CVE tracker
387 subscribers
5.44K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-59507 - Priority – CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

CVE ID :CVE-2026-59507
Published : Aug. 13, 2026, 10:17 a.m. | 1 hour, 23 minutes ago
Description :CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control
Severity: 9.3 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-45819 - baseline-browser-mapping Denial of Service Vulnerability

CVE ID :CVE-2026-45819
Published : Aug. 13, 2026, 11:03 a.m. | 37 minutes ago
Description :baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.
Severity: 6.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-12263 - Authentication Bypass

CVE ID :CVE-2026-12263
Published : Aug. 13, 2026, 11:17 a.m. | 23 minutes ago
Description :Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerability due to improper SAML validation.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-16455 - Local privilege escalation via improper input sanitization in execl() call

CVE ID :CVE-2026-16455
Published : Aug. 13, 2026, 11:17 a.m. | 23 minutes ago
Description :In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-18368 - Heap buffer overflow in Modbusgwd

CVE ID :CVE-2026-18368
Published : Aug. 13, 2026, 11:17 a.m. | 23 minutes ago
Description :In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data. A remote, unauthenticated attacker with access to the affected service could trigger a heap-based buffer overflow, resulting in a denial of service.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68453 - s390/zcrypt: Fix buffer over-read in cca_cipher2protkey

CVE ID :CVE-2026-68453
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in cca_gencipherkey() for possible underflow with returned key size. The CCA token structures contain user-controlled len fields that were used in operations without proper validation against both the actual buffer size and minimum token structure size. An attacker could set this field larger than the actual buffer size, leading to reading beyond buffer boundaries. This may result in a kernel crash or exposure of memory via sending this as part of a request down to the crypto card. Also an attacker could have used a very small len value and thus enforce a buffer under-run which may produce similar effects as a over-read. So now a key must - key buf length must be at least sizeof the token struct - the key len field inside the token must fit into the range of sizeof key token struct ... key buf length
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-68454 - KVM: s390: pci: Fix handling of AIF enable without AISB

CVE ID :CVE-2026-68454
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest AISB location instead of virt_to_phys(page_address(NULL)).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-6387 - Lenovo System Update Local Privilege Escalation Vulnerability

CVE ID :CVE-2026-6387
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70452 - rsync 3.1.0 < 3.5.0 Access Control Bypass via DNS Resolution Failure

CVE ID :CVE-2026-70452
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the daemon skips the rule rather than defaulting to a deny decision, enabling attackers who can trigger DNS failures to bypass module-level IP access controls and gain unauthorized access to restricted module file trees.
Severity: 9.1 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70453 - rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()

CVE ID :CVE-2026-70453
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash lookups to exhaust receiver CPU resources with a modest number of crafted entries, causing a sustained denial of service.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70454 - rsync < 3.5.0 TLS Certificate Validation Bypass via SSL/OpenSSL Mode

CVE ID :CVE-2026-70454
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS certificates against a trusted CA or verify certificate hostname matching to decrypt or tamper with rsync session content without detection by the client.
Severity: 8.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70455 - rsync 3.4.2 < 3.5.0 DoS via --zt Zstandard Compression Thread Exhaustion

CVE ID :CVE-2026-70455
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers can specify --zt=N with a large value to spawn an unbounded number of Zstandard worker threads on the receiver, exhausting available thread and memory resources.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70456 - rsync 3.0.1 < 3.5.0 Heap Out-of-Bounds Write via read_args()

CVE ID :CVE-2026-70456
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the trailing NULL terminator is written one slot beyond the allocation boundary, corrupting adjacent heap memory.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70457 - rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()

CVE ID :CVE-2026-70457
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a .bss-segment array without bounds checking. When snprintf truncates the formatted size string, the return value equals the number of characters that would have been written including the truncated portion, and this value may exceed the array length. The subsequent indexed write targets memory outside the intended array bounds, corrupting .bss memory.
Severity: 8.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70458 - rsync 3.0.0 < 3.5.0 Out-of-Bounds Write via FLAG_HLINKED Handling

CVE ID :CVE-2026-70458
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the missing F_SUM field in the file_struct layout to access memory past the end of the allocated structure, corrupting adjacent heap or stack data.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70459 - rsync 3.0.0 < 3.5.0 Daemon Crash via Malformed File List Entry

CVE ID :CVE-2026-70459
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daemon by sending a file list whose first entry is a dot entry not typed as a directory. The daemon dereferences the first file list entry as a directory structure pointer without verifying the entry type, resulting in an invalid or uninitialized pointer dereference that terminates the client connection.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70460 - rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink

CVE ID :CVE-2026-70460
Published : Aug. 13, 2026, 3:19 p.m. | 21 minutes ago
Description :rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under the module root, or who can exploit a pre-existing trusted symlink, can direct file writes to locations outside the intended module root, achieving arbitrary file write relative to the module root parent.
Severity: 9.2 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70461 - rsync 3.2.5 < 3.5.0 Heap Out-of-Bounds Write via files-from Entry

CVE ID :CVE-2026-70461
Published : Aug. 13, 2026, 3:20 p.m. | 21 minutes ago
Description :rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability against a read-only rsync daemon module by providing a files-from entry containing both an interior and trailing backslash, causing the add_implied_include() function to under-count the trailing backslash when sizing the destination buffer.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70462 - rsync 3.1.0 < 3.5.0 Signed Integer Overflow via MSG_IO_TIMEOUT

CVE ID :CVE-2026-70462
Published : Aug. 13, 2026, 3:20 p.m. | 21 minutes ago
Description :rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disable connection timeouts by injecting MSG_IO_TIMEOUT messages carrying non-positive (zero or negative) values. Attackers can craft malicious MSG_IO_TIMEOUT messages that cause the timeout variable to wrap to a non-positive value, preventing the timeout check from firing and enabling idle or stalled connections to hold daemon slots indefinitely, leading to resource exhaustion.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70463 - rsync 3.1.0 < 3.5.0 Authorization Bypass via auth users Directive Parsing

CVE ID :CVE-2026-70463
Published : Aug. 13, 2026, 3:20 p.m. | 21 minutes ago
Description :rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The space within the group name causes the parser to split the entry at the space boundary, discarding the deny rule associated with the group. An authenticated user whose username or group membership would be denied by an @Group Name auth users entry can connect to a restricted module because the deny rule is silently discarded during parsing.
Severity: 8.6 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-70464 - rsync 2.0.0 < 3.5.0 Connection Slot Exhaustion DoS via Handshake Stall

CVE ID :CVE-2026-70464
Published : Aug. 13, 2026, 3:20 p.m. | 21 minutes ago
Description :rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open many simultaneous connections and trickle data at the minimum rate to avoid timeout, or stall entirely before module selection where no timeout applies, consuming all available connection slots and denying service to legitimate clients.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...