← Back to the live CVE advisory feed

CVE-2026-86260: hosp_order

Severity
5.5 (MEDIUM)
Vendor
SFTURING
Affected versions
627f426331da8086ce8fff2017d65b1ddef384f8
Patch status
Unknown
Published
2026-09-07T03:17:17.647
Modified
2026-09-07T03:17:17.647

Why it matters

Vulnerability requiring standard triage and vendor validation.

Recommended admin actions

  • Review during normal vulnerability triage unless the affected system is internet-facing or business-critical.
  • Compare installed versions against the affected version range in the advisory.
  • Treat internet-facing systems as higher priority.

Technical summary

A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of the component Password Recovery. Performing a manipulation results in unverified password change. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The project was informed of the problem early through an issue report but has not responded yet.

CVE data is sourced from NVD/CNA records and optional enrichment. Validate against the vendor advisory before taking production action.

VULNERABILITY PULSE

LAST UPDATED: SEP 07, 2026 04:00 AM UTC
116 RECORDS
SECURE FEED ACTIVE
AFFECTED PRODUCT ACTION
CVE-2026-16876
UNIVERGE IX-R/IX-V
Reporter: PSIRT-INFO
9.3
CRITICAL
VIEW RECORD
CVE-2026-86259
OpenMAIC PATCH
Reporter: DISCLOSURE
9
CRITICAL
VIEW RECORD
CVE-2026-86165
HG10
Reporter: CNA
8.9
HIGH
VIEW RECORD
CVE-2026-18480
SureCart PATCH
Reporter: CONTACT
8.8
HIGH
VIEW RECORD
CVE-2026-19633
PostgreSQL Anonymizer PATCH
Reporter: F86EF6DC-4D3A-42AD-8F28-E6D5547A5007
8.8
HIGH
VIEW RECORD
CVE-2022-51009
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86250
Product identification pending PATCH
Reporter: DISCLOSURE
8.7
HIGH
VIEW RECORD
CVE-2026-86167
HG10
Reporter: CNA
8.6
HIGH
VIEW RECORD
CVE-2026-82750
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
8.3
HIGH
VIEW RECORD
CVE-2026-82751
Product identification pending PATCH
Reporter: 6B3AD84C-E1A6-4BF7-A703-F496B71E49DB
8.3
HIGH
VIEW RECORD
CVE-2026-86251
Product identification pending PATCH
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-86253
h3 PATCH
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-86258
Product identification pending
Reporter: DISCLOSURE
8.2
HIGH
VIEW RECORD
CVE-2026-86242
Product identification pending PATCH
Reporter: REEFS
8.1
HIGH
VIEW RECORD
CVE-2026-86313
Product identification pending
Reporter: PSIRT
7.8
HIGH
VIEW RECORD
CVE-2026-84219
Kirki PATCH
Reporter: CONTACT
7.5
HIGH
VIEW RECORD
CVE-2026-86166
HG10
Reporter: CNA
7.4
HIGH
VIEW RECORD
CVE-2020-37277
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2021-48007
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-86255
Product identification pending PATCH
Reporter: DISCLOSURE
7.1
HIGH
VIEW RECORD
CVE-2026-86283
MISP
Reporter: 5A6E4751-2F3F-4070-9419-94FB35B644E8
7.1
HIGH
VIEW RECORD
CVE-2022-51008
Product identification pending PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-86252
Product identification pending PATCH
Reporter: DISCLOSURE
6.9
MEDIUM
VIEW RECORD
CVE-2026-84028
Bold Page Builder PATCH
Reporter: CONTACT
6.8
MEDIUM
VIEW RECORD
CVE-2026-75793
SureCart PATCH
Reporter: CONTACT
6.5
MEDIUM
VIEW RECORD
CVE-2026-19859
JetFormBuilder PATCH
Reporter: CONTACT
6.5
MEDIUM
VIEW RECORD
CVE-2026-19634
PostgreSQL Anonymizer PATCH
Reporter: F86EF6DC-4D3A-42AD-8F28-E6D5547A5007
6.4
MEDIUM
VIEW RECORD
CVE-2026-83534
PostgreSQL Anonymizer PATCH
Reporter: F86EF6DC-4D3A-42AD-8F28-E6D5547A5007
6.4
MEDIUM
VIEW RECORD
CVE-2026-86314
Walrus
Reporter: PSIRT
6.2
MEDIUM
VIEW RECORD
CVE-2026-86254
wger
Reporter: DISCLOSURE
6.1
MEDIUM
VIEW RECORD
CVE-2026-86168
Content Management System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86179
Daily Expense Manager
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86180
Task Management System In PHP
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86183
diem
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86208
Class and Exam Timetabling System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86209
Class and Exam Timetabling System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86210
Class and Exam Timetabling System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86211
inventory-management-system
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86213
College-Management-System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86214
Mstfakts College-Management-System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86217
Hotel and Tourism Reservation in PHP
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86220
Class and Exam Timetabling System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86221
Class and Exam Timetabling System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86222
Class and Exam Timetabling System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86223
Class and Exam Timetabling System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86224
Class and Exam Timetabling System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86225
Class and Exam Timetabling System
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86237
openagents
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86239
FeehiCMS
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86260
hosp_order
