-2026-85487
Product identification pending PATCH
Reporter: SIRT
8.6
HIGH
VIEW RECORD
CVE-2026-87424
Product identification pending PATCH
Reporter: SIRT
8.6
HIGH
VIEW RECORD
CVE-2026-106057
Product identification pending PATCH
Reporter: DISCLOSURE
8.5
HIGH
VIEW RECORD
CVE-2026-34499
Product identification pending PATCH
Reporter: PRODUCTSECURITY
8.5
HIGH
VIEW RECORD
CVE-2026-87679
Product identification pending PATCH
Reporter: SIRT
8.5
HIGH
VIEW RECORD
CVE-2026-87680
Product identification pending PATCH
Reporter: SIRT
8.5
HIGH
VIEW RECORD
CVE-2026-87674
Product identification pending PATCH
Reporter: SIRT
8.5
HIGH
VIEW RECORD
CVE-2026-87687
Product identification pending PATCH
Reporter: SIRT
8.5
HIGH
VIEW RECORD
CVE-2026-87688
Product identification pending PATCH
Reporter: SIRT
8.5
HIGH
VIEW RECORD
CVE-2026-87664
Product identification pending
Reporter: SIRT
8.5
HIGH
VIEW RECORD
CVE-2026-94581
Product identification pending PATCH
Reporter: SIRT
8.5
HIGH
VIEW RECORD
CVE-2026-94586
Product identification pending PATCH
Reporter: SIRT
8.5
HIGH
VIEW RECORD
CVE-2026-93699
WP Toolkit
Reporter: SUPPORT
8.5
HIGH
VIEW RECORD
CVE-2026-87667
Product identification pending PATCH
Reporter: SIRT
8.4
HIGH
VIEW RECORD
CVE-2026-87685
Product identification pending PATCH
Reporter: SIRT
8.4
HIGH
VIEW RECORD
CVE-2026-85422
Product identification pending PATCH
Reporter: SIRT
8.4
HIGH
VIEW RECORD
CVE-2026-87428
Product identification pending PATCH
Reporter: SIRT
8.4
HIGH
VIEW RECORD
CVE-2026-77214
libexpat PATCH
Reporter: DISCLOSURE
8.3
HIGH
VIEW RECORD
CVE-2026-76468
Cisco Campus Gateway Software
Reporter: PSIRT
8.2
HIGH
VIEW RECORD
CVE-2026-97714
Product identification pending PATCH
Reporter: SECURITYRESPONSE
8.2
HIGH
VIEW RECORD
CVE-2026-5047
Product identification pending PATCH
Reporter: SIRT
8.2
HIGH
VIEW RECORD
CVE-2026-46570
Product identification pending PATCH
Reporter: CVE
8.1
HIGH
VIEW RECORD
CVE-2026-62251
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.1
HIGH
VIEW RECORD
CVE-2026-105816
Product identification pending PATCH
Reporter: SECURITY
8
HIGH
VIEW RECORD
CVE-2026-103647
hMailServer
Reporter: CVE
8
HIGH
VIEW RECORD
CVE-2026-102256
Product identification pending
Reporter: PSIRT
7.8
HIGH
VIEW RECORD
CVE-2026-103010
hMailServer
Reporter: CVE
7.8
HIGH
VIEW RECORD
CVE-2026-104658
hMailServer
Reporter: CVE
7.8
HIGH
VIEW RECORD
CVE-2026-104660
Product identification pending
Reporter: CVE
7.8
HIGH
VIEW RECORD
CVE-2026-106056
Product identification pending PATCH
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD
CVE-2026-106058
Product identification pending
Reporter: DISCLOSURE
7.7
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.