Cve
65 posts tagged with “Cve”

Aborted multer uploads still fill the disk after the 5038 fix
How to fix CVE-2026-88932: upgrade multer to 2.4.0

BREAKING: Unbound DNSKEY digest overflow can RCE your resolver (1.26.1)
How to fix CVE-2026-81642: upgrade Unbound to 1.26.1

ScreenConnect client file runs hit CISA KEV
How to fix CVE-2026-84869: upgrade ScreenConnect to 26.6.5 or later, then reinstall host clients and update access agents

Self-managed GitLab: unauth commits API file read hits CISA KEV
How to fix CVE-2026-85706: upgrade GitLab to 19.1.8 / 19.2.6 / 19.3.2

Artifactory anonymous token chain hits CISA KEV
How to fix CVE-2026-42018 / CVE-2026-42016: upgrade self-hosted Artifactory past the anonymous-JWT and token-scope floors (prefer 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20)

CVE-2026-71416: Headroom WebSocket proxy spends your OpenAI key for any reachable browser
How to fix CVE-2026-71416: upgrade headroom-ai to 0.35.0

CVE-2026-87776: Express compression leaks native memory until the process dies
How to fix CVE-2026-87776: upgrade compression to 1.8.2

CVE-2026-57967: unauth Artemis CORE session steal and OpenWire queue delete
How to fix CVE-2026-57967: upgrade Apache Artemis / ActiveMQ Artemis to 2.57.0. Unauth CORE SESSION_REATTACH can steal a live session; OpenWire RemoveSubscriptionInfo can delete queues before auth.

BREAKING: CVE-2026-0310 PAN-OS XML overflow gives unauth root on PA-Series
How to fix CVE-2026-0310: upgrade PAN-OS to the fixed hotfix for your train (for example 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, 10.2.18-h10). Unauth XML to management web or dataplane can root PA-Series firewalls.

CVE-2026-77774: Magento still needs APSB26-138 after the StyleSmuggler hotfix
How to fix CVE-2026-77774: apply Adobe APSB26-138 September Isolated patches (or *-2026-sep builds) after the StyleSmuggler hotfix, then verify with php vendor/bin/patch-status

CVE-2026-75021: fastify-cli debug-host bind can expose Inspector RCE
How to fix CVE-2026-75021: upgrade fastify-cli to 8.0.1

BREAKING: CVE-2026-75650 lets unauth callers run code on Adobe Commerce and Magento
How to fix CVE-2026-75650: apply Adobe hotfix VULN-39341 from repo.magento.com, then rotate the Commerce encryption key and every credential it protected

BREAKING: CVE-2026-75650 is unauthenticated RCE in Adobe Commerce and Magento, already exploited
How to fix CVE-2026-75650: apply Adobe hotfix VULN-39341 for Adobe Commerce / Magento Open Source, then rotate the encryption key and all protected credentials

BREAKING: CVE-2026-76578 lets an unauthenticated LDAP client become a FreeIPA admin
How to fix CVE-2026-76578: firewall FreeIPA LDAP ports 389/636 and disable anonymous binds until the IPA/IdM package with the hardened OTP ACI ships

BREAKING: CVE-2026-86259 lets unauth OpenMAIC callers pull cloud credentials via SSRF
How to fix CVE-2026-86259: upgrade OpenMAIC to 1.0.1

BREAKING: CVE-2026-67276 and MikroTrick can take over MikroTik RouterOS with SSH exposed
How to fix CVE-2026-67276: upgrade RouterOS to 7.24.2, 7.23.4, or 6.49.21

BREAKING: CVE-2026-0799 lets crafted BPF filters walk libpcap process memory
How to fix CVE-2026-0799: upgrade libpcap to 1.10.7 (covers six sibling CVEs)

CVE-2026-85787: AWS postgres MCP read-only denylist missed set_config()
How to fix CVE-2026-85787: upgrade awslabs.postgres-mcp-server to 1.1.7 or newer

BREAKING: CVE-2026-9317 lets anyone who can reach your Nango runner run code
How to fix CVE-2026-9317: upgrade nango to 0.71.6 and set NANGO_INTERNAL_AUTH_REQUIRED=true

