Siste sårbarheter

Siste 90 dager. Kilder: NVD (produktsøk), CVE.org (referansedata), CISA Known Exploited Vulnerabilities. Nyeste oppføring fra 4. okt. 2026.

278 oppføringer

  • Citrix NetScaler 8.7 KEV CVE-2026-88779 Memory overflow vulnerability leading to Denial of Service 4. okt. 2026

    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

    Produsent
    NetScaler · ADC
    Type svakhet
    CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
    Publisert
    4. okt. 2026
    I KEV-katalogen siden
    4. okt. 2026
  • Zammad 8.5 KEV CVE-2026-102490 Undisclosed LPE in Zammad v1.5.0 to v7.1.0-alpha 2. okt. 2026

    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

    Produsent
    Zammad GmbH · Zammad
    Type svakhet
    CWE-269: Improper Privilege Management
    CVSS 4.0
    CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/AU:Y/V:D
    Publisert
    30. sep. 2026
    I KEV-katalogen siden
    2. okt. 2026
  • Zammad 8.7 KEV CVE-2026-102489 Undisclosed RCE in Zammad v6.3 and higher 2. okt. 2026

    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

    Produsent
    Zammad GmbH · Zammad
    Type svakhet
    CWE-384: Session Fixation
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:A/AU:Y/V:C
    Publisert
    30. sep. 2026
    I KEV-katalogen siden
    2. okt. 2026
  • Microsoft Exchange Server 8.8 CVE-2026-96940 Microsoft Exchange Server Elevation of Privilege Vulnerability 2. okt. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-1390: Weak Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    2. okt. 2026
  • Fortinet FortiMail 9.8 KEV CVE-2026-104286 Fortinet FortiMail: Path Traversal 1. okt. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

    Produsent
    Fortinet · FortiMail
    Produktområde
    FortiMail
    Type svakhet
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
    Publisert
    1. okt. 2026
    I KEV-katalogen siden
    1. okt. 2026
  • Kiteworks Email Protection Gateway 9.4 CVE-2026-102149 Kiteworks Email Protection Gateway Improper Access Control 30. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail and, where certificate-based login is enabled, potentially permitting unauthorized access to the account.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-306: Missing Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 5.3 CVE-2026-102144 Kiteworks Email Protection Gateway Uncontrolled Resource Consumption 30. sep. 2026

    A resource exhaustion vulnerability in Kiteworks Email Protection Gateway allowed an unauthenticated remote attacker to repeatedly trigger a comparatively expensive server-side operation, causing a partial denial of service.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-306: Missing Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 6.5 CVE-2026-102139 Kiteworks Email Protection Gateway Incorrect Authorization 30. sep. 2026

    An authorization check in the large file exchange feature of Kiteworks Email Protection Gateway did not correctly establish that the requesting user was a party to the package being requested. An authenticated user of that optional feature could read the subject, message body, and attachments of packages they neither sent nor received.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-639: Authorization Bypass Through User-Controlled Key
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 6.6 CVE-2026-102135 Kiteworks Email Protection Gateway Deserialization of Untrusted Data 30. sep. 2026

    On a Kiteworks Email Protection Gateway cluster with database replication enabled, a party trusted by the cluster could submit a crafted serialized object that was deserialized without sufficient validation, potentially allowing code execution as the gateway service account. Replication is disabled by default, and exploitation requires control of a trusted cluster peer or administrative access to the appliance.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102131 Kiteworks Email Protection Gateway Improper Handling of Case Sensitivity 30. sep. 2026

    Kiteworks Email Protection Gateway rejected certain configuration settings, but its validation did not recognize every form in which they could be supplied. An authenticated administrator could potentially use an unrecognized form to have a file of their choosing written to the gateway and executed, resulting in code execution as the gateway service account.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102130 Kiteworks Email Protection Gateway Remote Code Execution 30. sep. 2026

    Kiteworks Email Protection Gateway did not sufficiently validate the content of an uploaded backup, and allowed an administrator to influence how the application loaded it. An authenticated administrator could potentially use this to execute arbitrary code on the gateway as the underlying service account.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 7.5 CVE-2026-102128 Kiteworks Email Protection Gateway Improper Authentication 30. sep. 2026

    An identity-verification weakness in Kiteworks Email Protection Gateway allowed the gateway to act on the Kiteworks platform on behalf of a user it had not authenticated, and to provision a platform account for an identity it did not already know. A remote, unauthenticated sender could potentially exploit this to obtain control of a platform account.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 7.0 CVE-2026-102127 Kiteworks Email Protection Gateway Improper Restriction of XML External Entity Reference 30. sep. 2026

    An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an optional, non-default message-processing feature is enabled, a remote and unauthenticated sender could potentially use a crafted message to read files accessible to the gateway service account, including cryptographic key material and credentials, and have them sent to a destination they control.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-611: XML External Entity
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102116 Kiteworks Email Protection Gateway Path Traversal 30. sep. 2026

    -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102108 Kiteworks Email Protection Gateway deserialization of untrusted data 30. sep. 2026

    An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102106 Kiteworks Email Protection Gateway improper authentication 30. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who referenced a valid administrator account could potentially create, modify, or delete internal users and managed domains and change their security-feature configuration without authenticating; deleting a managed domain also removes its user accounts and could lock administrators out of the gateway.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102105 Kiteworks Email Protection Gateway server-side request forgery 30. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway renders message content that references external resources. Depending on the services reachable from the gateway, this could disclose sensitive internal information or trigger unintended actions on internal systems.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102104 Kiteworks Email Protection Gateway server-side request forgery 30. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway performs an online certificate status check for an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102103 Kiteworks Email Protection Gateway server-side request forgery 30. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves a certificate revocation list in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102102 Kiteworks Email Protection Gateway server-side request forgery 30. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted requests to internal or otherwise unintended network destinations. The requests are triggered while the gateway retrieves an issuer certificate in an inbound message. Depending on the services reachable from the gateway, this could disclose sensitive internal information or disrupt gateway operation.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102097 Kiteworks Email Protection Gateway remote code execution 30. sep. 2026

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 9.1 CVE-2026-102095 Kiteworks Email Protection Gateway server-side request forgery 30. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message content it processed, without adequately restricting the fetch destination. A remote, unauthenticated sender could craft a message that caused the gateway to issue requests to internal services and cloud instance metadata endpoints and return the responses, potentially disclosing sensitive internal data and, depending on the internal service reached, affecting its state.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102094 Kiteworks Email Protection Gateway unsafe reflection 30. sep. 2026

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code that the mail-processing pipeline could load from an imported rule configuration. An authenticated administrator with mail-rule configuration privileges could cause the gateway to load and execute code beyond the approved set of mail-processing components, potentially in the context of the mail-gateway service account.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Publisert
    30. sep. 2026
  • Kiteworks Email Protection Gateway 7.2 CVE-2026-102089 Kiteworks Email Protection Gateway path traversal 30. sep. 2026

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.

    Produsent
    Kiteworks · Email Protection Gateway
    Produktområde
    totemomail / Kiteworks
    Type svakhet
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Publisert
    30. sep. 2026
  • Cisco Catalyst SD-WAN Manager 9.8 KEV CVE-2026-76504 Cisco Catalyst SD-WAN Manager System Account Authorization Bypass Vulnerability 30. sep. 2026

    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

    Produsent
    Cisco · Cisco Catalyst SD-WAN Manager
    Type svakhet
    CWE-177
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    30. sep. 2026
    I KEV-katalogen siden
    30. sep. 2026
  • Apple Multiple Products 8.8 KEV CVE-2026-86950 Apple iOS and iPadOS: Out-of-bounds Write 29. sep. 2026

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

    Produsent
    Apple · iOS and iPadOS
    Type svakhet
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    Publisert
    28. sep. 2026
    I KEV-katalogen siden
    29. sep. 2026
  • OpenSSL 7.5 CVE-2026-84784 QUIC: Unbounded RETIRE_CONNECTION_ID Backlog 29. sep. 2026

    Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    29. sep. 2026
  • OpenSSL 7.5 CVE-2026-84783 Use-After-Free in X.509 Extension Cache Under Concurrent Use 29. sep. 2026

    Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    29. sep. 2026
  • OpenSSL 5.3 CVE-2026-75805 NULL Pointer Dereference in CMP Client Revocation Response Handling 29. sep. 2026

    Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response. Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application. CWE: CWE-476: NULL-pointer dereference Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API. A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash. The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-476: NULL-pointer dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    Publisert
    29. sep. 2026
  • OpenSSL 5.3 CVE-2026-75804 QUIC Connection-Level Flow Control is Not Enforced for Streams 29. sep. 2026

    Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    Publisert
    29. sep. 2026
  • OpenSSL 7.5 CVE-2026-72897 Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake 29. sep. 2026

    Issue summary: A TLS server that calls SSL_set_SSL_CTX() to switch a connection to a different SSL_CTX part way through a handshake may access memory beyond the end of an internal array if the replacement context knows about more provider signature algorithms than the context the connection was created from. Applications which never call SSL_set_SSL_CTX() are not affected. Impact summary: A remote peer may be able to cause a small out-of-bounds read, and in some circumstances a fixed-value out-of-bounds write, on the server heap. This may lead to a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: A TLS connection records how many certificate slots it has when it is created, taken from the SSL_CTX that created it: the built-in certificate types plus one slot for each provider TLS-SIGALG entry that context was aware of. That count sizes an internal array of per-slot certificate validity flags. An application may replace a connection's SSL_CTX part way through the handshake by calling SSL_set_SSL_CTX(), most commonly from a servername callback in order to serve a different virtual host. Doing so did not refresh the recorded count. A provider signature algorithm's slot index is its position in the list of whichever context resolves it, so if the replacement context is aware of more of them than the original, an algorithm offered by the peer can resolve to an index beyond the end of the array. Processing the peer's signature algorithms then reads one four byte word past the end for each such algorithm and, where the word read is zero, writes a fixed value over it. A peer offering many of them can corrupt heap metadata and abort the process. Only provider signature algorithms which occupy one of the excess slots, and which the server also has configured, have this effect. Codepoints the replacement context does not recognise are discarded without being resolved to a slot, and provider signature algorithms are usable only from TLS 1.3. The two contexts must therefore be aware of different numbers of provider signature algorithms, which requires separate library contexts, a provider loaded between the two being created, or providers which differ in what they advertise - in 4.0, for example, the default provider advertises SM2 where the FIPS provider does not. A deployment meeting the condition is also unable to negotiate the affected algorithms with legitimate clients, since the same stale count hides the corresponding certificates, so the misconfiguration is likely to be noticed. For that reason, and because the configuration is not the default, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    29. sep. 2026
  • OpenSSL 3.7 CVE-2026-54875 Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V 29. sep. 2026

    Issue summary: A non-constant-time optimized implementation of scalar point multiplication is used for SM2 private key operations on ARM64 and RISC-V platforms. Impact summary: An attacker able to measure the time taken by, or to observe the cache-line access pattern of SM2 signing or decryption on an affected platform can learn information about the secret scalar. CWE: CWE-208: Observable Timing Discrepancy Description: On ARM64 and RISC-V processors, the SM2 curve uses an optimized scalar multiplication implementation whose conditional branches and table look ups are chosen according to the bits of the secret scalar. The execution time and the cache-access pattern therefore depend on the long-term private key (during SM2 decryption) or the per-signature nonce (during SM2 signature generation), forming a timing and cache side-channel. FIPS Impact: no SM2 is not a FIPS algorithm and the optimized SM2 implementation is not part of the FIPS module. OpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and RISC-V. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.5. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.9. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.8. This issue was reported on 2 May 2026 by Abhinav Agarwal. It was independently reported on 6 June 2026 by Feng Xue. The fix was developed by Igor Ustinov. -- cut (non-publishing metadata for internal use) -- Reported by: Abhinav Agarwal, Feng Xue Fixed by: Igor Ustinov

