CVE-2026-76986: Product identification pending
- Severity
- 6.1 (MEDIUM)
- Vendor
- APACHE
- Affected versions
- Through 8.18.0
- Fixed version
- 8.19.0
- Patch status
- Patched
- Published
- 2026-08-31T14:17:23.497
- Modified
- 2026-08-31T15:17:48.107
Why it matters
This matters because the affected product may allow code execution. Prioritize systems that are internet-facing or have privileged access to other infrastructure.
Recommended admin actions
- Review during normal vulnerability triage unless the affected system is internet-facing or business-critical.
- Compare installed versions against the affected version range in the advisory.
- Review logs for suspicious activity related to the affected application or component.
Technical summary
Improper neutralization of input during web page generation in Apache Wicket. org.apache.wicket.markup.html.form.AbstractSingleSelectChoice, the base class of DropDownChoice, writes the body of the default option — the entry shown when no choice is selected — into the markup as it is, while every other option body in the same select is escaped according to the escape-model-strings setting. The body comes from getNullValidDisplayValue() or getNullKeyDisplayValue(), both of which are protected, so what they return is not necessarily the plain text the default implementation reads from a resource bundle. An application is affected where it overrides one of those methods and returns a value holding data an attacker can influence, or where its own nullValid or null bundle entry holds such a value. The bundles shipped with Wicket contain plain text. RadioChoice overrides getDefaultChoice to emit no default option and is not affected. As a workaround, escape the value in the override. This issue affects Apache Wicket: from 8.0.0 through 8.18.0, from 9.0.0 through 9.23.0, from 10.0.0 through 10.10.0. Older, unsupported releases from 1.5.0 onwards are also affected. Users are recommended to upgrade to version 8.19.0, 9.24.0 or 10.11.0, which fix the issue.
View the official NVD record for CVE-2026-76986
CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.
VULNERABILITY PULSE
| AFFECTED PRODUCT | ACTION | ||
|---|---|---|---|
| CVE-2026-77956 |
ash_ai PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
10
CRITICAL
|
VIEW RECORD |
| CVE-2026-82970 |
WP Cookie Notice for GDPR, CCPA & ePrivacy Consent PATCH
Reporter: AUDIT
|
10
CRITICAL
|
VIEW RECORD |
| CVE-2026-58574 |
PowerStore 500T
Reporter: SECURITY_ALERT
|
9.8
CRITICAL
|
VIEW RECORD |
| CVE-2026-49003 |
ZXDU68 S202 V5.0
Reporter: PSIRT
|
9.6
CRITICAL
|
VIEW RECORD |
| CVE-2026-19410 |
Google Cloud Build PATCH
Reporter: F45CBF4E-4146-4068-B7E1-655FFC2C548C
|
9.4
CRITICAL
|
VIEW RECORD |
| CVE-2026-82628 |
iGameCenter
Reporter: CNA
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82854 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82855 |
policies PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82856 |
policies PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82857 |
hulumi PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82858 |
drift PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82859 |
hulumi PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82860 |
policies PATCH
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82876 |
PS3111-S11 Controller Firmware
Reporter: DISCLOSURE
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82693 |
AC1206
Reporter: CNA
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82694 |
AC1206
Reporter: CNA
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-82695 |
AC18
Reporter: CNA
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-59111 |
eObčanka-Identifikace PATCH
Reporter: A6D3DC9E-0591-4A13-BCE7-0F5B31FF6158
|
9.3
CRITICAL
|
VIEW RECORD |
| CVE-2026-66047 |
ProfilePress PATCH
Reporter: DISCLOSURE
|
9.2
CRITICAL
|
VIEW RECORD |
| CVE-2026-82866 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.9
HIGH
|
VIEW RECORD |
| CVE-2026-78078 |
Helix Ultimate extension for Joomla
Reporter: SECURITY
|
8.9
HIGH
|
VIEW RECORD |
| CVE-2026-12894 |
Product identification pending
Reporter: SECALERT
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-5956 |
Product identification pending
Reporter: ILETISIM
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-78074 |
miniOrange Oauth Client (free) extension for Joomla
Reporter: SECURITY
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-82217 |
Product identification pending
Reporter: EMO
|
8.8
HIGH
|
VIEW RECORD |
| CVE-2026-81636 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-56718 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-82861 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-82863 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-82880 |
Product identification pending
Reporter: DISCLOSURE
|
8.7
HIGH
|
VIEW RECORD |
| CVE-2026-82592 |
DIR-825M
Reporter: CNA
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-82593 |
DIR-825M
Reporter: CNA
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-82616 |
NR1800X
Reporter: CNA
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-82862 |
hulumi PATCH
Reporter: DISCLOSURE
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-82689 |
DNS-320L
Reporter: CNA
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-82692 |
DNS-340L
Reporter: CNA
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-78077 |
Helix Ultimate extension for Joomla
Reporter: SECURITY
|
8.6
HIGH
|
VIEW RECORD |
| CVE-2026-82688 |
DNS-340L
Reporter: CNA
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-82690 |
DNS-327L
Reporter: CNA