CVE-2026-85024: undici WebSocket deflate bug can crash the Node process
How to fix CVE-2026-85024: upgrade undici to 8.10.2 (or 7.29.1 / 6.28.1 on older trains)

BREAKING: CVE-2026-76169 lets malformed URLs skip Fastify not-found auth
How to fix CVE-2026-76169: upgrade fastify to 5.12.2

BREAKING: CVE-2026-85184 lets absolute-form requests skip Fastify middie auth
How to fix CVE-2026-85184: upgrade @fastify/middie to 9.3.4

BREAKING: CVE-2026-85046 is a Chrome V8 bug Google says is exploited in the wild
How to fix CVE-2026-85046: upgrade Chrome to 152.0.7977.82 (Linux) or 152.0.7977.82/.83 (Windows and Mac)

CVE-2026-71963: Hermes Agent runs Git config before the first prompt
How to fix CVE-2026-71963: update Hermes Agent to a build containing commit f6234d0 or a later vendor release.

CVE-2026-75033: one Rancher annotation copies another cluster's secrets
How to fix CVE-2026-75033: upgrade Rancher to 2.15.1, 2.14.5, 2.13.9, or 2.12.13, and move rancher-webhook with it.

BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts
How to fix CVE-2026-85180: no patched Ollama release is available yet

BREAKING: JFrog Artifactory unauth admin on default config
How to fix CVE-2026-82329: upgrade self-hosted Artifactory to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20

BREAKING: PaperCut NG/MF unauth admin config plus class-loading
How to fix CVE-2026-81578: install PaperCut Emergency Patch Release 2 (PO-4560) for NG/MF v24/v25/v26

BREAKING: WatchGuard Fireware iked type-confusion on IKE_AUTH
How to fix CVE-2026-19315: upgrade Fireware OS to 2026.2.2, 12.12.2, or 12.5.20

CVE-2026-81934: Redis TLS pending-list use-after-free (public RCE PoC)
How to fix CVE-2026-81934: upgrade Redis to 8.2.9, 8.4.6, 8.6.6, 8.8.2, or 8.10.1

CVE-2026-19042: TeamViewer Linux Chat Link Command Injection (and Sibling CVE-2026-16444)
How to fix CVE-2026-19042: upgrade TeamViewer Full Client and Host for Linux to 15.81

CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)
How to fix CVE-2026-45018: upgrade chainlit to 2.12.0, then restart so /mcp loads the new wheel

BREAKING: Next.js unauthenticated RCE in image optimization and Windows servers (CVE-2026-75604)
How to fix CVE-2026-75604: upgrade next to 15.5.24 or 16.3.3

CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)
How to fix CVE-2026-80104: upgrade dbgpt-app to 0.8.1, then confirm the python upload user_id fix is in your build

CVE-2026-63072: OpenSSL CMS decrypt writes eight bytes past the unwrap buffer
How to fix CVE-2026-63072: upgrade OpenSSL to 3.0.22, 3.4.7, 3.5.8, 3.6.4, or 4.0.2. CMS_decrypt writes eight bytes past the unwrap buffer. Same 25 August advisory as eight sibling CVEs. Not RCE. FIPS module not in scope.

CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation
How to fix CVE-2026-53561: upgrade Apache Hive to 4.2.1. Unauthenticated SAML Bearer impersonation in HiveServer2 HTTP. Same 4.2.1 train as Metastore SQLi and Avro SerDe SSRF. Not RCE. Not the Kerberos default.

CVE-2026-5006: Vault Privilege Escalation via Slash Injection in Templated Policy Paths
How to fix CVE-2026-5006: upgrade HashiCorp Vault Community Edition to 2.0.4 (Enterprise 2.0.4, 1.21.9, 1.20.14, or 1.19.20), then set deny_slash_in_templated_paths = true. Templated policy paths interpolate identity values. A slash in a controlled identity value becomes extra path segments and can grant capabilities the author did not intend. The deny-slash option defaults to false even after upgrade.

CVE-2026-75899: fast-uri SSRF via Repeated Hostname Decoding
How to fix CVE-2026-75899: upgrade fast-uri to 2.4.5, 3.1.6, or 4.1.3. Nested percent-encoding in a hostname becomes localhost after normalize() or resolve(). Not RCE. Same patch train as three sibling High SSRF and host-confusion GHSAs.