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-208: Observable Timing Discrepancy
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
    Publisert
    29. sep. 2026
  • OpenSSL 7.5 CVE-2026-54873 QUIC STREAM Fragment Metadata DoS 29. sep. 2026

    Issue summary: QUIC process may keep memory for QUIC packet buffer for much longer period than necessary. Impact summary: Remote peer can exploit this vulnerability by sending maliciously crafted packets, making the local QUIC stack to keep the memory for packet buffers allocated. The time for which the memory remains allocated is entirely under the control of the potentially malicious remote peer. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: To save copy operation from the packet buffer to the stream reassemble buffer the QUIC stack leaves the stream data on the packet buffer waiting to be copied to a buffer provided by the local receiving application. The QUIC stack releases a reference to the packet buffer only after the data are copied to the application buffer. This design is more efficient for legitimate data transfers but enables an attacker to allocate a lot more memory than actually required by the data kept in the receiving stream buffer. To mitigate the vulnerability, the QUIC stack now calculates and monitors memory overhead for every stream. The memory overhead for a single stream frame is calculated as a difference between the size of the whole packet that carries the stream frame and the size of the stream frame itself. The memory overhead for a single stream frame is added to the total (cumulative) memory overhead QUIC stack keeps for each stream. Once the cumulative memory overhead exceeds 64kB, the QUIC stack moves the stream frame data from the packet buffer to the stream buffer, starting with the next packet received. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    29. sep. 2026
  • OpenSSL 5.3 CVE-2026-42772 Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC 29. sep. 2026

    Issue summary: The QUIC stream reassembly algorithm performance deteriorates progressively as packets are arriving out of order. The worst case has a quadratic complexity proportional to the number of stream frames kept in the buffer for the received stream data. Impact summary: A remote QUIC peer that completes the handshake can create a connection-scoped CPU pressure and potentially a Denial of Service using compliant STREAM frames inside the advertised receive window, with low attacker bandwidth. CWE: CWE-407: Inefficient Algorithmic Complexity Description: OpenSSL manages received QUIC stream fragments using a doubly-linked list. While it optimizes for append operations (at the end of the list), it falls back to a head-to-tail linear search for any fragment that does not immediately follow the current `tail`. By manipulating the sequence of offsets, an attacker can force the server to perform O(n^2) operations, consuming excessive CPU time for the QUIC process. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-407: Inefficient Algorithmic Complexity
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    Publisert
    29. sep. 2026
  • OpenSSL 3.7 CVE-2026-35191 QUIC Unvalidated Amplification Credit may be Over Accounted 29. sep. 2026

    Issue summary: The OpenSSL QUIC server, when configured to not preform address validation, can be forced to count incoming packets multiple times in its unvalidated credit computation, leading to a violation of the RFC 9000 unvalidated connection amplification limit of 3 times the amount of data received. Impact summary: A remote attacker able to spoof packets to a server using the OpenSSL QUIC implementation might use the server for an amplification of a DDoS attack. CWE: CWE-440: Expected Behavior Violation Description: OpenSSL's QUIC stack, when operating as a server, enforces client address validation (RFC 9000, Section 8), to confirm the peer address is not used for a traffic amplification attack. If this feature is disabled on the server, the QUIC stack limits the amount of server data that can be sent to 3 times the amount of data received from the peer address, until such time as the TLS handshake is completed. The OpenSSL QUIC server, when operating in non-validation mode, adds the length of the whole datagram received to the unvalidated credit limit when processing each QUIC packet in the datagram. A remote peer may, after establishing a connection with an initial client hello frame, send a subsequent datagram containing multiple QUIC packets, leading the server to account the entire datagram length for each packet in the datagram, resulting in the server believing that the peer has sent more data than it actually has, thereby violating the 3x amplification limit mandated by the RFC. FIPS impact: no As the QUIC stack lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-440: Expected Behavior Violation
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
    Publisert
    29. sep. 2026
  • OpenSSL 5.3 CVE-2026-35189 Excessive Memory Allocation in Relative CRLDP Processing 29. sep. 2026

    Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    Publisert
    29. sep. 2026
  • Citrix NetScaler 9.5 KEV CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service 27. sep. 2026

    Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

    Produsent
    Citrix NetScaler · ADC
    Type svakhet
    CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
    CVSS 4.0
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Publisert
    27. sep. 2026
    I KEV-katalogen siden
    27. sep. 2026
  • Citrix NetScaler 9.5 KEV CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands 27. sep. 2026

    Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

    Produsent
    Citrix NetScaler · ADC
    Type svakhet
    CWE-20: Improper Input Validation
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Publisert
    27. sep. 2026
    I KEV-katalogen siden
    27. sep. 2026
  • Zimbra Collaboration Suite 9.3 CVE-2026-93647 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Crafted Calendar COUNTER Message From Address 25. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

    Produsent
    Zimbra · Zimbra Collaboration Suite (ZCS)
    Produktområde
    Webmail
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
    Publisert
    25. sep. 2026
  • Zimbra Collaboration Suite 9.3 CVE-2026-93642 Zimbra Collaboration Suite Modern Web Client Stored Cross-Site Scripting via Forged Share Invitation 25. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

    Produsent
    Zimbra · Zimbra Collaboration Suite (ZCS)
    Produktområde
    Webmail
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
    Publisert
    25. sep. 2026
  • Zimbra Collaboration Suite 9.3 CVE-2026-93641 Zimbra Collaboration Suite Classic Web Client Stored Cross-Site Scripting via Forged Share Invitation 25. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

    Produsent
    Zimbra · Zimbra Collaboration Suite (ZCS)
    Produktområde
    Webmail
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
    Publisert
    25. sep. 2026
  • WordPress Core 8.1 KEV CVE-2026-87902 WordPress: Remote File Inclusion 25. sep. 2026

    An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

    Produsent
    WordPress · WordPress
    Type svakhet
    CWE-98: Remote File Inclusion
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    22. sep. 2026
    I KEV-katalogen siden
    25. sep. 2026
  • MikroTik RouterOS 6.9 KEV CVE-2026-67279 SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS 25. sep. 2026

    RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

    Produsent
    Mikrotik · RouterOS
    Type svakhet
    CWE-841: Improper enforcement of behavioral workflow
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
    Publisert
    5. sep. 2026
    I KEV-katalogen siden
    25. sep. 2026
  • Microsoft SharePoint 8.8 KEV CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability 25. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

    Produsent
    Microsoft · Microsoft SharePoint
    Produktområde
    SharePoint
    Type svakhet
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
    I KEV-katalogen siden
    25. sep. 2026
  • Adobe Commerce and Magento 9.1 KEV CVE-2026-71362 Adobe Commerce | Incorrect Authorization (CWE-863) 24. sep. 2026

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

    Produsent
    Adobe · Adobe Commerce
    Type svakhet
    CWE-863: Incorrect Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
    Publisert
    11. aug. 2026
    I KEV-katalogen siden
    24. sep. 2026
  • WSO2 Multiple Products 10.0 KEV CVE-2026-5430 Authentication Bypass via JWT Algorithm Mismatch in Multiple WSO2 Products Allows Account Takeover 24. sep. 2026

    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful exploitation of this vulnerability may result in unauthorized access to the system, including the potential compromise of administrative accounts and full account takeover. The CVSS score is adjusted to 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) in single-tenant deployments, reflecting that the impact is contained within a single security authority boundary.

    Produsent
    WSO2 · WSO2 Universal Gateway
    Type svakhet
    CWE-347: Improper Validation of Certificate With Host Mismatch
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Publisert
    6. aug. 2026
    I KEV-katalogen siden
    24. sep. 2026
  • F5 BIG-IP APM 9.3 KEV CVE-2026-94127 BIG-IP APM OAuth vulnerability 22. sep. 2026

    When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Authorization Server. Deployments using APM strictly as an OAuth Client / Resource Server (without OAuth authorization server profiles configured) are not affected by this vulnerability. Impact: This vulnerability allows an unauthenticated attacker to perform remote code execution. The BIG-IP system in Appliance mode is also vulnerable. This is a data plane issue; there is no control plane exposure. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

    Produsent
    F5 · BIG-IP
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Publisert
    22. sep. 2026
    I KEV-katalogen siden
    22. sep. 2026
  • Arista VeloCloud Orchestrator 9.5 KEV CVE-2026-93952 Security Advisory 0183 22. sep. 2026

    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. Hosted, including Dedicated, versions of VCO were impacted and have already been patched.

    Produsent
    Arista Networks · VeloCloud Orchestrator (VCO) On-Prem
    Type svakhet
    CWE-20: Improper Input Validation
    CVSS 4.0
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Publisert
    22. sep. 2026
    I KEV-katalogen siden
    22. sep. 2026
  • Check Point Multiple Products 9.8 KEV CVE-2026-93616 Directory Traversal and File upload allows execution of arbitrary script on the Management Server 22. sep. 2026

    A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

    Produsent
    checkpoint · Quantum Security Management
    Type svakhet
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    22. sep. 2026
    I KEV-katalogen siden
    22. sep. 2026
  • Check Point Multiple Products 9.8 KEV CVE-2026-85102 Improper Certificate Validation in Quantum Security Gateway 22. sep. 2026

    Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

    Produsent
    checkpoint · Quantum Security Gateway
    Type svakhet
    CWE-295: Improper Certificate Validation.
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    9. sep. 2026
    I KEV-katalogen siden
    22. sep. 2026
  • Zyxel GS1900 Series Switches 8.8 KEV CVE-2026-7273 Zyxel GS1900-48HPv2 firmware: Stack-based Buffer Overflow 21. sep. 2026

    A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

    Produsent
    Zyxel · GS1900-48HPv2 firmware
    Type svakhet
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    16. juni 2026
    I KEV-katalogen siden
    21. sep. 2026
  • Exim 4.0 CVE-2026-94057 Exim: Improper Neutralization of CRLF Sequences ('CRLF Injection') 19. sep. 2026

    Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

    Produsent
    Exim · Exim
    Produktområde
    Postfix / Exim / Dovecot
    Type svakhet
    CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
    Publisert
    19. sep. 2026
  • Exim 7.5 CVE-2026-94056 Exim: Use of Uninitialized Resource 19. sep. 2026

    Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

    Produsent
    Exim · Exim
    Produktområde
    Postfix / Exim / Dovecot
    Type svakhet
    CWE-908: Use of Uninitialized Resource
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:L
    Publisert
    19. sep. 2026
  • Exim 3.7 CVE-2026-94055 Exim: Use After Free 19. sep. 2026

    Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

    Produsent
    Exim · Exim
    Produktområde
    Postfix / Exim / Dovecot
    Type svakhet
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
    Publisert
    19. sep. 2026
  • Exim 7.0 CVE-2026-94054 Exim: Out-of-bounds Write 19. sep. 2026

    Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

    Produsent
    Exim · Exim
    Produktområde
    Postfix / Exim / Dovecot
    Type svakhet
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
    Publisert
    19. sep. 2026
  • Linux Kernel 8.8 KEV CVE-2026-53266 netfilter: bridge: make ebt_snat ARP rewrite writable 18. sep. 2026

    In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().

