VulncastBriefing archive

Daily Brief - 2026-10-05

· 3 vulnerabilities · 5 min listen

▶ Listen to this briefing

CVE-2026-104118

Razorpay for WooCommerce

The Razorpay for WooCommerce WordPress plugin before 4.8.8 does not perform ownership or authorization checks on a REST API route used during checkout, allowing unauthenticated attackers to modify the shipping information stored on arbitrary orders.

  • Insecure Direct Object Reference
  • wordpress plugin
  • rest api

CVE-2026-105215

critical · CVSS 9.1 · ZITADEL

ZITADEL before 3.4.14 and 4.x before 4.16.2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback. Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.

  • Authentication Bypass
  • identity provider
  • web application

CVE-2026-88779

Citrix NetScaler

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

  • Unknown
  • load balancer
  • gateway