Cve

65 posts tagged with “Cve

Aborted multer uploads still fill the disk after the 5038 fix
cvemulternpm

Aborted multer uploads still fill the disk after the 5038 fix

How to fix CVE-2026-88932: upgrade multer to 2.4.0

Sep 16, 2026
Read
BREAKING: Unbound DNSKEY digest overflow can RCE your resolver (1.26.1)
cveunbounddns

BREAKING: Unbound DNSKEY digest overflow can RCE your resolver (1.26.1)

How to fix CVE-2026-81642: upgrade Unbound to 1.26.1

Sep 16, 2026
Read
ScreenConnect client file runs hit CISA KEV
cvescreenconnectconnectwise

ScreenConnect client file runs hit CISA KEV

How to fix CVE-2026-84869: upgrade ScreenConnect to 26.6.5 or later, then reinstall host clients and update access agents

Sep 11, 2026
Read
Self-managed GitLab: unauth commits API file read hits CISA KEV
cvegitlabpath-traversal

Self-managed GitLab: unauth commits API file read hits CISA KEV

How to fix CVE-2026-85706: upgrade GitLab to 19.1.8 / 19.2.6 / 19.3.2

Sep 11, 2026
Read
Artifactory anonymous token chain hits CISA KEV
cvejfrogartifactory

Artifactory anonymous token chain hits CISA KEV

How to fix CVE-2026-42018 / CVE-2026-42016: upgrade self-hosted Artifactory past the anonymous-JWT and token-scope floors (prefer 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20)

Sep 11, 2026
Read
CVE-2026-71416: Headroom WebSocket proxy spends your OpenAI key for any reachable browser
cveheadroomheadroom-ai

CVE-2026-71416: Headroom WebSocket proxy spends your OpenAI key for any reachable browser

How to fix CVE-2026-71416: upgrade headroom-ai to 0.35.0

Sep 11, 2026
Read
CVE-2026-87776: Express compression leaks native memory until the process dies
cvecompressionexpress

CVE-2026-87776: Express compression leaks native memory until the process dies

How to fix CVE-2026-87776: upgrade compression to 1.8.2

Sep 11, 2026
Read
CVE-2026-57967: unauth Artemis CORE session steal and OpenWire queue delete
cveapache-artemisactivemq-artemis

CVE-2026-57967: unauth Artemis CORE session steal and OpenWire queue delete

How to fix CVE-2026-57967: upgrade Apache Artemis / ActiveMQ Artemis to 2.57.0. Unauth CORE SESSION_REATTACH can steal a live session; OpenWire RemoveSubscriptionInfo can delete queues before auth.

Sep 10, 2026
Read
BREAKING: CVE-2026-0310 PAN-OS XML overflow gives unauth root on PA-Series
cvepan-ospalo-alto

BREAKING: CVE-2026-0310 PAN-OS XML overflow gives unauth root on PA-Series

How to fix CVE-2026-0310: upgrade PAN-OS to the fixed hotfix for your train (for example 12.2.3, 12.1.10, 11.2.13-h2, 11.1.16-h2, 10.2.18-h10). Unauth XML to management web or dataplane can root PA-Series firewalls.

Sep 10, 2026
Read
CVE-2026-77774: Magento still needs APSB26-138 after the StyleSmuggler hotfix
cveadobe-commercemagento

CVE-2026-77774: Magento still needs APSB26-138 after the StyleSmuggler hotfix

How to fix CVE-2026-77774: apply Adobe APSB26-138 September Isolated patches (or *-2026-sep builds) after the StyleSmuggler hotfix, then verify with php vendor/bin/patch-status

Sep 8, 2026
Read
CVE-2026-75021: fastify-cli debug-host bind can expose Inspector RCE
cvefastify-clinodejs

CVE-2026-75021: fastify-cli debug-host bind can expose Inspector RCE

How to fix CVE-2026-75021: upgrade fastify-cli to 8.0.1

Sep 8, 2026
Read
BREAKING: CVE-2026-75650 lets unauth callers run code on Adobe Commerce and Magento
cveadobe-commercemagento

BREAKING: CVE-2026-75650 lets unauth callers run code on Adobe Commerce and Magento

How to fix CVE-2026-75650: apply Adobe hotfix VULN-39341 from repo.magento.com, then rotate the Commerce encryption key and every credential it protected

Sep 7, 2026
Read
BREAKING: CVE-2026-75650 is unauthenticated RCE in Adobe Commerce and Magento, already exploited
cveadobe-commercemagento