    Produsent
    Linux · Linux
    Type svakhet
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    Publisert
    25. juni 2026
    I KEV-katalogen siden
    18. sep. 2026
  • Linux Kernel 7.8 KEV CVE-2025-39964 crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg 18. sep. 2026

    In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

    Produsent
    Linux · Linux
    Type svakhet
    CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Publisert
    13. okt. 2025
    I KEV-katalogen siden
    18. sep. 2026
  • Linux Kernel 9.8 KEV CVE-2025-39682 tls: fix handling of zero-length records on the rx_list 18. sep. 2026

    In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted (which may be the case for TLS 1.3 where we don't know type until decryption) we queue the pending record to the rx_list. Next recvmsg() will pick it up from there. Queuing the skb to rx_list after zero-copy decrypt is not possible, since in that case we decrypted directly to the user space buffer, and we don't have an skb to queue (darg.skb points to the ciphertext skb for access to metadata like length). Only data records are allowed zero-copy, and we break the processing loop after each non-data record. So we should never zero-copy and then find out that the record type has changed. The corner case we missed is when the initial record comes from rx_list, and it's zero length.

    Produsent
    Linux · Linux
    Type svakhet
    CWE-754: Improper Check for Unusual or Exceptional Conditions
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    5. sep. 2025
    I KEV-katalogen siden
    18. sep. 2026
  • Acronis Backup 7.8 KEV CVE-2026-87886 Acronis Backup 17. sep. 2026

    Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Acronis Backup plugin for DirectAdmin (Linux) before build 1.2.3.238.

    Produsent
    Acronis · Acronis Backup
    Type svakhet
    CWE-276
    CVSS 3.0
    CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Publisert
    17. sep. 2026
    I KEV-katalogen siden
    16. sep. 2026
  • Cisco Identity Services Engine 10.0 KEV CVE-2026-76460 Cisco Identity Services Engine Authentication Bypass Vulnerability 16. sep. 2026

    A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

    Produsent
    Cisco · Cisco Identity Services Engine Software
    Type svakhet
    CWE-648
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Publisert
    16. sep. 2026
    I KEV-katalogen siden
    16. sep. 2026
  • Google Pixel 8.8 KEV CVE-2026-58704 Google Android: Protection Mechanism Failure 16. sep. 2026

    In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Produsent
    Google · Android
    Type svakhet
    CWE-693: Protection Mechanism Failure
    CVSS 3.1
    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    15. sep. 2026
    I KEV-katalogen siden
    16. sep. 2026
  • Cisco Secure Email Gateway 9.8 KEV CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability 14. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

    Produsent
    Cisco · Cisco Secure Email
    Produktområde
    Mail-Gateways
    Type svakhet
    CWE-89: SQL Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    14. sep. 2026
    I KEV-katalogen siden
    14. sep. 2026
  • Cisco Secure Email 9.8 CVE-2026-76443 Cisco Secure Email Gateway Security Hardening Release 14. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76443 are related to issues with improper neutralization that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.

    Produsent
    Cisco · Cisco Secure Email
    Produktområde
    Mail-Gateways
    Type svakhet
    CWE-707
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    14. sep. 2026
  • Cisco Secure Email 7.5 CVE-2026-76442 Cisco Secure Email Gateway Security Hardening Release 14. sep. 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76442 are related to issues with improper validation of specified quantity in input that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-1284.

    Produsent
    Cisco · Cisco Secure Email
    Produktområde
    Mail-Gateways
    Type svakhet
    CWE-1284
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    14. sep. 2026
  • Cisco Secure Email and Web Manager 9.8 CVE-2026-76441 Cisco Secure Email Gateway Security Hardening Release 14. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76441 are related to issues with improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.

    Produsent
    Cisco · Cisco Secure Email and Web Manager
    Produktområde
    Mail-Gateways
    Type svakhet
    CWE-284
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    14. sep. 2026
  • Cisco Secure Email 9.8 CVE-2026-76440 Cisco Secure Email Gateway Security Hardening Release 14. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76440 are related to path traversal issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-23.

    Produsent
    Cisco · Cisco Secure Email
    Produktområde
    Mail-Gateways
    Type svakhet
    CWE-23
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    14. sep. 2026
  • Cisco Secure Email 9.8 CVE-2026-20353 Cisco Secure Email Gateway Security Hardening Release 14. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20353 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.

    Produsent
    Cisco · Cisco Secure Email
    Produktområde
    Mail-Gateways
    Type svakhet
    CWE-664
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    14. sep. 2026
  • GitLab Community Edition and Enterprise Edition 10.0 KEV CVE-2026-85706 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab 12. sep. 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

    Produsent
    GitLab · GitLab
    Type svakhet
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
    Publisert
    12. sep. 2026
    I KEV-katalogen siden
    11. sep. 2026
  • ConnectWise ScreenConnect 9.9 KEV CVE-2026-84869 ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions 11. sep. 2026

    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

    Produsent
    ConnectWise · ScreenConnect
    Type svakhet
    CWE-862: Missing Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    Publisert
    8. sep. 2026
    I KEV-katalogen siden
    11. sep. 2026
  • JFrog Artifactory 7.5 KEV CVE-2026-42018 Anonymous user token generation exposure in JFrog Artifactory 11. sep. 2026

    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

    Produsent
    jfrog · artifactory
    Type svakhet
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    Publisert
    12. aug. 2026
    I KEV-katalogen siden
    11. sep. 2026
  • JFrog Artifactory 8.1 KEV CVE-2026-42016 Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation 11. sep. 2026

    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

    Produsent
    jfrog · artifactory
    Type svakhet
    CWE-863: Incorrect Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
    Publisert
    27. juli 2026
    I KEV-katalogen siden
    11. sep. 2026
  • MikroTik RouterOS 9.2 KEV CVE-2026-86060 SSH session privilege manipulation via a crafted username in Mikrotik RouterOS 10. sep. 2026

    RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

    Produsent
    Mikrotik · RouterOS
    Type svakhet
    CWE-88: Improper neutralization of argument delimiters in a command ('argument injection')
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Publisert
    5. sep. 2026
    I KEV-katalogen siden
    10. sep. 2026
  • MikroTik RouterOS 8.8 KEV CVE-2026-67277 Kernel memory disclosure and denial of service in MikroTik RouterOS btest service 10. sep. 2026

    RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

    Produsent
    Mikrotik · RouterOS
    Type svakhet
    CWE-306: Missing Authentication
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
    Publisert
    5. sep. 2026
    I KEV-katalogen siden
    10. sep. 2026
  • Google Chromium V8 8.8 KEV CVE-2026-87491 Google Chrome: Out-of-bounds Write 9. sep. 2026

    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

    Produsent
    Google · Chrome
    Type svakhet
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    Publisert
    9. sep. 2026
    I KEV-katalogen siden
    9. sep. 2026
  • Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management 10.0 KEV CVE-2026-20079 Cisco Secure Firewall Management Center Authentication Bypass Remote Code Execution Vulnerability 9. sep. 2026

    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow&nbsp;root access to the device.&nbsp;

    Produsent
    Cisco · Cisco Secure Firewall Management Center (FMC)
    Type svakhet
    CWE-288
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Publisert
    4. mars 2026
    I KEV-katalogen siden
    9. sep. 2026
  • Citrix NetScaler 9.3 KEV CVE-2026-19490 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 9. sep. 2026

    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

    Produsent
    NetScaler · ADC
    Type svakhet
    CWE-288: Authentication Bypass Using an Alternate Path or Channel
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
    Publisert
    19. aug. 2026
    I KEV-katalogen siden
    9. sep. 2026
  • Fortinet Multiple Products 7.4 KEV CVE-2025-25249 Fortinet FortiSwitchManager: Heap-based Buffer Overflow 9. sep. 2026

    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets

    Produsent
    Fortinet · FortiSwitchManager
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
    Publisert
    13. jan. 2026
    I KEV-katalogen siden
    9. sep. 2026
  • N-able N-central 10.0 KEV CVE-2026-86218 pre-authentication remote code execution 8. sep. 2026

    N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

    Produsent
    N-able · N-central
    Type svakhet
    CWE-96: Improper neutralization of directives in statically saved code ('static code injection')
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Publisert
    6. sep. 2026
    I KEV-katalogen siden
    8. sep. 2026
  • Microsoft Windows 7.8 KEV CVE-2026-85880 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 8. sep. 2026

    Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1607
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Publisert
    8. sep. 2026
    I KEV-katalogen siden
    8. sep. 2026
  • Microsoft Windows 7.8 KEV CVE-2026-81963 Windows Update Stack Elevation of Privilege Vulnerability 8. sep. 2026

    Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 11 version 23H2
    Type svakhet
    CWE-59: Improper Link Resolution Before File Access ('Link Following')
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Publisert
    8. sep. 2026
    I KEV-katalogen siden
    8. sep. 2026
  • Adobe Commerce and Magento 10.0 KEV CVE-2026-75650 Adobe Commerce | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336) 8. sep. 2026

    Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

    Produsent
    Adobe · Adobe Commerce
    Type svakhet
    CWE-1336
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Publisert
    7. sep. 2026
    I KEV-katalogen siden
    8. sep. 2026
  • Microsoft Active Directory / Entra 5.9 CVE-2026-72978 Active Directory Federation Services (AD FS) Denial of Service Vulnerability 8. sep. 2026

    Allocation of resources without limits or throttling in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-69822 Windows Kerberos Elevation of Privilege Vulnerability 8. sep. 2026

    Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1809
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-197: Numeric Truncation Error
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-69821 Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability 8. sep. 2026

    Improper encoding or escaping of output in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-116: Improper Encoding or Escaping of Output
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-69809 Windows Active Directory Domain Services Denial of Service Vulnerability 8. sep. 2026

    Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Windows 11 version 23H2
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-401: Missing Release of Memory after Effective Lifetime
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-69760 Windows Kerberos Denial of Service Vulnerability 8. sep. 2026

    Out-of-bounds read in Windows Kerberos allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-125: Out-of-bounds Read
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-69744 Windows Kerberos Denial of Service Vulnerability 8. sep. 2026

    Null pointer dereference in Windows Kerberos allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Windows 11 Version 24H2
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-69685 Windows Kerberos Elevation of Privilege Vulnerability 8. sep. 2026

    Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 8.8 CVE-2026-69676 Windows Kerberos Remote Code Execution Vulnerability 8. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Authentication bypass by capture-replay in Windows Kerberos allows an authorized attacker to execute code over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-294: Authentication Bypass by Capture-replay
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Exchange Server 9.1 CVE-2026-69641 Microsoft Exchange Server Elevation of Privilege Vulnerability 8. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-862: Missing Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 6.5 CVE-2026-69624 Active Directory Certificate Services (AD CS) Tampering Vulnerability 8. sep. 2026

    Incomplete list of disallowed inputs in Active Directory Certificate Services (AD CS) allows an authorized attacker to perform tampering over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-184: Incomplete List of Disallowed Inputs
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Teams 5.8 CVE-2026-69559 Microsoft Teams for Android Information Disclosure Vulnerability 8. sep. 2026

    Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

    Produsent
    Microsoft · Microsoft Teams for Android
    Produktområde
    Teams
    Type svakhet
    CWE-346: Origin Validation Error
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 8.1 CVE-2026-69546 Windows Active Directory Domain Services Remote Code Execution Vulnerability 8. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 8.1 CVE-2026-69524 Windows Active Directory Domain Services Remote Code Execution Vulnerability 8. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Use after free in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 6.5 CVE-2026-69395 Active Directory Certificate Services (AD CS) Information Disclosure Vulnerability 8. sep. 2026

    Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-134: Use of Externally-Controlled Format String
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Exchange Server 5.9 CVE-2026-69382 Microsoft Exchange Server Information Disclosure Vulnerability 8. sep. 2026