CVE-2026-18420: OpenSearch Dashboards TSVB Prototype Pollution RCE
How to fix CVE-2026-18420: upgrade OpenSearch Dashboards to 3.8.0. Authenticated TSVB metrics JSON prototype pollution RCE. Affects OSS and AWS Managed >=3.0.0 <3.8.0.

CVE-2026-19516: Grafana MCP Server SSRF Via Caller-Controlled URL Header
CVE-2026-19516 is a server-side request forgery in the Grafana MCP Server. A caller can set the X-Grafana-URL header to any destination and use the grafana_api_request tool to reach internal services and cloud metadata endpoints. No fix available.

CVE-2026-77068: n8n Member RCE via MCP Node-Schema Path Traversal
How to fix CVE-2026-77068: upgrade n8n to 2.35.5 (floor 2.33.4 / 2.34.1). Member-level MCP schema path traversal RCE in the MAIN process. Not unauthenticated.

CVE-2026-76832: Agno PythonTools Path Traversal Escapes base_dir
How to fix CVE-2026-76832: upgrade agno to 2.3.24 or later (current PyPI 2.9.0). PythonTools path traversal can read, write, or run files outside base_dir.

BREAKING: CVE-2026-76850 - LMDeploy Pickle RCE in Disaggregated Serving
How to fix CVE-2026-76850: upgrade InternLM lmdeploy to 0.16.0. Unauthenticated pickle RCE in disaggregated serving. Affects >=0.9.2 and <0.16.0.

BREAKING: CVE-2026-18432 - Frontend Admin WordPress Unauthenticated Admin Takeover
CVE-2026-18432 is a CVSS 9.8 privilege-escalation flaw in Frontend Admin by DynamiApps that can let unauthenticated attackers reset the default WordPress administrator account. Update to 3.29.10.

BREAKING: CVE-2026-74764 - Pandora TAR Path Traversal Enables Arbitrary File Write
CVE-2026-74764 is a CVSS 10.0 path traversal in Pandora TAR extraction that lets untrusted archives write outside the analysis directory. v1.12.5 is affected; deploy the upstream fix.

BREAKING: CVE-2026-73043 - SiYuan Template Calculation RCE in Desktop Client
CVE-2026-73043 is a critical SiYuan flaw where unsanitized database Template calculation output reaches Electron innerHTML and can become OS command execution. Upgrade to 3.7.4 or later.

BREAKING: CVE-2026-73046 - SiYuan Basic Auth Lockout Bypass Enables Admin Brute Force
CVE-2026-73046 is a CVSS 9.8 flaw in SiYuan that lets remote attackers bypass CAPTCHA and lockout controls through HTTP Basic Auth and brute-force the admin access code. Upgrade to 3.8.0 or later.

BREAKING: CVE-2026-19598 - Pods WordPress Plugin Unauthenticated Admin Takeover
CVE-2026-19598 is a CVSS 9.8 authorization bypass in the Pods WordPress plugin that lets unauthenticated attackers reach admin methods and take over sites. Update to 3.3.9.1.

BREAKING: CVE-2026-18549 - @fastify/multipart Aborted Upload DoS
CVE-2026-18549 lets unauthenticated clients leak temp files and hang request handlers in @fastify/multipart <10.1.1, causing disk and event-loop exhaustion. Upgrade to 10.1.1.

BREAKING: CVE-2026-18165 - @fastify/oauth2 Login CSRF via Plantable State Cookies
@fastify/oauth2 7.2.0 through 8.2.0 accepts plantable OAuth state cookies from related hosts, enabling login CSRF. Upgrade to 8.3.0 and enable hostPrefixedCookies.

BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass
CVE-2026-18500 lets @fastify/jwt before 10.2.2 override a route-specific verification key with the global secret, breaking JWT authorization-domain separation. NVD scores it 8.1 HIGH.

CVE-2026-72880: Dokploy Certificate Path Traversal Enables Arbitrary File Write and Remote Code Execution
Dokploy prior to 0.29.13 accepts a user-supplied certificatePath without confinement, allowing authenticated users to write files to arbitrary host locations and achieve remote code execution. Fixed in 0.29.13.