BREAKING: CVE-2026-75650 is unauthenticated RCE in Adobe Commerce and Magento, already exploited

How to fix CVE-2026-75650: apply Adobe hotfix VULN-39341 for Adobe Commerce / Magento Open Source, then rotate the encryption key and all protected credentials

Sep 7, 2026
Read
BREAKING: CVE-2026-76578 lets an unauthenticated LDAP client become a FreeIPA admin
cvefreeipaidm

BREAKING: CVE-2026-76578 lets an unauthenticated LDAP client become a FreeIPA admin

How to fix CVE-2026-76578: firewall FreeIPA LDAP ports 389/636 and disable anonymous binds until the IPA/IdM package with the hardened OTP ACI ships

Sep 7, 2026
Read
BREAKING: CVE-2026-86259 lets unauth OpenMAIC callers pull cloud credentials via SSRF
cveopenmaicssrf

BREAKING: CVE-2026-86259 lets unauth OpenMAIC callers pull cloud credentials via SSRF

How to fix CVE-2026-86259: upgrade OpenMAIC to 1.0.1

Sep 6, 2026
Read
BREAKING: CVE-2026-67276 and MikroTrick can take over MikroTik RouterOS with SSH exposed
cvemikrotikrouteros

BREAKING: CVE-2026-67276 and MikroTrick can take over MikroTik RouterOS with SSH exposed

How to fix CVE-2026-67276: upgrade RouterOS to 7.24.2, 7.23.4, or 6.49.21

Sep 5, 2026
Read
BREAKING: CVE-2026-0799 lets crafted BPF filters walk libpcap process memory
cvelibpcaptcpdump

BREAKING: CVE-2026-0799 lets crafted BPF filters walk libpcap process memory

How to fix CVE-2026-0799: upgrade libpcap to 1.10.7 (covers six sibling CVEs)

Sep 5, 2026
Read
CVE-2026-85787: AWS postgres MCP read-only denylist missed set_config()
cveawslabspostgres-mcp-server

CVE-2026-85787: AWS postgres MCP read-only denylist missed set_config()

How to fix CVE-2026-85787: upgrade awslabs.postgres-mcp-server to 1.1.7 or newer

Sep 4, 2026
Read
BREAKING: CVE-2026-9317 lets anyone who can reach your Nango runner run code
cvenangorce

BREAKING: CVE-2026-9317 lets anyone who can reach your Nango runner run code

How to fix CVE-2026-9317: upgrade nango to 0.71.6 and set NANGO_INTERNAL_AUTH_REQUIRED=true

Sep 4, 2026
Read
CVE-2026-85024: undici WebSocket deflate bug can crash the Node process
cveundicinodejs

CVE-2026-85024: undici WebSocket deflate bug can crash the Node process

How to fix CVE-2026-85024: upgrade undici to 8.10.2 (or 7.29.1 / 6.28.1 on older trains)

Sep 4, 2026
Read
BREAKING: CVE-2026-76169 lets malformed URLs skip Fastify not-found auth
cvefastifyauth-bypass

BREAKING: CVE-2026-76169 lets malformed URLs skip Fastify not-found auth

How to fix CVE-2026-76169: upgrade fastify to 5.12.2

Sep 4, 2026
Read
BREAKING: CVE-2026-85184 lets absolute-form requests skip Fastify middie auth
cvefastifymiddie

BREAKING: CVE-2026-85184 lets absolute-form requests skip Fastify middie auth

How to fix CVE-2026-85184: upgrade @fastify/middie to 9.3.4

Sep 4, 2026
Read
BREAKING: CVE-2026-85046 is a Chrome V8 bug Google says is exploited in the wild
cvechromev8

BREAKING: CVE-2026-85046 is a Chrome V8 bug Google says is exploited in the wild

How to fix CVE-2026-85046: upgrade Chrome to 152.0.7977.82 (Linux) or 152.0.7977.82/.83 (Windows and Mac)

Sep 3, 2026
Read
CVE-2026-71963: Hermes Agent runs Git config before the first prompt
cvehermes-agentai-agents

CVE-2026-71963: Hermes Agent runs Git config before the first prompt

How to fix CVE-2026-71963: update Hermes Agent to a build containing commit f6234d0 or a later vendor release.

