Nuclei Templates v10.4.9 - Release Notes
New Templates Added: 123 | CVEs Added: 85 | First-time contributions: 15 🔥 Release Highlights 🔥 [ CVE-2026-86207 ] N-able N-central - Authentication Bypass ( @rapid7 , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-85706 ] GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File Read ( @flx ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-83548 ] SonicWall SMA1000 WorkPlace - Unauthenticated SSRF to CouchDB ( @rapid7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82329 ] JFrog Artifactory Access Blank Join Key Authentication Bypass ( @johnk3r , @pruva ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-82222 ] GiveWP <= 4.16.7.1 - Remote Code Execution (@0x_Akoko, @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-81578 ] PaperCut NG/MF <=26.0.4 - Unauthenticated ConfigEditor Access via Tapestry Complex-Direct ( @darses , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-73570 ] Zimbra Collaboration Suite < 10.1.20 - OS Command Injection (@0x_Akoko, @ritikchaddha ) [high] (kev) (vKEV) 🔥 [ CVE-2026-55040 ] Microsoft SharePoint Server - JWT Authentication Bypass ( @sfewer-r7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-48558 ] SimpleHelp <=5.5.15 - OIDC JWT Authentication Bypass (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-41948 ] Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-32475 ] Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form Handler ( @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-18963 ] Keycloak < 26.7.2 - Unauthenticated Account Takeover via Reset-Credentials Bypass ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-18577 ] N-able N-central < 2026.3.1.10 - Authentication Bypass ( @patrick-threatmate ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-9586 ] Sangoma Switchvox < 8.4.0.2 - Unauthenticated SQL Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-1281 ] Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection ( @rxerium ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-0768 ] Langflow <=1.2.x - Unauthenticated Remote Code Execution via validate_code ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2024-1708 ] ConnectWise ScreenConnect <= 23.9.7 - Path Traversal ( @Popy21 ) [high] (kev) (vKEV) 🔥 [ CVE-2023-54391 ] Proxmox VE - Default Credentials with TFA Bypass ( @dhiyaneshdk , @0x_Akoko) [critical] (vKEV) 🔥 [ CVE-2020-10221 ] rConfig <= 3.9.4 - Authenticated OS Command Injection ( @Jayachandran from Securin Labs ( https://securin.io )) [high] (kev) (vKEV) 🔥 [ CVE-2019-11043 ] PHP-FPM Path Info Buffer Underflow - Remote Code Execution ( @prasath from Securin Labs ( https://securin.io )) [critical] (kev) (vKEV) 🔥 [ CVE-2017-7504 ] JBossMQ HTTP Invocation Layer (HTTPServerILServlet) - Unauthenticated Java Deserialization ( @Jayachandran ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Fixed the CVE-2026-41042 template filename so the template loads correctly (PR #17024 , Issue #17022 ). Corrected the filename casing on CVE-2025-14047 .yaml (PR #16994 ). Resolved an unresolved nested payload variable in CVE-2026-4257 that stopped the WordPress Contact Form by Supsystic template running on nuclei v3.11.1 (PR #17039 ). Fixed the matched_feature extractor in CVE-2026-76904 .yaml (PR #16969 ). Corrected the author field in CVE-2026-61511 .yaml (PR #16976 ). Removed six imprecise CVE templates whose proofs of concept were not reliable — CVE-2016-3714 , CVE-2018-10933 , CVE-2018-15708 , CVE-2019-8942 , CVE-2019-17554 and CVE-2020-2555 (PR #16567 ). False Negatives CVE-2021-43798 — the Grafana arbitrary file read template now fires on instances sitting behind an nginx reverse proxy (PR #17185 ). CVE-2018-3760 — restored broken detection on Ruby on Rails local file inclusion using disable-path-automerge and a flow block (PR #17235 ). CVE-2021-34429 — replaced unsafe with disable-path-automerge so the Jetty request path is no longer duplicated (PR #17236 ). CVE-2024-52433 — the My Geo Posts Free template could never match a genuin