    Use of a broken or risky cryptographic algorithm in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-327: Use of a Broken or Risky Cryptographic Algorithm
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Exchange Server 8.1 CVE-2026-69380 Microsoft Exchange Server Elevation of Privilege Vulnerability 8. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-862: Missing Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Exchange Server 7.5 CVE-2026-69378 Microsoft Exchange Server Denial of Service Vulnerability 8. sep. 2026

    Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-674: Uncontrolled Recursion
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Exchange Server 6.5 CVE-2026-69375 Microsoft Exchange Server Tampering Vulnerability 8. sep. 2026

    Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-639: Authorization Bypass Through User-Controlled Key
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Exchange Server 6.5 CVE-2026-69361 Microsoft Exchange Server Spoofing Vulnerability 8. sep. 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-69359 Active Directory Domain Services Elevation of Privilege Vulnerability 8. sep. 2026

    Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Exchange Server 9.3 CVE-2026-69356 Microsoft Exchange Server Spoofing Vulnerability 8. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Exchange Server 8.8 CVE-2026-69355 Microsoft Exchange Server Remote Code Execution Vulnerability 8. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-73: External Control of File Name or Path
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Teams 6.8 CVE-2026-65812 Microsoft Teams for Android Information Disclosure Vulnerability 8. sep. 2026

    Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

    Produsent
    Microsoft · Microsoft Teams for Android
    Produktområde
    Teams
    Type svakhet
    CWE-201: Insertion of Sensitive Information Into Sent Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-62813 Windows Active Directory Domain Services Remote Code Execution Vulnerability 8. sep. 2026

    Use after free in Active Directory Domain Services allows an authorized attacker to execute code over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-62810 Active Directory Certificate Services (AD CS) Elevation of Privilege Vulnerability 8. sep. 2026

    Heap-based buffer overflow in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Active Directory / Entra 6.5 CVE-2026-62762 Windows Active Directory Domain Services Denial of Service Vulnerability 8. sep. 2026

    Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Microsoft Exchange Server 8.1 CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability 8. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-415: Double Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    8. sep. 2026
  • Google Chromium V8 8.8 KEV CVE-2026-85046 Google Chrome 4. sep. 2026

    Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

    Produsent
    Google · Chrome
    Type svakhet
    CWE-843
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    Publisert
    3. sep. 2026
    I KEV-katalogen siden
    4. sep. 2026
  • SEPPmail 8.6 CVE-2026-84832 Unsafe deserialization in the REST interface 3. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.

    Produsent
    SEPPmail AG · SEPPmail Secure Email Gateway (SEG)
    Produktområde
    SEPPmail
    Type svakhet
    CWE-502: Deserialization of Untrusted Data
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Publisert
    3. sep. 2026
  • SEPPmail 7.7 CVE-2026-84831 Mandatory MFA bypass before enrollment 3. sep. 2026

    SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.

    Produsent
    SEPPmail AG · SEPPmail Secure Email Gateway (SEG)
    Produktområde
    SEPPmail
    Type svakhet
    CWE-287: Improper Authentication
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Publisert
    3. sep. 2026
  • Microsoft Active Directory / Entra 10.0 CVE-2026-83711 Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability 3. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Entra
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-639: Authorization Bypass Through User-Controlled Key
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    3. sep. 2026
  • Microsoft Active Directory / Entra 9.1 CVE-2026-62916 Microsoft Entra ID Elevation of Privilege Vulnerability 3. sep. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft Entra
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-288: Authentication Bypass Using an Alternate Path or Channel
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    3. sep. 2026
  • SonicWall SMA1000 Appliances 7.8 KEV CVE-2026-83549 SonicWall SMA1000: OS Command Injection 2. sep. 2026

    Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

    Produsent
    SonicWall · SMA1000
    Type svakhet
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Publisert
    1. sep. 2026
    I KEV-katalogen siden
    2. sep. 2026
  • SonicWall SMA1000 Appliances 10.0 KEV CVE-2026-83548 SonicWall SMA1000: Server-Side Request Forgery 2. sep. 2026

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

    Produsent
    SonicWall · SMA1000
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Publisert
    1. sep. 2026
    I KEV-katalogen siden
    2. sep. 2026
  • JFrog Artifactory 9.8 KEV CVE-2026-82329 Potential authentication bypass leading to administrative access in Artifactory 2. sep. 2026

    JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

    Produsent
    jfrog · artifactory
    Type svakhet
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    28. aug. 2026
    I KEV-katalogen siden
    2. sep. 2026
  • BerriAI LiteLLM 8.8 KEV CVE-2026-59822 LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback 2. sep. 2026

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

    Produsent
    BerriAI · litellm
    Type svakhet
    CWE-287: Improper Authentication
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
    Publisert
    8. juli 2026
    I KEV-katalogen siden
    2. sep. 2026
  • Kestra OSS 10.0 KEV CVE-2026-49869 Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter` 2. sep. 2026

    Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather than an exact path match, any API path whose last segment is configs bypasses authentication entirely. An unauthenticated remote attacker can exploit this to create and execute arbitrary workflows without credentials. Because Kestra ships with script execution plugins (plugin-script-shell, plugin-script-python, etc.) enabled by default, this directly results in unauthenticated Remote Code Execution as root inside the Kestra worker container. This vulnerability is fixed in 1.0.45 and 1.3.21.

    Produsent
    kestra-io · kestra
    Type svakhet
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Publisert
    26. juni 2026
    I KEV-katalogen siden
    2. sep. 2026
  • Kludex Starlette 6.5 KEV CVE-2026-48710 Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks 2. sep. 2026

    Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.

    Produsent
    Kludex · starlette
    Type svakhet
    CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
    Publisert
    26. mai 2026
    I KEV-katalogen siden
    2. sep. 2026
  • Cisco Secure Email 5.9 CVE-2026-20355 Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty 2. sep. 2026

    Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

    Produsent
    Cisco · Cisco Secure Email
    Produktområde
    Mail-Gateways
    Type svakhet
    CWE-345
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
    Publisert
    2. sep. 2026
  • Cisco Secure Email 5.9 CVE-2026-20354 Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty 2. sep. 2026

    Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

    Produsent
    Cisco · Cisco Secure Email
    Produktområde
    Mail-Gateways
    Type svakhet
    CWE-354
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
    Publisert
    2. sep. 2026
  • Sangoma Switchvox 9.3 KEV CVE-2026-9586 Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB 2. sep. 2026

    An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

    Produsent
    Sangoma · Switchvox SMB Edition
    Type svakhet
    CWE-89: SQL Injection
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Publisert
    17. juli 2026
    I KEV-katalogen siden
    2. sep. 2026
  • PaperCut NG/MF 9.4 KEV CVE-2026-82078 PaperCut MF/NG: Unsafe Dynamic Class Loading in Database Connector 31. aug. 2026

    An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

    Produsent
    PaperCut · PaperCut MF/NG
    Type svakhet
    CWE-470: Use of Externally-Controlled input to select classes or code ('unsafe reflection')
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Publisert
    28. aug. 2026
    I KEV-katalogen siden
    31. aug. 2026
  • PaperCut NG/MF 8.8 KEV CVE-2026-81578 PaperCut MF/NG: Authentication Bypass 31. aug. 2026

    An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

    Produsent
    PaperCut · PaperCut MF/NG
    Type svakhet
    CWE-305: Authentication bypass by primary weakness
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
    Publisert
    28. aug. 2026
    I KEV-katalogen siden
    31. aug. 2026
  • Open-Xchange OX Dovecot 7.4 CVE-2026-73208 Open-Xchange GmbH OX Dovecot: Improper Authentication 28. aug. 2026

    An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim does not describe what a token is allowed to do. A token that grants no relevant permissions can be accepted because its intended recipient value happens to match a configured scope name, granting access that should have been denied. It also hides an identity provider misconfiguration where scopes are not being issued at all. Ensure the identity provider issues a scope claim for all tokens used with Dovecot, and that configured scope names do not match audience values. Update to non-vulnerable version. No publicly available exploits are known.

    Produsent
    Open-Xchange GmbH · OX Dovecot
    Produktområde
    Postfix / Exim / Dovecot
    Type svakhet
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
    Publisert
    28. aug. 2026
  • Open-Xchange OX Dovecot 4.3 CVE-2026-42008 Open-Xchange GmbH OX Dovecot: Improper Authentication 28. aug. 2026

    Forwarding information received from a host listed as a trusted proxy is not kept separate from Dovecot's own authentication fields, so a value sent by that host can be injected as an internal authentication field. Any host permitted to act as a trusted proxy can authenticate as any user without knowing that user's password. This affects deployments whose password database honours a field that permits authentication without a password. Deployments that do not configure trusted proxies are not affected. Restrict the list of trusted proxy networks to hosts that are fully under your control. Update to non-vulnerable version. No publicly available exploits are known.

    Produsent
    Open-Xchange GmbH · OX Dovecot
    Produktområde
    Postfix / Exim / Dovecot
    Type svakhet
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
    Publisert
    28. aug. 2026
  • Open-Xchange OX Dovecot 5.9 CVE-2026-33604 Open-Xchange GmbH OX Dovecot 28. aug. 2026

    An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a crafted line ending in the message body to bypass the outbound protection that prevents message content from being interpreted as SMTP commands. A downstream mail server that hasn't yet fixed the SMTP smuggling vulnerability can be tricked into treating part of the message body as new SMTP commands, allowing injection of spoofed email. This is the same vulnerability class as CVE-2023-51764 and CVE-2023-51766. Where you control the receiving mail servers, ensure they reject bare carriage returns in message data. Update to non-vulnerable version. No publicly available exploits are known.

    Produsent
    Open-Xchange GmbH · OX Dovecot
    Produktområde
    Postfix / Exim / Dovecot
    Type svakhet
    CWE-655
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
    Publisert
    28. aug. 2026
  • JFrog Artifactory 5.3 KEV CVE-2026-66384 Authenticated users may write data outside the intended Docker cache path 27. aug. 2026

    An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

    Produsent
    jfrog · artifactory
    Type svakhet
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
    Publisert
    12. aug. 2026
    I KEV-katalogen siden
    27. aug. 2026
  • Linux Kernel 7.8 KEV CVE-2026-53362 ipv6: account for fraggap on the paged allocation path 27. aug. 2026

    In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.

    Produsent
    Linux · Linux
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Publisert
    4. juli 2026
    I KEV-katalogen siden
    27. aug. 2026
  • ownCloud 9.8 KEV CVE-2023-49105 Improper Authentication 27. aug. 2026

    An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

    Type svakhet
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
    Publisert
    21. nov. 2023
    I KEV-katalogen siden
    27. aug. 2026
  • Gitea 9.8 KEV CVE-2026-60004 Gitea: Code Injection 26. aug. 2026

    Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

    Produsent
    Gitea · Gitea
    Type svakhet
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    26. aug. 2026
    I KEV-katalogen siden
    25. aug. 2026
  • Citrix NetScaler ADC and NetScaler Gateway 8.8 KEV CVE-2026-8452 Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service 26. aug. 2026

    Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

    Produsent
    NetScaler · ADC
    Type svakhet
    CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
    Publisert
    30. juni 2026
    I KEV-katalogen siden
    26. aug. 2026
  • Linux Kernel 7.8 KEV CVE-2022-0995 n/a kernel: Out-of-bounds Write 26. aug. 2026

    An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.

