Critical Alert 4 Active Exploits Detected Today

CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability →
CVE-2026-81963 Microsoft Windows Link Following Vulnerability →
CVE-2026-86218 N-able N-central Static Code Injection Vulnerability →
CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower


← Back to CVE List

CVE-2026-77635NVD

Vulnerability Summary

### Impact
The `FunctionsBuilder::jsonValue($field, $jsonPath)` methods with the Postgres driver is vulnerable to SQL injection if user controlled data is supplied to the `$jsonPath` parameter.

### Patches
5.1.10, 5.2.15, 5.3.7

### Workarounds
Don't provide user controlled data to these functions/parameters.
Severity Level
CRITICAL
Published Date
Sep 8, 2026
Last Modified
Sep 8, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.29%Probability
Root Weakness (CWE)
N/A

External References