CVE tracker
322 subscribers
4.53K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-44917 - OpenStack Ironic Local File Read via PXE Template

CVE ID :CVE-2026-44917
Published : June 4, 2026, 4:17 a.m. | 2 hours, 54 minutes ago
Description :OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-48681 - OpenStack Ironic Directory Traversal File Overwrite

CVE ID :CVE-2026-48681
Published : June 4, 2026, 4:17 a.m. | 2 hours, 54 minutes ago
Description :OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49185 - Instruction Injection via FieldX MDM

CVE ID :CVE-2026-49185
Published : June 4, 2026, 4:17 a.m. | 2 hours, 54 minutes ago
Description :The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction injection.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49186 - Lack of MQTT Broker Topic Access Control Lists

CVE ID :CVE-2026-49186
Published : June 4, 2026, 4:17 a.m. | 2 hours, 54 minutes ago
Description :The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10805 - Networkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backend

CVE ID :CVE-2026-10805
Published : June 4, 2026, 6:16 a.m. | 54 minutes ago
Description :A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via a crafted MUD URL, provided an administrator has explicitly configured NetworkManager to use dhclient. This issue does not affect default configurations of NetworkManager.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49187 - Hard-coded APK Resource Credentials & Scepters

CVE ID :CVE-2026-49187
Published : June 4, 2026, 6:16 a.m. | 54 minutes ago
Description :The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49188 - Elevated Root Command Execution via ai_cmd Sockets

CVE ID :CVE-2026-49188
Published : June 4, 2026, 6:16 a.m. | 54 minutes ago
Description :The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49189 - Broadcast Receiver Privilege Escalation

CVE ID :CVE-2026-49189
Published : June 4, 2026, 6:16 a.m. | 54 minutes ago
Description :Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50219 - Expat Use-After-Free Vulnerability

CVE ID :CVE-2026-50219
Published : June 4, 2026, 6:16 a.m. | 54 minutes ago
Description :libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-49204 - Hard-coded AWS Cognito Testing Accounts

CVE ID :CVE-2026-49204
Published : June 4, 2026, 7:16 a.m. | 3 hours, 56 minutes ago
Description :Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50205 - Plaintext Log Credential Leakage

CVE ID :CVE-2026-50205
Published : June 4, 2026, 7:16 a.m. | 3 hours, 56 minutes ago
Description :System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50206 - VPN Command Injection Vulnerability

CVE ID :CVE-2026-50206
Published : June 4, 2026, 7:16 a.m. | 3 hours, 56 minutes ago
Description :Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-3820 - Supermicro BMC's SMTP service contains a command injection vulnerability

CVE ID :CVE-2026-3820
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.  An attacker may obtain administrator privileges and inject specially crafted characters into the SMTP service configuration. This may cause the underlying system to execute unintended commands during process invocation. Potential impact includes denial-of-service attacks, arbitrary code execution, or permanent compromise of the controller.
Severity: 7.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50207 - Local Modem Manipulation via Binder Interfaces

CVE ID :CVE-2026-50207
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50208 - Permissive TrustAllCerts TLS Verification

CVE ID :CVE-2026-50208
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
Severity: 9.2 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50209 - MDM Server Registration Overriding

CVE ID :CVE-2026-50209
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50210 - Weak Static Cryptographic Initialization Vectors

CVE ID :CVE-2026-50210
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50211 - Exposed Factory Testing App Boundaries

CVE ID :CVE-2026-50211
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50212 - Arbitrary Remote Device Unbinding

CVE ID :CVE-2026-50212
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-50213 - Bulk User Private Data Harvesting

CVE ID :CVE-2026-50213
Published : June 4, 2026, 9:16 a.m. | 1 hour, 56 minutes ago
Description :The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-10305 - Samsung Open Source rlottie Out-of-Bounds Read

CVE ID :CVE-2026-10305
Published : June 4, 2026, 10:16 a.m. | 56 minutes ago
Description :Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.
Severity: 6.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...