← Back to the live CVE advisory feed

CVE-2026-43641: Product identification pending

Severity
9.3 (CRITICAL)
Affected versions
Before 3.2.9
Fixed version
3.2.9
Patch status
Patched
Published
2026-09-22T18:17:14.357
Modified
2026-09-22T20:43:58.793

Why it matters

This matters because the affected product may be exploitable without valid credentials. Internet-facing deployments should be reviewed first.

Recommended admin actions

  • Prioritize validation immediately due to critical CVSS severity.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.

Technical summary

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentication through specific parameter combinations. Attackers can deserialize a crafted billing_data POST field and inject shell payloads through the uid field, which is passed unmodified to proc_open() via vexec(), yielding complete control of the host and all managed VPS instances.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 23, 2026 12:00 PM UTC
524 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-80155
SLC8000
Reporter: DISCLOSURE
10
CRITICAL
VIEW RECORD
CVE-2026-73369
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-75699
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-75703
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-75721
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-75723
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-77244
mcp-atlassian PATCH
Reporter: SECURITY-ADVISORIES
10
CRITICAL
VIEW RECORD
CVE-2026-7866
Product identification pending PATCH
Reporter: 3F572A00-62E2-4423-959A-7EA25EFF1638
10
CRITICAL
VIEW RECORD
CVE-2026-84412
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-89275
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-75745
Product identification pending
Reporter: PSIRT
10
CRITICAL
VIEW RECORD
CVE-2026-82008
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-82010
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-82013
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-83660
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-89276
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-57149
plone.app.portlets PATCH
Reporter: SECURITY-ADVISORIES
9.9
CRITICAL
VIEW RECORD
CVE-2026-75682
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-16346
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-18169
Product identification pending
Reporter: PSIRT
9.9
CRITICAL
VIEW RECORD
CVE-2026-74849
ManageEngine ADSelfService Plus
Reporter: 0FC0942C-577D-436F-AE8E-945763C79B02
9.8
CRITICAL
VIEW RECORD
CVE-2026-93616 EXPLOITED
Quantum Security Management
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-12718
Product identification pending
Reporter: ILETISIM
9.8
CRITICAL
VIEW RECORD
CVE-2026-65113
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-79313
Product identification pending
Reporter: CVE
9.8
CRITICAL
VIEW RECORD
CVE-2026-93088
SGLang
Reporter: CRET
9.8
CRITICAL
VIEW RECORD
CVE-2026-28324
Observability Self-Hosted PATCH
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76708
Product identification pending
Reporter: SECURITY-ALERT
9.8
CRITICAL
VIEW RECORD
CVE-2026-76709
Product identification pending
Reporter: SECURITY-ALERT
9.8
CRITICAL
VIEW RECORD
CVE-2026-18162
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-18163
Product identification pending
Reporter: PSIRT
9.8
CRITICAL
VIEW RECORD
CVE-2026-84388
FortiPAM Chrome Extension
Reporter: PSIRT
9.6
CRITICAL
VIEW RECORD
CVE-2026-86059
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.6
CRITICAL
VIEW RECORD
CVE-2026-82443
Product identification pending
Reporter: PSIRT
9.6
CRITICAL
VIEW RECORD
CVE-2026-82000
Product identification pending
Reporter: PSIRT
9.6
CRITICAL
VIEW RECORD
CVE-2026-17472
Product identification pending
Reporter: PSIRT
9.6
CRITICAL
VIEW RECORD
CVE-2026-80143
SLC8000
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-80144
SLC8000
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-80145
SLC8000
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-80146
SLC8000
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-80147
SLC8000
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-80151
SLC8000
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-80152
SLC8000
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-80156
SLC8000
Reporter: DISCLOSURE
9.4
CRITICAL
VIEW RECORD
CVE-2026-95675
Product identification pending
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-94127 EXPLOITED
BIG-IP