    Produsent
    n/a · kernel
    Type svakhet
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Publisert
    25. mars 2022
    I KEV-katalogen siden
    26. aug. 2026
  • Ajax.NET Professional 8.1 KEV CVE-2021-23758 Deserialization of Untrusted Data 26. aug. 2026

    All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

    Produsent
    n/a · AjaxPro.2
    Type svakhet
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    3. des. 2021
    I KEV-katalogen siden
    26. aug. 2026
  • Microsoft SQL Server 8.8 KEV CVE-2019-1068 Microsoft SQL Server: Improper Input Validation 26. aug. 2026

    A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

    Produsent
    Microsoft · Microsoft SQL Server
    Type svakhet
    CWE-20: Improper Input Validation
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Publisert
    15. juli 2019
    I KEV-katalogen siden
    26. aug. 2026
  • Red Hat Automatic Bug Reporting Tool 7.8 KEV CVE-2015-5287 Improper Link Resolution Before File Access ('Link Following') 26. aug. 2026

    The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.

    Type svakhet
    CWE-59: Improper Link Resolution Before File Access ('Link Following')
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Publisert
    7. des. 2015
    I KEV-katalogen siden
    26. aug. 2026
  • Red Hat Libuser 7.4 KEV CVE-2015-3246 Time-of-check Time-of-use (TOCTOU) Race Condition 26. aug. 2026

    libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

    Type svakhet
    CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    11. aug. 2015
    I KEV-katalogen siden
    26. aug. 2026
  • OpenSSL 7.5 CVE-2026-63076 Invalid Pointer Dereference in CMP Server via Crafted protectionAlg 25. aug. 2026

    Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer. Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service. CWE: CWE-476: NULL Pointer Dereference Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted. This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable. FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    25. aug. 2026
  • OpenSSL 7.5 CVE-2026-63075 QUIC ACK-only Packet Retention Can Cause Memory Exhaustion 25. aug. 2026

    Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can complete a QUIC handshake can cause connection-scoped memory growth which may lead to Denial of Service through memory exhaustion, especially with sustained traffic or many concurrent QUIC connections. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: When the OpenSSL QUIC stack sends an ACK-only packet, there is no requirement by the QUIC protocol that the peer will acknowledge that ACK-only packet (i.e. it is itself not ack-eliciting). However, the OpenSSL implementation stores the metadata about the ACK frames regardless. In and of itself that's ok, but if a malicious peer establishes a connection, and then drives the connection such that ACK-only packets are forced from the OpenSSL implementation peer (i.e., by sending numerous PING frames), and then withholding any subsequent acks for ack-eliciting data, like legitimate data, said malicious peer can force inappropriate memory growth on the OpenSSL peer, potentially leading to a Denial of Service. The fix is to ensure that we account for the transmission of the ACK-only packet in the packet histories high and low watermark without actually storing the ACK-only packet metadata itself. FIPS impact: no The OpenSSL FIPS module is not affected as the QUIC code is outside the FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    25. aug. 2026
  • OpenSSL 5.9 CVE-2026-63074 CMP Indefinite Cache Growth of ExtraCerts 25. aug. 2026

    Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth. Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack. This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely. The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all. FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    25. aug. 2026
  • OpenSSL 9.8 CVE-2026-63073 Untrusted Sender DN Used as Format String in CMP Response Validation 25. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client that enforces an expected sender or uses a pinned server certificate whose subject becomes the default expected sender. CWE: CWE-134 (Use of Externally-Controlled Format String) Description: When validating a received CMP message, ossl_cmp_msg_check_update() converts the peer-supplied sender distinguished name with X509_NAME_oneline() and passes it directly as the format argument to ERR_raise_data(). Percent characters survive the conversion, so a sender DN such as "CN=%s%n" reaches BIO_vsnprintf() as an attacker-controlled format string with no matching variadic arguments. This path is only reached when the caller configures an expected sender or pins a server certificate, which is the normal configuration for a CMP client validating server responses. Since the attacker controls the format string but none of the variadic arguments, such specifiers as %s and %n dereference or write through unrelated stack contents and crash the client. The reliable consequence is a denial of service, when the response comes from a malicious or intercepted CMP endpoint. There is no controlled memory write, arbitrary-address read, or reliable path to remote code execution. FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-134
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    25. aug. 2026
  • OpenSSL 7.5 CVE-2026-63072 Heap Buffer Overflow in CMS Key Unwrapping 25. aug. 2026

    Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write. Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service. CWE: CWE-787: Out-of-bounds Write Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure. The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation. FIPS impact: no As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-787: Out-of-bounds Write
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    25. aug. 2026
  • OpenSSL 7.5 CVE-2026-54874 Excessive Memory Use Buffering DTLS Records for a Future Epoch 25. aug. 2026

    Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service. CWE: CWE-405: Asymmetric Resource Consumption (Amplification) Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up. Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network. An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity. FIPS impact: no No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary. OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22. Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell. -- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt Caswell

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-405: Asymmetric Resource Consumption (Amplification)
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    25. aug. 2026
  • OpenSSL 7.5 CVE-2026-18798 QUIC Server May Trigger Double Free When Processing INITIAL Packet 25. aug. 2026

    Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time. The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length. FIPS impact: no The FIPS module is not affected, as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-415: Double Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    25. aug. 2026
  • OpenSSL 7.5 CVE-2026-14457 RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate 25. aug. 2026

    Issue summary: In a server or client configuration with RFC7250 Raw Public Keys (RPKs) enabled, and only the private key (with no associated certificate) configured locally, a NULL pointer dereference may occur when the remote peer solicits raw public keys and also sends the typically omitted "signature_algorithms_cert" TLS extension. Impact summary: The impact is limited to a possible Denial of Service as a result of an application abort, no data disclosure or remote command execution are possible. CWE: CWE-476: NULL Pointer Dereference Description: While a passing comment in sample code in the documentation suggests that key-only RPK configurations are supported, the best-practice RPK configuration is to always configure a corresponding certificate (possibly self-signed or signed by any convenient CA). When the private key is configured along with a matching certificate, the "signature_algorithms_cert" extension is handled reliably even without the fix, and peer clients or servers that don't support raw public keys may be able to complete a TLS connection by pinning or verifying the corresponding certificate or its public key. Deployments that prefer to configure just a private key with no certificate need to upgrade to an updated release as noted below. FIPS impact: no No FIPS modules are affected by this issue, as the SSL protocol implementation is outside the OpenSSL FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    25. aug. 2026
  • Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in 10.0 KEV CVE-2026-21962 Oracle Corporation Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in: Improper Access Control 24. aug. 2026

    Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

    Produsent
    Oracle Corporation · Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in
    Type svakhet
    CWE-284: Improper Access Control
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
    Publisert
    20. jan. 2026
    I KEV-katalogen siden
    24. aug. 2026
  • Synacor Zimbra Collaboration Suite (ZCS) 8.9 KEV CVE-2026-73570 Zimbra Collaboration: OS Command Injection 21. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

    Produsent
    Zimbra · Collaboration
    Produktområde
    Webmail
    Type svakhet
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
    Publisert
    13. aug. 2026
    I KEV-katalogen siden
    21. aug. 2026
  • TrueConf Server 9.5 KEV CVE-2026-72530 TrueConf Server: Code Injection 20. aug. 2026

    A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

    Produsent
    TrueConf · TrueConf Server
    Type svakhet
    CWE-94: Code Injection
    CVSS 4.0
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Publisert
    19. aug. 2026
    I KEV-katalogen siden
    20. aug. 2026
  • TrueConf Server 9.3 KEV CVE-2026-72529 TrueConf Server: Missing Authentication 20. aug. 2026

    A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

    Produsent
    TrueConf · TrueConf Server
    Type svakhet
    CWE-306: Missing Authentication
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Publisert
    19. aug. 2026
    I KEV-katalogen siden
    20. aug. 2026
  • Microsoft Active Directory / Entra 9.9 CVE-2026-69851 Microsoft Entra ID Elevation of Privilege Vulnerability 20. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft Entra
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    20. aug. 2026
  • Microsoft Active Directory / Entra 10.0 CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability 20. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

    Produsent
    Microsoft · Microsoft Entra
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    20. aug. 2026
  • MLflow 9.3 KEV CVE-2026-64849 MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) 19. aug. 2026

    MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

    Produsent
    mlflow · mlflow
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
    Publisert
    17. aug. 2026
    I KEV-katalogen siden
    19. aug. 2026
  • Apple macOS 9.8 KEV CVE-2026-65400 Apple macOS: Improper Authentication 18. aug. 2026

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

    Produsent
    Apple · macOS
    Type svakhet
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    6. aug. 2026
    I KEV-katalogen siden
    18. aug. 2026
  • Broadcom VMware vCenter 9.8 KEV CVE-2026-59310 vCenter directory-traversal vulnerability 18. aug. 2026

    VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

    Produsent
    VMware · Cloud Foundation
    Type svakhet
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    30. juli 2026
    I KEV-katalogen siden
    18. aug. 2026 · Brukt i løsepengevirus-kampanjer
  • Microsoft SharePoint 9.1 KEV CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability 18. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

    Produsent
    Microsoft · Microsoft SharePoint
    Produktområde
    SharePoint
    Type svakhet
    CWE-1390: Weak Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
    I KEV-katalogen siden
    18. aug. 2026
  • Microsoft Internet Key Exchange (IKE) Service Extensions 9.8 KEV CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability 18. aug. 2026

    Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Type svakhet
    CWE-415: Double Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    14. apr. 2026
    I KEV-katalogen siden
    18. aug. 2026
  • Roundcube Webmail 6.4 CVE-2026-75010 Roundcube Webmail: Incorrect Resource Transfer Between Spheres 17. aug. 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authentication token to a user-controlled host via crafted session data. This issue only affects Roundcube instances using the password plugin with its modoboa driver.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-669: Incorrect Resource Transfer Between Spheres
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
    Publisert
    17. aug. 2026
  • Roundcube Webmail 5.4 CVE-2026-75007 Roundcube Webmail: Command Injection 17. aug. 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-77: Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
    Publisert
    17. aug. 2026
  • Roundcube Webmail 5.8 CVE-2026-75006 Roundcube Webmail: Server-Side Request Forgery 17. aug. 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
    Publisert
    17. aug. 2026
  • Roundcube Webmail 4.3 CVE-2026-75004 Roundcube Webmail: Command Injection 17. aug. 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-77: Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
    Publisert
    17. aug. 2026
  • Roundcube Webmail 5.8 CVE-2026-75003 Roundcube Webmail: Incorrect Resource Transfer Between Spheres 17. aug. 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed url() in a FuncIRI attribute of an SVG image could evade the remote image blocking, which may lead to information disclosure or privilege escalation.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-669: Incorrect Resource Transfer Between Spheres
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
    Publisert
    17. aug. 2026
  • Roundcube Webmail 7.1 CVE-2026-75002 Roundcube Webmail: Command Injection 17. aug. 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-77: Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
    Publisert
    17. aug. 2026
  • Roundcube Webmail 5.8 CVE-2026-75000 Roundcube Webmail: Incorrect Resource Transfer Between Spheres 17. aug. 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-669: Incorrect Resource Transfer Between Spheres
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
    Publisert
    17. aug. 2026
  • Roundcube Webmail 5.4 CVE-2026-74999 Roundcube Webmail: Cross-Site Scripting 17. aug. 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
    Publisert
    17. aug. 2026
  • Roundcube Webmail 7.2 CVE-2026-74998 Roundcube Webmail: Cross-Site Scripting 17. aug. 2026

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
    Publisert
    17. aug. 2026
  • Roundcube Webmail 8.8 CVE-2026-74997 Roundcube Webmail: OS Command Injection 17. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
    Publisert
    17. aug. 2026
  • Ray-Project Ray 9.4 KEV CVE-2025-62593 Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack 17. aug. 2026

    Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.

    Produsent
    ray-project · ray
    Type svakhet
    CWE-94: Code Injection
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Publisert
    26. nov. 2025
    I KEV-katalogen siden
    17. aug. 2026
  • Zimbra Collaboration 6.3 CVE-2026-73576 Zimbra Collaboration: Use of Predictable Algorithm in Random Number Generator 13. aug. 2026

    In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery.