Sep 3, 2026
Read
CVE-2026-75033: one Rancher annotation copies another cluster's secrets
cverancherkubernetes

CVE-2026-75033: one Rancher annotation copies another cluster's secrets

How to fix CVE-2026-75033: upgrade Rancher to 2.15.1, 2.14.5, 2.13.9, or 2.12.13, and move rancher-webhook with it.

Sep 3, 2026
Read
BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts
cveollamassrf

BREAKING: CVE-2026-85180 lets Ollama model pulls reach internal hosts

How to fix CVE-2026-85180: no patched Ollama release is available yet

Sep 3, 2026
Read
BREAKING: JFrog Artifactory unauth admin on default config
cveartifactoryjfrog

BREAKING: JFrog Artifactory unauth admin on default config

How to fix CVE-2026-82329: upgrade self-hosted Artifactory to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20

Aug 28, 2026
Read
BREAKING: PaperCut NG/MF unauth admin config plus class-loading
cvepapercutng

BREAKING: PaperCut NG/MF unauth admin config plus class-loading

How to fix CVE-2026-81578: install PaperCut Emergency Patch Release 2 (PO-4560) for NG/MF v24/v25/v26

Aug 28, 2026
Read
BREAKING: WatchGuard Fireware iked type-confusion on IKE_AUTH
cvewatchguardfireware

BREAKING: WatchGuard Fireware iked type-confusion on IKE_AUTH

How to fix CVE-2026-19315: upgrade Fireware OS to 2026.2.2, 12.12.2, or 12.5.20

Aug 28, 2026
Read
CVE-2026-81934: Redis TLS pending-list use-after-free (public RCE PoC)
cveredistls

CVE-2026-81934: Redis TLS pending-list use-after-free (public RCE PoC)

How to fix CVE-2026-81934: upgrade Redis to 8.2.9, 8.4.6, 8.6.6, 8.8.2, or 8.10.1

Aug 27, 2026
Read
CVE-2026-19042: TeamViewer Linux Chat Link Command Injection (and Sibling CVE-2026-16444)
cveteamviewercommand-injection

CVE-2026-19042: TeamViewer Linux Chat Link Command Injection (and Sibling CVE-2026-16444)

How to fix CVE-2026-19042: upgrade TeamViewer Full Client and Host for Linux to 15.81

Aug 26, 2026
Read
CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)
cvechainlitmcp

CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)

How to fix CVE-2026-45018: upgrade chainlit to 2.12.0, then restart so /mcp loads the new wheel

Aug 25, 2026
Read
BREAKING: Next.js unauthenticated RCE in image optimization and Windows servers (CVE-2026-75604)
cvenextjsrce

BREAKING: Next.js unauthenticated RCE in image optimization and Windows servers (CVE-2026-75604)

How to fix CVE-2026-75604: upgrade next to 15.5.24 or 16.3.3

Aug 25, 2026
Read
CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)
cvedb-gptpath-traversal

CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)

How to fix CVE-2026-80104: upgrade dbgpt-app to 0.8.1, then confirm the python upload user_id fix is in your build

Aug 25, 2026
Read
CVE-2026-63072: OpenSSL CMS decrypt writes eight bytes past the unwrap buffer
cveopensslcms

CVE-2026-63072: OpenSSL CMS decrypt writes eight bytes past the unwrap buffer

How to fix CVE-2026-63072: upgrade OpenSSL to 3.0.22, 3.4.7, 3.5.8, 3.6.4, or 4.0.2. CMS_decrypt writes eight bytes past the unwrap buffer. Same 25 August advisory as eight sibling CVEs. Not RCE. FIPS module not in scope.

Aug 25, 2026
Read
CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation
cveapache-hiveauthn

CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation

How to fix CVE-2026-53561: upgrade Apache Hive to 4.2.1. Unauthenticated SAML Bearer impersonation in HiveServer2 HTTP. Same 4.2.1 train as Metastore SQLi and Avro SerDe SSRF. Not RCE. Not the Kerberos default.

Aug 25, 2026
Read
CVE-2026-5006: Vault Privilege Escalation via Slash Injection in Templated Policy Paths
cvevaulthashicorp

CVE-2026-5006: Vault Privilege Escalation via Slash Injection in Templated Policy Paths

How to fix CVE-2026-5006: upgrade HashiCorp Vault Community Edition to 2.0.4 (Enterprise 2.0.4, 1.21.9, 1.20.14, or 1.19.20), then set deny_slash_in_templated_paths = true. Templated policy paths interpolate identity values. A slash in a controlled identity value becomes extra path segments and can grant capabilities the author did not intend. The deny-slash option defaults to false even after upgrade.