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-82691 |
DNS-320L
Reporter: CNA
|
8.5
HIGH
|
VIEW RECORD |
| CVE-2026-77850 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
8.4
HIGH
|
VIEW RECORD |
| CVE-2026-75757 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
8.3
HIGH
|
VIEW RECORD |
| CVE-2026-82673 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
8.3
HIGH
|
VIEW RECORD |
| CVE-2026-82722 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
8.3
HIGH
|
VIEW RECORD |
| CVE-2026-82662 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
8.3
HIGH
|
VIEW RECORD |
| CVE-2026-82869 |
ToolJet PATCH
Reporter: DISCLOSURE
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-82871 |
ToolJet PATCH
Reporter: DISCLOSURE
|
8.2
HIGH
|
VIEW RECORD |
| CVE-2026-19702 |
Product identification pending PATCH
Reporter: ILETISIM
|
7.8
HIGH
|
VIEW RECORD |
| CVE-2026-82724 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
7.6
HIGH
|
VIEW RECORD |
| CVE-2026-81624 |
Product identification pending
Reporter: SECALERT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-19616 |
Product identification pending
Reporter: ILETISIM
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-76763 |
Product identification pending
Reporter: SECALERT
|
7.5
HIGH
|
VIEW RECORD |
| CVE-2026-81315 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
7.4
HIGH
|
VIEW RECORD |
| CVE-2026-82680 |
DSM-G600
Reporter: CNA
|
7.4
HIGH
|
VIEW RECORD |
| CVE-2026-78422 |
Product identification pending PATCH
Reporter: MEISSNER
|
7.3
HIGH
|
VIEW RECORD |
| CVE-2026-78699 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
7.2
HIGH
|
VIEW RECORD |
| CVE-2026-80223 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-75760 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-82564 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-82659 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-82864 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-82872 |
ToolJet PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-82877 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
7.1
HIGH
|
VIEW RECORD |
| CVE-2026-82870 |
ToolJet PATCH
Reporter: DISCLOSURE
|
7
HIGH
|
VIEW RECORD |
| CVE-2026-78693 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-81633 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-68951 |
GROWI
Reporter: VULTURES
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2024-58379 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-82853 |
Product identification pending PATCH
Reporter: DISCLOSURE
|
6.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-82838 |
venueless
Reporter: 655498C3-6EC5-4F0B-AEA6-853B334D05A6
|
6.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-82726 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
6.3
MEDIUM
|
VIEW RECORD |
| CVE-2026-76986 |
Product identification pending PATCH
Reporter: SECURITY
|
6.1
MEDIUM
|
VIEW RECORD |
| CVE-2026-82579 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
6
MEDIUM
|
VIEW RECORD |
| CVE-2026-81319 |
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
|
5.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-58301 |
Product identification pending PATCH
Reporter: SECURITY
|
5.9
MEDIUM
|
VIEW RECORD |
| CVE-2026-82549 |
Magma
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82550 |
Magma
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82551 |
Magma
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82598 |
SeaCMS
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82600 |
SeaCMS
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82602 |
SeaCMS
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82607 |
Profile Builder Plugin PATCH
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82610 |
Online Medicine Delivery System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82611 |
Online Medicine Delivery System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82612 |
Online Medicine Delivery System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82613 |
Online Medicine Delivery System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82614 |
Online Medicine Delivery System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82615 |
Online Medicine Delivery System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82621 |
StudentManagement
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82623 |
open62541
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82624 |
Simple Inventory System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82630 |
PowerJob
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82668 |
GitList PATCH
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82669 |
GitList PATCH
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82797 |
Product identification pending PATCH
Reporter: PSIRT
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82698 |
Student-Management-System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82701 |
Online Shopping System
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-82801 |
earthdata-search
Reporter: CNA
|
5.5
MEDIUM
|
VIEW RECORD |
| CVE-2026-40464 |
NSP PATCH
Reporter: B48C3B8F-639E-4C16-8725-497BC411DAD0
|
5.4
MEDIUM
|
VIEW RECORD |
| CVE-2026-82588 |
Product identification pending
Reporter: CNA
|
5.3
MEDIUM
|
VIEW RECORD |
About the Vulnerability Pulse CVE Feed
The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.
How to Use the CVE Advisory Tracker
Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.
What Is a CVE Advisory?
A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.
CVE Analysis & Writeups
For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.