    Produsent
    Zimbra · Collaboration
    Produktområde
    Webmail
    Type svakhet
    CWE-1241: Use of Predictable Algorithm in Random Number Generator
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
    Publisert
    13. aug. 2026
  • Zimbra Collaboration 3.1 CVE-2026-73575 Zimbra Collaboration: Cross-Site Request Forgery 13. aug. 2026

    In Zimbra Collaboration (ZCS) before 10.1.17, a Cross-Site Request Forgery (CSRF) vulnerability exists in the Exchange Web Services (EWS) endpoint of Zimbra Collaboration (ZCS) due to insufficient validation of request content types. An attacker can exploit this vulnerability by causing an authenticated user to submit a crafted request, potentially allowing unauthorized actions to be performed on behalf of the victim.

    Produsent
    Zimbra · Collaboration
    Produktområde
    Webmail
    Type svakhet
    CWE-352: Cross-Site Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
    Publisert
    13. aug. 2026
  • Zimbra Collaboration 3.1 CVE-2026-73574 Zimbra Collaboration: Incorrect Resource Transfer Between Spheres 13. aug. 2026

    In Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper validation of the fu request parameter. An unauthenticated attacker can exploit this vulnerability by supplying a crafted path, potentially allowing unauthorized disclosure of protected files, such as WEB-INF/web.xml, within the web application directory. This occurs in the Forward servlet.

    Produsent
    Zimbra · Collaboration
    Produktområde
    Webmail
    Type svakhet
    CWE-669: Incorrect Resource Transfer Between Spheres
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
    Publisert
    13. aug. 2026
  • Zimbra Collaboration 3.1 CVE-2026-73573 Zimbra Collaboration: Path Traversal: '../filedir' 13. aug. 2026

    In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory.

    Produsent
    Zimbra · Collaboration
    Produktområde
    Webmail
    Type svakhet
    CWE-24: Path Traversal: '../filedir'
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
    Publisert
    13. aug. 2026
  • Zimbra Collaboration 6.1 CVE-2026-73572 Zimbra Collaboration: Cross-Site Scripting 13. aug. 2026

    In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insufficient sanitization of specific attachment content during inline preview. An attacker can send a crafted email containing a malicious attachment that, when previewed by a user, executes arbitrary JavaScript within the victim's browser session. Successful exploitation may allow an attacker to perform unauthorized actions on behalf of the victim user, potentially leading to data exfiltration or unauthorized access to sensitive information.

    Produsent
    Zimbra · Collaboration
    Produktområde
    Webmail
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
    Publisert
    13. aug. 2026
  • Zimbra Collaboration 3.1 CVE-2026-73571 Zimbra Collaboration: Incorrect Authorization 13. aug. 2026

    An authorization bypass vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.17 due to improper authorization validation in delegated email sending functionality. An authenticated attacker can send specially crafted SOAP requests to impersonate another user and send emails without possessing the required delegation or send-as permissions. This occurs in the SaveDraftRequest SOAP handler.

    Produsent
    Zimbra · Collaboration
    Produktområde
    Webmail
    Type svakhet
    CWE-863: Incorrect Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
    Publisert
    13. aug. 2026
  • OpenSSL 7.5 CVE-2026-14456 Unbounded Memory Growth in QUIC Server Incoming Channel Queue 13. aug. 2026

    Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit. Impact summary: A remote peer that can make many Initial packets reach the server listener faster than the application accepts connections, can cause the memory allocated to store the per-channel state to grow without any limits, potentially making the QUIC listener unavailable and causing Denial of Service. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The function that handles inbound QUIC packets uses Connection-Id from the packet header to find an existing connection (QUIC channel). If no existing connection is found and the packet type is INITIAL, the function treats the packet as a new connection. It allocates a new channel object and inserts it into a queue where it waits to be accepted by the local application with SSL_accept(3ossl). The memory occupied by these initial channel objects may grow without bounds if the application is not able to call SSL_accept() frequently enough to serve these inbound connection requests. The issue is present since OpenSSL 3.5 when the QUIC server implementation was added. The fix introduces a limit for pending connections. The default limit is set to 256 pending connections (waiting to be accepted by the local application). Applications may change the default by calling SSL_set_value_uint(3ossl). FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    13. aug. 2026
  • OpenBSD OpenSSH 2.5 CVE-2026-73283 OpenBSD OpenSSH: Always-Incorrect Control Flow Implementation 11. aug. 2026

    In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

    Produsent
    OpenBSD · OpenSSH
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-670: Always-Incorrect Control Flow Implementation
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
    Publisert
    11. aug. 2026
  • OpenBSD OpenSSH 4.8 CVE-2026-73282 OpenBSD OpenSSH: Use After Free 11. aug. 2026

    In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

    Produsent
    OpenBSD · OpenSSH
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
    Publisert
    11. aug. 2026
  • OpenBSD OpenSSH 3.5 CVE-2026-73281 OpenBSD OpenSSH: Incorrect Resource Transfer Between Spheres 11. aug. 2026

    In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

    Produsent
    OpenBSD · OpenSSH
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-669: Incorrect Resource Transfer Between Spheres
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N
    Publisert
    11. aug. 2026
  • Metabase 10.0 KEV CVE-2026-72898 Metabase SQL injection via password reset endpoint 11. aug. 2026

    Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

    Produsent
    Metabase · Metabase
    Type svakhet
    CWE-89: SQL Injection
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
    Publisert
    10. aug. 2026
    I KEV-katalogen siden
    11. aug. 2026
  • Microsoft Windows Ancillary Function Driver for WinSock 7.0 KEV CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 11. aug. 2026

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1607
    Type svakhet
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
    I KEV-katalogen siden
    11. aug. 2026
  • Microsoft Exchange Server 6.5 CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability 11. aug. 2026

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Active Directory / Entra 5.3 CVE-2026-65777 Active Directory Security Feature Bypass Vulnerability 11. aug. 2026

    Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.

    Produsent
    Microsoft · Windows 11 version 23H2
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-326: Inadequate Encryption Strength
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Teams 6.5 CVE-2026-65769 Microsoft Teams iOS Information Disclosure Vulnerability 11. aug. 2026

    Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.

    Produsent
    Microsoft · Microsoft Teams for iOS
    Produktområde
    Teams
    Type svakhet
    CWE-200: Information Disclosure
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Teams 8.8 CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability 11. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.

    Produsent
    Microsoft · Microsoft Teams for Android
    Produktområde
    Teams
    Type svakhet
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Teams 8.8 CVE-2026-65767 Microsoft Teams for Android Spoofing Vulnerability 11. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

    Produsent
    Microsoft · Microsoft Teams for Android
    Produktområde
    Teams
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-65673 Microsoft Entra Connect Elevation of Privilege Vulnerability 11. aug. 2026

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Microsoft Entra Connect
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-89: SQL Injection
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Exchange Server 6.5 CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability 11. aug. 2026

    Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-862: Missing Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Exchange Server 7.3 CVE-2026-62914 Microsoft Exchange Server Spoofing Vulnerability 11. aug. 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Exchange Server 8.8 CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability 11. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Exchange Server 6.5 CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability 11. aug. 2026

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Exchange Server 8.0 CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability 11. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-294: Authentication Bypass by Capture-replay
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Exchange Server 7.2 CVE-2026-62910 Microsoft Exchange Server Elevation of Privilege Vulnerability 11. aug. 2026

    Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-99: Improper Control of Resource Identifiers ('Resource Injection')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Active Directory / Entra 8.8 CVE-2026-62818 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability 11. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Use after free in Active Directory Certificate Services (AD CS) allows an authorized attacker to execute code over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Active Directory / Entra 7.0 CVE-2026-62773 Windows Kerberos Elevation of Privilege Vulnerability 11. aug. 2026

    Use after free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Active Directory / Entra 7.0 CVE-2026-62766 Windows Kerberos Elevation of Privilege Vulnerability 11. aug. 2026

    Double free in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 11 Version 24H2
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-415: Double Free
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-62754 Windows Kerberos Elevation of Privilege Vulnerability 11. aug. 2026

    Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-62752 Windows Kerberos Elevation of Privilege Vulnerability 11. aug. 2026

    Heap-based buffer overflow in Windows Kerberos allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Microsoft Active Directory / Entra 8.8 CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerability 11. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-77: Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    11. aug. 2026
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) 8.6 KEV CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability 11. aug. 2026

    A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.&nbsp; This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

    Produsent
    Cisco · Cisco Secure Firewall
    Type svakhet
    CWE-244
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
    Publisert
    11. aug. 2026
    I KEV-katalogen siden
    11. aug. 2026
  • Progress LoadMaster 9.6 KEV CVE-2026-8037 OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF 7. aug. 2026

    OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

    Produsent
    Progress Software · LoadMaster
    Type svakhet
    CWE-77: Command Injection
    CVSS 3.1
    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Publisert
    4. juni 2026
    I KEV-katalogen siden
    7. aug. 2026
  • Microsoft Teams 10.0 CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability 6. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft Teams
    Produktområde
    Teams
    Type svakhet
    CWE-862: Missing Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    6. aug. 2026
  • Microsoft Teams 7.5 CVE-2026-62918 Microsoft Teams Spoofing Vulnerability 6. aug. 2026

    Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.

    Produsent
    Microsoft · Microsoft Teams
    Produktområde
    Teams
    Type svakhet
    CWE-347: Improper Verification of Cryptographic Signature
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    6. aug. 2026
  • Microsoft Teams 9.6 CVE-2026-62896 Microsoft Teams Elevation of Privilege Vulnerability 6. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft Teams
    Produktområde
    Teams
    Type svakhet
    CWE-287: Improper Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
    Publisert
    6. aug. 2026
  • Microsoft Active Directory / Entra 9.9 CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability 6. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft Entra Provisioning Service
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-35: Path Traversal: '.../...//'
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    6. aug. 2026
  • Microsoft Active Directory / Entra 9.9 CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability 6. aug. 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Azure Active Directory
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-471: Modification of Assumed-Immutable Data (MAID)
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C
    Publisert
    6. aug. 2026
  • JetBrains TeamCity 9.8 KEV CVE-2026-63077 JetBrains TeamCity: Deserialization of Untrusted Data 5. aug. 2026

    In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

    Produsent
    JetBrains · TeamCity
    Type svakhet
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    27. juli 2026
    I KEV-katalogen siden
    5. aug. 2026 · Brukt i løsepengevirus-kampanjer
  • OpenSSL 7.5 CVE-2026-54876 Client-Side Memory Leak in OCSP Response Checking 5. aug. 2026

    Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker-tunable amount of memory per TLS handshake in a victim client application. A long-running client that repeatedly connects to a malicious server can have its memory exhausted, resulting in a Denial of Service. CWE: CWE-401: Missing Release of Memory after Effective Lifetime Description: The affected function is called during X.509 certificate chain verification when OCSP response checking is enabled with the X509_V_FLAG_OCSP_RESP_CHECK or X509_V_FLAG_OCSP_RESP_CHECK_ALL verification flags, for example when a TLS client verifies an OCSP response stapled into the TLS handshake by the server. When the received BasicOCSPResponse contains an empty SEQUENCE OF SingleResponse, which is permitted on the wire and accepted by the OpenSSL decoder, the OCSP_BASICRESP structure allocated by OCSP_response_get1_basic() was not freed because an early return bypassed the cleanup code at the end of the function. The amount of memory leaked per handshake can be amplified by the attacker by padding the certs field of the BasicOCSPResponse with bogus certificates, which are parsed and stored in the leaked structure before the empty response check triggers the early return. A long-running TLS client that repeatedly connects to a malicious server can have its memory exhausted over time. OCSP response checking is not enabled by default. Only client applications that explicitly enable the OCSP response check verification flags are affected. FIPS impact: no The FIPS modules in 4.0 and 3.6 are not affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.