Aug 24, 2026
Read
CVE-2026-75899: fast-uri SSRF via Repeated Hostname Decoding
cvefast-urissrf

CVE-2026-75899: fast-uri SSRF via Repeated Hostname Decoding

How to fix CVE-2026-75899: upgrade fast-uri to 2.4.5, 3.1.6, or 4.1.3. Nested percent-encoding in a hostname becomes localhost after normalize() or resolve(). Not RCE. Same patch train as three sibling High SSRF and host-confusion GHSAs.

Aug 24, 2026
Read
CVE-2026-18420: OpenSearch Dashboards TSVB Prototype Pollution RCE
cvesecurityopensearch

CVE-2026-18420: OpenSearch Dashboards TSVB Prototype Pollution RCE

How to fix CVE-2026-18420: upgrade OpenSearch Dashboards to 3.8.0. Authenticated TSVB metrics JSON prototype pollution RCE. Affects OSS and AWS Managed >=3.0.0 <3.8.0.

Aug 21, 2026
Read
CVE-2026-19516: Grafana MCP Server SSRF Via Caller-Controlled URL Header
cvesecurityvulnerability

CVE-2026-19516: Grafana MCP Server SSRF Via Caller-Controlled URL Header

CVE-2026-19516 is a server-side request forgery in the Grafana MCP Server. A caller can set the X-Grafana-URL header to any destination and use the grafana_api_request tool to reach internal services and cloud metadata endpoints. No fix available.

Aug 21, 2026
Read
CVE-2026-77068: n8n Member RCE via MCP Node-Schema Path Traversal
cvesecurityvulnerability

CVE-2026-77068: n8n Member RCE via MCP Node-Schema Path Traversal

How to fix CVE-2026-77068: upgrade n8n to 2.35.5 (floor 2.33.4 / 2.34.1). Member-level MCP schema path traversal RCE in the MAIN process. Not unauthenticated.

Aug 20, 2026
Read
CVE-2026-76832: Agno PythonTools Path Traversal Escapes base_dir
cvesecurityvulnerability

CVE-2026-76832: Agno PythonTools Path Traversal Escapes base_dir

How to fix CVE-2026-76832: upgrade agno to 2.3.24 or later (current PyPI 2.9.0). PythonTools path traversal can read, write, or run files outside base_dir.

Aug 19, 2026
Read
BREAKING: CVE-2026-76850 - LMDeploy Pickle RCE in Disaggregated Serving
cvesecurityvulnerability

BREAKING: CVE-2026-76850 - LMDeploy Pickle RCE in Disaggregated Serving

How to fix CVE-2026-76850: upgrade InternLM lmdeploy to 0.16.0. Unauthenticated pickle RCE in disaggregated serving. Affects >=0.9.2 and <0.16.0.

Aug 19, 2026
Read
BREAKING: CVE-2026-18432 - Frontend Admin WordPress Unauthenticated Admin Takeover
cvesecurityvulnerability

BREAKING: CVE-2026-18432 - Frontend Admin WordPress Unauthenticated Admin Takeover

CVE-2026-18432 is a CVSS 9.8 privilege-escalation flaw in Frontend Admin by DynamiApps that can let unauthenticated attackers reset the default WordPress administrator account. Update to 3.29.10.

Aug 16, 2026
Read
BREAKING: CVE-2026-74764 - Pandora TAR Path Traversal Enables Arbitrary File Write
cvesecurityvulnerability

BREAKING: CVE-2026-74764 - Pandora TAR Path Traversal Enables Arbitrary File Write

CVE-2026-74764 is a CVSS 10.0 path traversal in Pandora TAR extraction that lets untrusted archives write outside the analysis directory. v1.12.5 is affected; deploy the upstream fix.

Aug 16, 2026
Read
BREAKING: CVE-2026-73043 - SiYuan Template Calculation RCE in Desktop Client
cvesecurityvulnerability

BREAKING: CVE-2026-73043 - SiYuan Template Calculation RCE in Desktop Client

CVE-2026-73043 is a critical SiYuan flaw where unsanitized database Template calculation output reaches Electron innerHTML and can become OS command execution. Upgrade to 3.7.4 or later.

