ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-73475
Incorrect Authorization (Forceful Browsing) in Drupal Commerce PayPal

Commerce PayPal, the PayPal payment-gateway integration module for Drupal Commerce maintained by Centarro, contains an incorrect authorization flaw (CWE-863) that Drupal classifies as Forceful Browsing. Because the module fails to correctly enforce its access checks, an unauthenticated remote attacker can request protected routes or endpoints handled by the module and reach content or functionality they should not be able to access; the CVSS vector (network vector, no privileges, no user interaction, high confidentiality and integrity impact, no availability impact) indicates the attacker can both read sensitive data and modify data or state. Every published version of the module is affected, since both the 1.x line through 1.12.0 and the 2.x line through 2.1.3 fall within the affected ranges, so any Drupal site running Commerce PayPal is exposed. There is currently no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns a low 0.2% probability of exploitation within 30 days, so no exploitation in the wild has been confirmed.

Do: Update Commerce PayPal to the first release published after 1.12.0 on the 1.x branch or after 2.1.3 on the 2.x branch, distributed via drupal.org. Until patched, review web-server logs for unauthenticated requests to the module's routes and audit recent PayPal orders and transactions for unauthorized access or changes. Take care that any network-level mitigation does not block PayPal's server-to-server callbacks (webhooks/IPN), which must remain publicly reachable.

9.1<1%
  • Centarro Commerce PayPal 0.0.0 through 1.12.0 (entire 1.x line up to and including 1.12.0)
  • Centarro Commerce PayPal 2.0.0 through 2.1.3 (entire 2.x line up to and including 2.1.3)
large≈10,000+ Drupal sites
CVE-2026-44210
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers.

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into the virtiofsd process through the `io.katacontainers.config.hypervisor.virtio_fs_extra_args` pod annotation. By injecting `-o source=/` along with `--no-announce-submounts` and `--sandbox=none`, an attacker can override the virtiofsd shared directory to serve the entire host root filesystem into the guest VM. Combined with the `kernel_params` annotation (also enabled by default) to activate the agent debug console, the attacker can mount the host filesystem from inside the VM and read or write any file on the host, including /etc/shadow. Version 3.31.0 patches the issue.

NVD description · AI analysis pending
5.8<1% PoC
  • katacontainers kata containers
CVE-2026-10770
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS.

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Anti-Spam by CleanTalk allows Reflected XSS. This issue affects Anti-Spam by CleanTalk versions: from 0.0.0 to 9.7.1.

NVD description · AI analysis pending
6.1<1%
  • cleantalk anti-spam
CVE-2026-10769
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Commerce Core allows Stored XSS.

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Commerce Core allows Stored XSS. This issue affects Commerce Core versions: from 3.3.0 to 3.3.6.

NVD description · AI analysis pending
5.4<1%
  • centarro commerce core