    Produsent
    OpenSSL · OpenSSL
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-401: Missing Release of Memory after Effective Lifetime
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    5. aug. 2026
  • Apache Tomcat 7.5 KEV CVE-2026-34486 Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor 4. aug. 2026

    Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

    Produsent
    Apache Software Foundation · Apache Tomcat
    Type svakhet
    CWE-311: Missing Encryption of Sensitive Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    Publisert
    9. apr. 2026
    I KEV-katalogen siden
    4. aug. 2026
  • N-able N-central 8.2 KEV CVE-2026-18556 Unauthenticated administrative account takeover 4. aug. 2026

    Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

    Produsent
    N-able · N-central
    Type svakhet
    CWE-288: Authentication bypass using an alternate path or channel
    CVSS 4.0
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
    Publisert
    1. aug. 2026
    I KEV-katalogen siden
    4. aug. 2026
  • IBM Langflow 9.8 KEV CVE-2026-9198 Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation 4. aug. 2026

    IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

    Produsent
    IBM · Langflow OSS
    Type svakhet
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    17. juli 2026
    I KEV-katalogen siden
    4. aug. 2026
  • N-able N-central 8.2 KEV CVE-2026-18577 Incomplete patch leads to administrative account takeover 3. aug. 2026

    An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

    Produsent
    N-able · N-central
    Type svakhet
    CWE-288: Authentication bypass using an alternate path or channel
    CVSS 4.0
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:A
    Publisert
    2. aug. 2026
    I KEV-katalogen siden
    3. aug. 2026
  • Cisco Secure Firewall Management Center (FMC) 5.3 KEV CVE-2026-20316 Cisco Secure Firewall Management Center Software Static Credential Vulnerability 29. juli 2026

    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.&nbsp; Note:&nbsp;If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.&nbsp;&nbsp; Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

    Produsent
    Cisco · Cisco Secure Firewall Management Center (FMC)
    Type svakhet
    CWE-259
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    Publisert
    29. juli 2026
    I KEV-katalogen siden
    29. juli 2026 · Brukt i løsepengevirus-kampanjer
  • Arista VeloCloud Orchestrator 10.0 KEV CVE-2026-16812 VeloCloud Orchestrator OS Command Injection 27. juli 2026

    VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited.

    Produsent
    Arista Networks · VeloCloud Orchestrator On-Prem
    Type svakhet
    CWE-78: OS Command Injection
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P
    Publisert
    27. juli 2026
    I KEV-katalogen siden
    27. juli 2026
  • Fortinet FortiOS 5.3 KEV CVE-2025-68686 Fortinet FortiOS: Information Disclosure 27. juli 2026

    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level.

    Produsent
    Fortinet · FortiOS
    Type svakhet
    CWE-200: Information Disclosure
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
    Publisert
    10. feb. 2026
    I KEV-katalogen siden
    27. juli 2026
  • Exim 7.4 CVE-2026-66141 Exim: Inclusion of Functionality from Untrusted Control Sphere 24. juli 2026

    Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

    Produsent
    Exim · Exim
    Produktområde
    Postfix / Exim / Dovecot
    Type svakhet
    CWE-829: Inclusion of Functionality from Untrusted Control Sphere
    CVSS 3.1
    CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    24. juli 2026
  • Exim 8.4 CVE-2026-66140 Exim: Path Traversal: '../filedir' 24. juli 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

    Produsent
    Exim · Exim
    Produktområde
    Postfix / Exim / Dovecot
    Type svakhet
    CWE-24: Path Traversal: '../filedir'
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    24. juli 2026
  • Microsoft SharePoint 9.8 KEV CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability 22. juli 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

    Produsent
    Microsoft · Microsoft SharePoint
    Produktområde
    SharePoint
    Type svakhet
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
    I KEV-katalogen siden
    22. juli 2026
  • Check Point SmartConsole 9.3 KEV CVE-2026-16232 Authentication Bypass in the SmartConsole Login Process Using an Application Token 22. juli 2026

    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

    Produsent
    checkpoint · Quantum Security Management
    Type svakhet
    CWE-287: Improper Authentication
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Publisert
    22. juli 2026
    I KEV-katalogen siden
    22. juli 2026
  • WordPress Core 9.8 KEV CVE-2026-63030 WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution 21. juli 2026

    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

    Produsent
    WordPress · WordPress
    Type svakhet
    CWE-436: Interpretation Conflict
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    17. juli 2026
    I KEV-katalogen siden
    21. juli 2026
  • WordPress Core 5.9 KEV CVE-2026-60137 WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_Query 21. juli 2026

    WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

    Produsent
    WordPress · WordPress
    Type svakhet
    CWE-89: SQL Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
    Publisert
    17. juli 2026
    I KEV-katalogen siden
    21. juli 2026
  • Langflow 9.8 KEV CVE-2026-0770 Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability 21. juli 2026

    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

    Produsent
    Langflow · Langflow
    Type svakhet
    CWE-829: Inclusion of Functionality from Untrusted Control Sphere
    CVSS 3.0
    CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    23. jan. 2026
    I KEV-katalogen siden
    21. juli 2026
  • DD-WRT 8.1 KEV CVE-2021-27137 DD-WRT: Stack-based Buffer Overflow 21. juli 2026

    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).

    Produsent
    DD-WRT · DD-WRT
    Type svakhet
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    16. juli 2026
    I KEV-katalogen siden
    21. juli 2026
  • rust-openssl 5.1 CVE-2026-45784 rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers 17. juli 2026

    rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.

    Produsent
    rust-openssl · rust-openssl
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-131: Incorrect Calculation of Buffer Size
    CVSS 4.0
    CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
    Publisert
    17. juli 2026
  • SEPPmail 7.5 CVE-2026-9592 Sensitive Information Disclosure in HTTP header 17. juli 2026

    SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.

    Produsent
    SEPPmail · SEPPmail Secure Email Gateway & SEPPmail Cloud
    Produktområde
    SEPPmail
    Type svakhet
    CWE-598: Use of GET request method with sensitive query strings
    CVSS 4.0
    CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:U
    Publisert
    17. juli 2026
  • Microsoft SharePoint 9.8 KEV CVE-2026-58644 Microsoft SharePoint Remote Code Execution Vulnerability 16. juli 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

    Produsent
    Microsoft · Microsoft SharePoint
    Produktområde
    SharePoint
    Type svakhet
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Publisert
    14. juli 2026
    I KEV-katalogen siden
    16. juli 2026
  • Microsoft Teams 9.3 CVE-2026-54733 moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint 16. juli 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT payload and authenticates users from the upn claim without verifying the JWT signature, allowing an unauthenticated attacker to forge a token and obtain a Moodle session as an O365-authenticated user. This issue is fixed in versions 4.5.6, 5.0.5, and 5.1.1.

    Produsent
    microsoft · o365-moodle
    Produktområde
    Teams
    Type svakhet
    CWE-347: Improper Verification of Cryptographic Signature
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
    Publisert
    16. juli 2026
  • Fortinet FortiSandbox 9.1 KEV CVE-2026-39808 Fortinet FortiSandbox: OS Command Injection 16. juli 2026

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

    Produsent
    Fortinet · FortiSandbox
    Type svakhet
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Publisert
    14. apr. 2026
    I KEV-katalogen siden
    16. juli 2026
  • Fortinet FortiSandbox 9.1 KEV CVE-2026-25089 Fortinet FortiSandbox: OS Command Injection 16. juli 2026

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests

    Produsent
    Fortinet · FortiSandbox
    Type svakhet
    CWE-78: OS Command Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Publisert
    9. juni 2026
    I KEV-katalogen siden
    16. juli 2026
  • Oracle E-Business Suite 9.8 KEV CVE-2026-46817 Oracle Corporation Oracle Payments: Missing Authentication 15. juli 2026

    Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

    Produsent
    Oracle Corporation · Oracle Payments
    Type svakhet
    CWE-306: Missing Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Publisert
    28. mai 2026
    I KEV-katalogen siden
    15. juli 2026
  • KNX Association KNX Protocol Connection Authorization Option 1 7.5 KEV CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1: Overly Restrictive Account Lockout Mechanism 15. juli 2026

    KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices can be used to create a password for the device, but this password can often not be reset without entering the current password. If the device is configured to interface with a network, an attacker with access to that network could interface with the KNX installation, purge all devices without additional security options enabled, and set a BCU key, locking the device. Even if a device is not connected to a network, an attacker with physical access to the device could also exploit this vulnerability in the same way.

    Produsent
    KNX Association · KNX Protocol Connection Authorization Option 1
    Type svakhet
    CWE-645: Overly Restrictive Account Lockout Mechanism
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    Publisert
    29. aug. 2023
    I KEV-katalogen siden
    15. juli 2026
  • Roundcube Webmail 6.4 CVE-2026-62644 Roundcube Webmail: Authentication Bypass by Spoofing 14. juli 2026

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the password plugin of the Roundcube Webmail was subject to username spoofing via session data, which could lead to account takeover.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-290: Authentication Bypass by Spoofing
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
    Publisert
    14. juli 2026
  • Roundcube Webmail 7.2 CVE-2026-62643 Roundcube Webmail: Server-Side Request Forgery 14. juli 2026

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. NOTE: this issue exists because of insufficient fixes for CVE-2026-35540 and CVE-2026-48843.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
    Publisert
    14. juli 2026
  • Roundcube Webmail 4.3 CVE-2026-62642 Roundcube Webmail: Loop with Unreachable Exit Condition ('Infinite Loop') 14. juli 2026

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
    Publisert
    14. juli 2026
  • Roundcube Webmail 4.3 CVE-2026-62641 Roundcube Webmail: Allocation of Resources Without Limits or Throttling 14. juli 2026

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, the TNEF decoder was subject to denial of service via a crafted compressed-RTF size.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.1 CVE-2026-58529 Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability 14. juli 2026

    Out-of-bounds read in Active Directory Federation Services (AD FS) allows an authorized attacker to disclose information over a network.

    Produsent
    Microsoft · Windows 11 version 26H1
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-125: Out-of-bounds Read
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 6.5 CVE-2026-57976 Windows Active Directory Domain Services Denial of Service Vulnerability 14. juli 2026

    Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft SharePoint 5.3 KEV CVE-2026-56164 Microsoft SharePoint Server Elevation of Privilege Vulnerability 14. juli 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Microsoft SharePoint
    Produktområde
    SharePoint
    Type svakhet
    CWE-306: Missing Authentication
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:F/RL:O/RC:C
    Publisert
    14. juli 2026
    I KEV-katalogen siden
    14. juli 2026
  • Microsoft Active Directory / Entra 7.8 KEV CVE-2026-56155 Active Directory Federation Services Elevation of Privilege Vulnerability 14. juli 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-1220: Insufficient Granularity of Access Control
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
    Publisert
    14. juli 2026
    I KEV-katalogen siden
    14. juli 2026
  • Microsoft Exchange Server 7.8 CVE-2026-55009 Microsoft Exchange Server Elevation of Privilege Vulnerability 14. juli 2026

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Exchange Server 9.6 CVE-2026-55008 Microsoft Exchange Server Spoofing Vulnerability 14. juli 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Exchange Server 7.8 CVE-2026-55006 Microsoft Exchange Server Elevation of Privilege Vulnerability 14. juli 2026

    Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-1220: Insufficient Granularity of Access Control
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Exchange Server 8.8 CVE-2026-55005 Microsoft Exchange Server Remote Code Execution Vulnerability 14. juli 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

    Produsent
    Microsoft · Microsoft Exchange Server
    Produktområde
    Exchange Server
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.8 CVE-2026-55001 Active Directory Domain Services Elevation of Privilege Vulnerability 14. juli 2026

    Improper certificate validation in Windows Active Directory allows an authorized attacker to elevate privileges locally.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-295: Improper Certificate Validation
    CVSS 3.1
    CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-54983 Windows Active Directory Federation Services Denial of Service Vulnerability 14. juli 2026

    Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Roundcube Webmail 7.2 CVE-2026-54433 Roundcube Webmail: Cross-Site Scripting 14. juli 2026

    In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or previewing the message (zero-click).