Aug 16, 2026
Read
BREAKING: CVE-2026-73046 - SiYuan Basic Auth Lockout Bypass Enables Admin Brute Force
cvesecurityvulnerability

BREAKING: CVE-2026-73046 - SiYuan Basic Auth Lockout Bypass Enables Admin Brute Force

CVE-2026-73046 is a CVSS 9.8 flaw in SiYuan that lets remote attackers bypass CAPTCHA and lockout controls through HTTP Basic Auth and brute-force the admin access code. Upgrade to 3.8.0 or later.

Aug 16, 2026
Read
BREAKING: CVE-2026-19598 - Pods WordPress Plugin Unauthenticated Admin Takeover
cvesecurityvulnerability

BREAKING: CVE-2026-19598 - Pods WordPress Plugin Unauthenticated Admin Takeover

CVE-2026-19598 is a CVSS 9.8 authorization bypass in the Pods WordPress plugin that lets unauthenticated attackers reach admin methods and take over sites. Update to 3.3.9.1.

Aug 16, 2026
Read
BREAKING: CVE-2026-18549 - @fastify/multipart Aborted Upload DoS
cvesecurityvulnerability

BREAKING: CVE-2026-18549 - @fastify/multipart Aborted Upload DoS

CVE-2026-18549 lets unauthenticated clients leak temp files and hang request handlers in @fastify/multipart <10.1.1, causing disk and event-loop exhaustion. Upgrade to 10.1.1.

Aug 16, 2026
Read
BREAKING: CVE-2026-18165 - @fastify/oauth2 Login CSRF via Plantable State Cookies
cvesecurityvulnerability

BREAKING: CVE-2026-18165 - @fastify/oauth2 Login CSRF via Plantable State Cookies

@fastify/oauth2 7.2.0 through 8.2.0 accepts plantable OAuth state cookies from related hosts, enabling login CSRF. Upgrade to 8.3.0 and enable hostPrefixedCookies.

Aug 15, 2026
Read
BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass
cvesecurityvulnerability

BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass

CVE-2026-18500 lets @fastify/jwt before 10.2.2 override a route-specific verification key with the global secret, breaking JWT authorization-domain separation. NVD scores it 8.1 HIGH.

Aug 15, 2026
Read
CVE-2026-72880: Dokploy Certificate Path Traversal Enables Arbitrary File Write and Remote Code Execution
cvesecurityvulnerability

CVE-2026-72880: Dokploy Certificate Path Traversal Enables Arbitrary File Write and Remote Code Execution

Dokploy prior to 0.29.13 accepts a user-supplied certificatePath without confinement, allowing authenticated users to write files to arbitrary host locations and achieve remote code execution. Fixed in 0.29.13.

Aug 14, 2026
Read
CVE-2026-72842: OpenWrt luci-app-lxc ACL bypass to root code execution
cvesecurityvulnerability

CVE-2026-72842: OpenWrt luci-app-lxc ACL bypass to root code execution

CVE-2026-72842 lets a low-privileged LuCI user reach admin-only container routes in OpenWrt luci-app-lxc, then chains path traversal in the lxc_name parameter to control lxc.hook.start-host and execute code as root on the host.

Aug 14, 2026
Read
CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files
cvesecurityvulnerability

CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files

Hugging Face Accelerate through 1.14.0 fails to sanitize weight_map entries in sharded checkpoint indexes, allowing arbitrary file reads and denial of service via named pipes. Affects 27M monthly downloads.

Aug 13, 2026
Read
CVE-2026-19135: OpenNMS JEXL Measurement Sandbox Bypass
cvesecurityvulnerability

CVE-2026-19135: OpenNMS JEXL Measurement Sandbox Bypass

A JEXL sandbox bypass in the OpenNMS Measurements REST API lets a low-privileged authenticated user load arbitrary Java classes on the server (CVSS 5.4, CWE-470). Upgrade to Horizon 36.0.3, Meridian 2024.3.12, or Meridian 2025.0.9.

Aug 13, 2026
Read
CVE-2026-49819: UpSnap Initial-Superuser Takeover Chained to Root RCE
cvesecurityvulnerability

CVE-2026-49819: UpSnap Initial-Superuser Takeover Chained to Root RCE

UpSnap 4.4.1 through 5.3.5 lets an unauthenticated network-adjacent attacker claim the initial superuser account on a fresh install, then execute shell commands as root through the wake command handler. Upgrade to 5.4.0.