CVE-2026-72842: OpenWrt luci-app-lxc ACL bypass to root code execution
CVE-2026-72842 lets a low-privileged LuCI user reach admin-only container routes in OpenWrt luci-app-lxc, then chains path traversal in the lxc_name parameter to control lxc.hook.start-host and execute code as root on the host.

CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files
Hugging Face Accelerate through 1.14.0 fails to sanitize weight_map entries in sharded checkpoint indexes, allowing arbitrary file reads and denial of service via named pipes. Affects 27M monthly downloads.

CVE-2026-19135: OpenNMS JEXL Measurement Sandbox Bypass
A JEXL sandbox bypass in the OpenNMS Measurements REST API lets a low-privileged authenticated user load arbitrary Java classes on the server (CVSS 5.4, CWE-470). Upgrade to Horizon 36.0.3, Meridian 2024.3.12, or Meridian 2025.0.9.

CVE-2026-49819: UpSnap Initial-Superuser Takeover Chained to Root RCE
UpSnap 4.4.1 through 5.3.5 lets an unauthenticated network-adjacent attacker claim the initial superuser account on a fresh install, then execute shell commands as root through the wake command handler. Upgrade to 5.4.0.

CVE-2026-12624: HashiCorp Vault LIST Authorization Bypass via Trailing Slash
CVE-2026-12624 lets a Vault token enumerate secrets beneath a path a deny policy was supposed to block. The ACL engine failed to enforce wildcard deny rules on LIST requests with a trailing slash. Fixed in Vault 2.0.3.

CVE-2026-9318: tablib Stored XSS via HTML Export Dataset Title
tablib, a Python tabular data library with over 147 million PyPI downloads, contains a stored cross-site scripting vulnerability in its HTML export functionality. Attackers can embed JavaScript payloads in dataset titles that execute when the exported HTML file is opened in a browser. Fixed in version 3.10.0.

CVE-2026-44763: Path Traversal in SAP MII Writes Files Outside Intended Directories
SAP Manufacturing Integration and Intelligence fails to validate file paths in certain functions. A privileged attacker can write files outside the intended directory, with high impact across confidentiality, integrity, and availability.

CVE-2026-66763: SAP BusinessObjects CMS Stores Credentials Behind a Hardcoded Cryptographic Key
SAP BusinessObjects BI Platform CMS encrypts sensitive credentials with a hardcoded cryptographic key baked into the source code. Anyone with high privileges and local server access can extract and decrypt every stored password.

CVE-2026-72693: kbd openvt Privilege Escalation Enables Passwordless Root Login
The kbd package, shipped on virtually every Linux distribution, contains a local privilege escalation in openvt -u. A flaw in how authenticate_user() verifies process ownership lets an unprivileged user trigger a passwordless login -f root on a new virtual terminal.

CVE-2026-6791: glibc wordexp Stack Clash via Tilde Expansion
CVE-2026-6791 is a stack-based buffer overflow in glibc's wordexp() function. The parse_tilde internal function uses strndupa to allocate stack memory sized by attacker input with no bounds check, enabling a stack clash.

CVE-2026-38447: osTicket Generates Predictable API Keys via MD5 Hashing (CVSS 9.8)
osTicket 1.18.3 generates API keys using MD5 with predictable inputs (timestamp and client IP). An attacker can approximate the key generation time and brute-force the key space. Affects 5 million+ users and 15,000+ businesses worldwide.

CVE-2026-18108: Net::SAML2 Authentication Bypass via Unsigned Encrypted Assertions (CVSS 9.8)
Net::SAML2 before 0.86 accepts decrypted SAML assertions that carry no XML signature. Any party can encrypt an unsigned assertion to an SP's published certificate and authenticate as an arbitrary user. Affects Azure AD, Okta, Google, ADFS, and all other IdPs.

CVE-2026-52855: Pterodactyl Wings Leaks Daemon Configuration Secrets via Egg Templates (CVSS 9.9)
Pterodactyl Wings exposes its entire daemon configuration through egg configuration-file templating, leaking API keys, SFTP credentials, and database connection strings. CVSS 9.9. Fixed in version 1.12.3.