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
    Publisert
    14. juli 2026
  • Roundcube Webmail 4.7 CVE-2026-54432 Roundcube Webmail: Cross-Site Scripting 14. juli 2026

    Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs because the attachment MIME type is not properly escaped on the attachment-validation warning page.

    Produsent
    Roundcube · Webmail
    Produktområde
    Webmail
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 8.8 CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Vulnerability 14. juli 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-285: Improper Authorization
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-54119 Windows Active Directory Denial of Service Vulnerability 14. juli 2026

    Loop with unreachable exit condition ('infinite loop') in Windows Active Directory allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50695 Windows Active Directory Federation Services Denial of Service Vulnerability 14. juli 2026

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 4.8 CVE-2026-50684 Active Directory Federation Server Spoofing Vulnerability 14. juli 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-79: Cross-Site Scripting
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.1 CVE-2026-50682 Active Directory Denial of Service Vulnerability 14. juli 2026

    Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.

    Produsent
    Microsoft · Windows 10 Version 21H2
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-125: Out-of-bounds Read
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability 14. juli 2026

    Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Azure Active Directory
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50652 Azure Active Directory Denial of Service Vulnerability 14. juli 2026

    Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Azure Active Directory
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-502: Deserialization of Untrusted Data
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50647 Active Directory Federation Server Denial of Service Vulnerability 14. juli 2026

    Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50411 Windows Active Directory Federation Services Denial of Service Vulnerability 14. juli 2026

    Stack-based buffer overflow in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50368 Windows Active Directory Federation Services Denial of Service Vulnerability 14. juli 2026

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 6.5 CVE-2026-50366 Windows Active Directory Domain Services Denial of Service Vulnerability 14. juli 2026

    Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-476: NULL Pointer Dereference
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50355 Windows Active Directory Federation Services Denial of Service Vulnerability 14. juli 2026

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 5.9 CVE-2026-50324 Windows Active Directory Federation Services Denial of Service Vulnerability 14. juli 2026

    Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 7.5 CVE-2026-50304 Windows Active Directory Federation Services Denial of Service Vulnerability 14. juli 2026

    Stack-based buffer overflow in Active Directory Federation Services allows an unauthorized attacker to deny service over a network.

    Produsent
    Microsoft · Microsoft .NET Framework 3.5 AND 4.7.2
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-121: Stack-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 8.8 CVE-2026-49178 Windows Active Directory Domain Services Remote Code Execution Vulnerability 14. juli 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Heap-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • Microsoft Active Directory / Entra 8.1 CVE-2026-49164 Windows Active Directory Domain Services Remote Code Execution Vulnerability 14. juli 2026

    Kritisk eller aktivt utnyttet: gir et e-postvarsel

    Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.

    Produsent
    Microsoft · Windows 10 Version 1607
    Produktområde
    Active Directory / Entra
    Type svakhet
    CWE-122: Heap-based Buffer Overflow
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
    Publisert
    14. juli 2026
  • SonicWall SMA1000 Appliances 7.2 KEV CVE-2026-15410 SonicWall SMA1000: Code Injection 14. juli 2026

    Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

    Produsent
    SonicWall · SMA1000
    Type svakhet
    CWE-94: Code Injection
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
    Publisert
    14. juli 2026
    I KEV-katalogen siden
    14. juli 2026 · Brukt i løsepengevirus-kampanjer
  • SonicWall SMA1000 Appliances 10.0 KEV CVE-2026-15409 SonicWall SMA1000: Server-Side Request Forgery 14. juli 2026

    A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

    Produsent
    SonicWall · SMA1000
    Type svakhet
    CWE-918: Server-Side Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Publisert
    14. juli 2026
    I KEV-katalogen siden
    14. juli 2026 · Brukt i løsepengevirus-kampanjer
  • Cisco IOS 8.1 KEV CVE-2008-4128 Cross-Site Request Forgery 13. juli 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. NOTE: some of these details are obtained from third party information.

    Type svakhet
    CWE-352: Cross-Site Request Forgery
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
    Publisert
    18. sep. 2008
    I KEV-katalogen siden
    13. juli 2026
  • Balbooa Forms 10.0 KEV CVE-2026-56291 Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 10. juli 2026

    Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

    Produsent
    balbooa.com · balbooa.com Balbooa Forms extension for Joomla
    Type svakhet
    CWE-434: Unrestricted File Upload
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
    Publisert
    9. juli 2026
    I KEV-katalogen siden
    10. juli 2026
  • iCagenda 10.0 KEV CVE-2026-48939 Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15 10. juli 2026

    A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

    Produsent
    icagenda.com · iCagenda extension for Joomla
    Type svakhet
    CWE-434: Unrestricted File Upload
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
    Publisert
    20. juni 2026
    I KEV-katalogen siden
    10. juli 2026
  • OpenBSD OpenSSH 7.7 CVE-2026-60002 OpenBSD OpenSSH: Use After Free 8. juli 2026

    ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

    Produsent
    OpenBSD · OpenSSH
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-416: Use After Free
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
    Publisert
    8. juli 2026
  • OpenBSD OpenSSH 6.5 CVE-2026-60001 OpenBSD OpenSSH: Allocation of Resources Without Limits or Throttling 8. juli 2026

    sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

    Produsent
    OpenBSD · OpenSSH
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
    Publisert
    8. juli 2026
  • OpenBSD OpenSSH 3.7 CVE-2026-60000 OpenBSD OpenSSH: Allocation of Resources Without Limits or Throttling 8. juli 2026

    sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

    Produsent
    OpenBSD · OpenSSH
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-770: Allocation of Resources Without Limits or Throttling
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
    Publisert
    8. juli 2026
  • OpenBSD OpenSSH 5.9 CVE-2026-59999 OpenBSD OpenSSH: Use of Less Trusted Source 8. juli 2026

    In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

    Produsent
    OpenBSD · OpenSSH
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-348: Use of Less Trusted Source
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
    Publisert
    8. juli 2026
  • OpenBSD OpenSSH 4.8 CVE-2026-59998 OpenBSD OpenSSH: Improper Following of Specification by Caller 8. juli 2026

    sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

    Produsent
    OpenBSD · OpenSSH
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-573: Improper Following of Specification by Caller
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
    Publisert
    8. juli 2026
  • OpenBSD OpenSSH 4.2 CVE-2026-59997 OpenBSD OpenSSH: Improper Validation of Specified Quantity in Input 8. juli 2026

    internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

    Produsent
    OpenBSD · OpenSSH
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-1284: Improper Validation of Specified Quantity in Input
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
    Publisert
    8. juli 2026
  • OpenBSD OpenSSH 4.2 CVE-2026-59996 OpenBSD OpenSSH: Relative Path Traversal 8. juli 2026

    scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

    Produsent
    OpenBSD · OpenSSH
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-23: Relative Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
    Publisert
    8. juli 2026
  • OpenBSD OpenSSH 4.2 CVE-2026-59995 OpenBSD OpenSSH: Relative Path Traversal 8. juli 2026

    sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

    Produsent
    OpenBSD · OpenSSH
    Produktområde
    OpenSSL / OpenSSH
    Type svakhet
    CWE-23: Relative Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
    Publisert
    8. juli 2026
  • Joomlack Page Builder 10.0 KEV CVE-2026-56290 Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 7. juli 2026

    Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

    Produsent
    joomlack.fr · JoomlaCK.fr Page Builder CK extension for Joomla
    Type svakhet
    CWE-434: Unrestricted File Upload
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
    Publisert
    29. juni 2026
    I KEV-katalogen siden
    7. juli 2026
  • Langflow 8.4 KEV CVE-2026-55255 Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow 7. juli 2026

    Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability is fixed in 1.9.1.

    Produsent
    langflow-ai · langflow
    Type svakhet
    CWE-639: Authorization Bypass Through User-Controlled Key
    CVSS 3.1
    CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
    Publisert
    23. juni 2026
    I KEV-katalogen siden
    7. juli 2026
  • JoomShaper SP Page Builder 10.0 KEV CVE-2026-48908 Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2 7. juli 2026

    A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

    Produsent
    joomshaper.net · SP Page Builder extension for Joomla
    Type svakhet
    CWE-434: Unrestricted File Upload
    CVSS 4.0
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
    Publisert
    20. juni 2026
    I KEV-katalogen siden
    7. juli 2026
  • Adobe ColdFusion 10.0 KEV CVE-2026-48282 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) 7. juli 2026

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

    Produsent
    Adobe · ColdFusion 2025
    Type svakhet
    CWE-22: Path Traversal
    CVSS 3.1
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Publisert
    30. juni 2026
    I KEV-katalogen siden
    7. juli 2026

Omtalt i artikler

Sårbarheter som gjennomgås i detalj i artiklene og kunnskapsbasen. Hver CVE fører til sin analyse.

16 sårbarheter · Referansedata: CVE.org (CNA-opplysninger) og CISA Known Exploited Vulnerabilities, per siste build.

CVE Produkt CVSS Publisert Analyse
CVE-2026-104286 Fortinet FortiMail: Path Traversal FortiMail 9.8 KEV 1. okt. 2026
CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability Cisco Secure Email 9.8 KEV 14. sep. 2026
CVE-2026-73570 Zimbra Collaboration: OS Command Injection Collaboration 8.9 KEV 13. aug. 2026
CVE-2026-65813 Microsoft Exchange Server Elevation of Privilege Vulnerability Microsoft Exchange Server 6.5 11. aug. 2026
CVE-2026-62915 Microsoft Exchange Server Security Feature Bypass Vulnerability Microsoft Exchange Server 6.5 11. aug. 2026
CVE-2026-62914 Microsoft Exchange Server Spoofing Vulnerability Microsoft Exchange Server 7.3 11. aug. 2026
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server 8.8 11. aug. 2026
CVE-2026-62912 Microsoft Exchange Server Denial of Service Vulnerability Microsoft Exchange Server 6.5 11. aug. 2026
CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability Microsoft Exchange Server 8.0 11. aug. 2026
CVE-2026-62910 Microsoft Exchange Server Elevation of Privilege Vulnerability Microsoft Exchange Server 7.2 11. aug. 2026
CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability Microsoft Exchange Server 8.1 KEV 14. mai 2026
CVE-2025-20393 Cisco Secure Email Gateway and Cisco Secure Email and Web Manager Remote Command Execution Vulnerability Cisco Secure Email 10.0 KEV 17. des. 2025
CVE-2025-32756 Fortinet FortiNDR: Stack-based Buffer Overflow FortiNDR 9.6 KEV 13. mai 2025
CVE-2024-28063 Kiteworks totemomail: Cross-Site Scripting totemomail 6.1 18. mai 2024
CVE-2020-7918 totemomail: Insecure Direct Object Reference totemomail – 27. mars 2020
CVE-2018-6563 totemomail Encryption Gateway: Cross-Site Request Forgery totemomail Encryption Gateway – 20. juni 2018