Aug 13, 2026
Read
CVE-2026-12624: HashiCorp Vault LIST Authorization Bypass via Trailing Slash
cvesecurityvulnerability

CVE-2026-12624: HashiCorp Vault LIST Authorization Bypass via Trailing Slash

CVE-2026-12624 lets a Vault token enumerate secrets beneath a path a deny policy was supposed to block. The ACL engine failed to enforce wildcard deny rules on LIST requests with a trailing slash. Fixed in Vault 2.0.3.

Aug 12, 2026
Read
CVE-2026-9318: tablib Stored XSS via HTML Export Dataset Title
cvesecurityvulnerability

CVE-2026-9318: tablib Stored XSS via HTML Export Dataset Title

tablib, a Python tabular data library with over 147 million PyPI downloads, contains a stored cross-site scripting vulnerability in its HTML export functionality. Attackers can embed JavaScript payloads in dataset titles that execute when the exported HTML file is opened in a browser. Fixed in version 3.10.0.

Aug 12, 2026
Read
CVE-2026-44763: Path Traversal in SAP MII Writes Files Outside Intended Directories
cvesecurityvulnerability

CVE-2026-44763: Path Traversal in SAP MII Writes Files Outside Intended Directories

SAP Manufacturing Integration and Intelligence fails to validate file paths in certain functions. A privileged attacker can write files outside the intended directory, with high impact across confidentiality, integrity, and availability.

Aug 11, 2026
Read
CVE-2026-66763: SAP BusinessObjects CMS Stores Credentials Behind a Hardcoded Cryptographic Key
cvesecurityvulnerability

CVE-2026-66763: SAP BusinessObjects CMS Stores Credentials Behind a Hardcoded Cryptographic Key

SAP BusinessObjects BI Platform CMS encrypts sensitive credentials with a hardcoded cryptographic key baked into the source code. Anyone with high privileges and local server access can extract and decrypt every stored password.

Aug 11, 2026
Read
CVE-2026-72693: kbd openvt Privilege Escalation Enables Passwordless Root Login
cvesecurityvulnerability

CVE-2026-72693: kbd openvt Privilege Escalation Enables Passwordless Root Login

The kbd package, shipped on virtually every Linux distribution, contains a local privilege escalation in openvt -u. A flaw in how authenticate_user() verifies process ownership lets an unprivileged user trigger a passwordless login -f root on a new virtual terminal.

Aug 11, 2026
Read
CVE-2026-6791: glibc wordexp Stack Clash via Tilde Expansion
cvesecurityvulnerability

CVE-2026-6791: glibc wordexp Stack Clash via Tilde Expansion

CVE-2026-6791 is a stack-based buffer overflow in glibc's wordexp() function. The parse_tilde internal function uses strndupa to allocate stack memory sized by attacker input with no bounds check, enabling a stack clash.

Aug 11, 2026
Read
CVE-2026-38447: osTicket Generates Predictable API Keys via MD5 Hashing (CVSS 9.8)
cvesecurityvulnerability

CVE-2026-38447: osTicket Generates Predictable API Keys via MD5 Hashing (CVSS 9.8)

osTicket 1.18.3 generates API keys using MD5 with predictable inputs (timestamp and client IP). An attacker can approximate the key generation time and brute-force the key space. Affects 5 million+ users and 15,000+ businesses worldwide.

Aug 4, 2026
Read
CVE-2026-18108: Net::SAML2 Authentication Bypass via Unsigned Encrypted Assertions (CVSS 9.8)
cvesecurityvulnerability

CVE-2026-18108: Net::SAML2 Authentication Bypass via Unsigned Encrypted Assertions (CVSS 9.8)

Net::SAML2 before 0.86 accepts decrypted SAML assertions that carry no XML signature. Any party can encrypt an unsigned assertion to an SP's published certificate and authenticate as an arbitrary user. Affects Azure AD, Okta, Google, ADFS, and all other IdPs.

Aug 4, 2026
Read
CVE-2026-52855: Pterodactyl Wings Leaks Daemon Configuration Secrets via Egg Templates (CVSS 9.9)
cvesecurityvulnerability

CVE-2026-52855: Pterodactyl Wings Leaks Daemon Configuration Secrets via Egg Templates (CVSS 9.9)

Pterodactyl Wings exposes its entire daemon configuration through egg configuration-file templating, leaking API keys, SFTP credentials, and database connection strings. CVSS 9.9. Fixed in version 1.12.3.

Aug 3, 2026
Read