Reporter: F5SIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-63374
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-77621
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-43641
Product identification pending PATCH
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-75684
Product identification pending
Reporter: PSIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-75686
Product identification pending
Reporter: PSIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-75689
Product identification pending
Reporter: PSIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-75697
Product identification pending
Reporter: PSIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-75698
Product identification pending
Reporter: PSIRT
9.3
CRITICAL
VIEW RECORD
CVE-2026-91130
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.3
CRITICAL
VIEW RECORD
CVE-2026-47116
LTK3500SF
Reporter: DISCLOSURE
9.3
CRITICAL
VIEW RECORD
CVE-2026-87121
Product identification pending
Reporter: ICS-CERT
9.3
CRITICAL
VIEW RECORD
CVE-2026-77987
Enterprise Server PATCH
Reporter: PRODUCT-CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-96257
FAC1203R Gigabit Edition
Reporter: CNA
9.3
CRITICAL
VIEW RECORD
CVE-2026-18461
Product identification pending PATCH
Reporter: 3F572A00-62E2-4423-959A-7EA25EFF1638
9.2
CRITICAL
VIEW RECORD
CVE-2026-43642
Virtualizor PATCH
Reporter: DISCLOSURE
9.2
CRITICAL
VIEW RECORD
CVE-2026-95654
Product identification pending PATCH
Reporter: DISCLOSURE
9.1
CRITICAL
VIEW RECORD
CVE-2026-85734
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-94456
postiz-app
Reporter: 4CDC9741-F887-419A-A2FD-ACBBD2729276
9.1
CRITICAL
VIEW RECORD
CVE-2026-75728
Product identification pending
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-82009
Product identification pending
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-82011
Product identification pending
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-77254
mcp-atlassian PATCH
Reporter: SECURITY-ADVISORIES
9.1
CRITICAL
VIEW RECORD
CVE-2026-81995
Product identification pending
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-17635
Product identification pending
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-17645
Product identification pending
Reporter: PSIRT
9.1
CRITICAL
VIEW RECORD
CVE-2026-19202
Product identification pending
Reporter: CVE-COORDINATION
9.1
CRITICAL
VIEW RECORD
CVE-2026-75799
YAHMAN Add-ons PATCH
Reporter: CONTACT
9
CRITICAL
VIEW RECORD
CVE-2026-82843
WP OAuth Server ( Login with WordPress ) PATCH
Reporter: CONTACT
9
CRITICAL
VIEW RECORD
CVE-2026-80154
SLC8000
Reporter: DISCLOSURE
8.9
HIGH
VIEW RECORD
CVE-2026-65128
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-65179
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-70410
Product identification pending PATCH
Reporter: SECURITY
8.8
HIGH
VIEW RECORD
CVE-2026-13087
Red Hat Enterprise Linux 10
Reporter: SECALERT
8.8
HIGH
VIEW RECORD
CVE-2026-77243
mcp-atlassian PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-77274
mcp-atlassian PATCH
Reporter: SECURITY-ADVISORIES
8.8
HIGH
VIEW RECORD
CVE-2026-28325
Observability Self-Hosted
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-88419
Product identification pending
Reporter: CVE
8.8
HIGH
VIEW RECORD
CVE-2026-16468
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-16469
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-16672
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-17102
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-17636
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-17637
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-17643
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-17644
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-17647
Product identification pending
Reporter: PSIRT
8.8
HIGH
VIEW RECORD
CVE-2026-91798
Foxit PDF Editor
Reporter: 14984358-7092-470D-8F34-ADE47A7658A2
8.8
HIGH
VIEW RECORD
CVE-2026-91800
Foxit PDF Editor
Reporter: 14984358-7092-470D-8F34-ADE47A7658A2
8.8
HIGH
VIEW RECORD
CVE-2026-91803
Foxit PDF Editor
Reporter: 14984358-7092-470D-8F34-ADE47A7658A2
8.8
HIGH
VIEW RECORD
CVE-2026-91813
Foxit PDF Editor
Reporter: 14984358-7092-470D-8F34-ADE47A7658A2
8.8
HIGH
VIEW RECORD
CVE-2026-96455
Reachy Mini
Reporter: REEFS
8.8
HIGH
VIEW RECORD
CVE-2026-77619
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-77620
Product identification pending PATCH
Reporter: SECURITY-ADVISORIES
8.7
HIGH
VIEW RECORD
CVE-2026-95653
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.