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86261
hosp_order
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86262
hosp_order
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-86263
hosp_order
Reporter: CNA
5.5
MEDIUM
VIEW RECORD
CVE-2026-85038
B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More PATCH
Reporter: CONTACT
5.3
MEDIUM
VIEW RECORD
CVE-2026-86205
Product identification pending PATCH
Reporter: DISCLOSURE
5.3
MEDIUM
VIEW RECORD
CVE-2026-86256
Product identification pending PATCH
Reporter: DISCLOSURE
5.1
MEDIUM
VIEW RECORD
CVE-2026-19862
JetFormBuilder PATCH
Reporter: CONTACT
4.8
MEDIUM
VIEW RECORD
CVE-2026-80437
Ninja Forms PATCH
Reporter: CONTACT
4.8
MEDIUM
VIEW RECORD
CVE-2026-80439
Redirection for Contact Form 7 PATCH
Reporter: CONTACT
4.8
MEDIUM
VIEW RECORD
CVE-2021-48006
Product identification pending PATCH
Reporter: DISCLOSURE
4.8
MEDIUM
VIEW RECORD
CVE-2026-86257
Product identification pending PATCH
Reporter: DISCLOSURE
4.8
MEDIUM
VIEW RECORD
CVE-2026-13159
Real Estate Papi
Reporter: CONTACT
4.3
MEDIUM
VIEW RECORD
CVE-2026-86231
jsch PATCH
Reporter: CNA
2.9
LOW
VIEW RECORD
CVE-2026-86163
Sales and Inventory System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86164
Sales and Inventory System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86170
CRM
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86171
CRM
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86172
CRM
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86182
diem
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86212
Open5GS
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86215
College-Management-System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86216
Hotel and Tourism Reservation in PHP
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86228
JeecgBoot PATCH
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86232
Sales and Inventory System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86233
Sales and Inventory System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86234
Sales and Inventory System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86235
Sales and Inventory System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86236
Sales and Inventory System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86238
Online Examination System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86241
FeehiCMS
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86244
FastAdmin PATCH
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86245
Sales and Inventory System
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86264
ssm_pro
Reporter: CNA
2.1
LOW
VIEW RECORD
CVE-2026-86181
Task Management System
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-86226
Online Attendance System
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-86240
FeehiCMS
Reporter: CNA
2
LOW
VIEW RECORD
CVE-2026-86227
valkey
Reporter: CNA
1.3
LOW
VIEW RECORD
CVE-2026-13608
curl
Reporter: 2499F714-1537-4658-8207-48AE4BB9EAE9
0
N/A
VIEW RECORD
CVE-2026-18924
curl
Reporter: 2499F714-1537-4658-8207-48AE4BB9EAE9
0
N/A
VIEW RECORD
CVE-2026-19931
curl
Reporter: 2499F714-1537-4658-8207-48AE4BB9EAE9
0
N/A
VIEW RECORD
CVE-2026-80229
curl
Reporter: 2499F714-1537-4658-8207-48AE4BB9EAE9
0
N/A
VIEW RECORD
CVE-2026-80230
curl
Reporter: 2499F714-1537-4658-8207-48AE4BB9EAE9
0
N/A
VIEW RECORD
CVE-2026-80231
curl
Reporter: 2499F714-1537-4658-8207-48AE4BB9EAE9
0
N/A
VIEW RECORD
CVE-2026-80255
curl
Reporter: 2499F714-1537-4658-8207-48AE4BB9EAE9
0
N/A
VIEW RECORD
CVE-2026-82208
curl
Reporter: 2499F714-1537-4658-8207-48AE4BB9EAE9
0
N/A
VIEW RECORD
CVE-2026-82209
curl
Reporter: 2499F714-1537-4658-8207-48AE4BB9EAE9
0
N/A
VIEW RECORD
CVE-2026-86219
Authen-SASL PATCH
Reporter: 9B29ABF9-4AB0-4765-B253-1875CD9B441E
0
N/A
VIEW RECORD
CVE-2026-86304
Product identification pending PATCH
Reporter: 9B29ABF9-4AB0-4765-B253-1875CD9B441E
0
N/A
VIEW RECORD
CVE-2026-20500
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD
CVE-2026-20501
Product identification pending
Reporter: SECURITY
0
N/A
VIEW RECORD

About the Vulnerability Pulse CVE Feed

The Vulnerability Pulse feed tracks live CVE advisories sourced from the National Vulnerability Database and vendor security disclosures. It is designed for SOC analysts, IT administrators, and security teams who need a fast, filterable view of current vulnerabilities without digging through raw NVD data.

How to Use the CVE Advisory Tracker

Use the severity filters to narrow results to Critical or High priority vulnerabilities. Filter by vendor to focus on software and hardware relevant to your environment. Export to CSV for reporting, ticketing, or patch prioritization workflows.

What Is a CVE Advisory?

A CVE (Common Vulnerabilities and Exposures) advisory is a public disclosure of a security vulnerability assigned a unique identifier by MITRE. Advisories include severity scores (CVSS), affected versions, and remediation guidance. Monitoring CVE advisories is a core function of vulnerability management programs and SOC operations.

CVE Analysis & Writeups

For in-depth analysis of specific vulnerabilities, visit the IT Knowledge Bases blog for CVE breakdowns, exploitation analysis, and remediation guidance written for security practitioners.