CVE tracker
385 subscribers
5.43K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-73746 - Authenticated Denial of Service Vulnerability in HPE Networking Fabric Composer API

CVE ID :CVE-2026-73746
Published : Sept. 1, 2026, 7:47 p.m. | 21 minutes ago
Description :A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated low privilege operator user to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73747 - Local Privilege Escalation Vulnerability in HPE Networking Fabric Composer

CVE ID :CVE-2026-73747
Published : Sept. 1, 2026, 7:47 p.m. | 21 minutes ago
Description :A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user with local access to elevate their user privileges and make limited modifications on the affected system.
Severity: 2.5 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-73748 - Authenticated Sensitive Information Disclosure in HPE Networking Fabric Composer

CVE ID :CVE-2026-73748
Published : Sept. 1, 2026, 7:47 p.m. | 21 minutes ago
Description :A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privileges to access sensitive information in a cleartext format. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Fabric Composer.
Severity: 2.2 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76657 - Authentication Bypass in HPE Networking Fabric Composer API allows Administrative Access

CVE ID :CVE-2026-76657
Published : Sept. 1, 2026, 7:47 p.m. | 21 minutes ago
Description :Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-76658 - Unauthenticated Remote Code Execution in HPE Networking Fabric Composer SSH Daemon

CVE ID :CVE-2026-76658
Published : Sept. 1, 2026, 7:47 p.m. | 21 minutes ago
Description :A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84352 - Google Chrome WebGL Use-After-Free Vulnerability

CVE ID :CVE-2026-84352
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84354 - Google Chrome FileSystem Incorrect Authorization Arbitrary Code Execution

CVE ID :CVE-2026-84354
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84359 - Google Chrome Skia Cross-Origin Information Disclosure

CVE ID :CVE-2026-84359
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84357 - Google Chrome Omnibox Improper Input Validation

CVE ID :CVE-2026-84357
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84324 - Google Chrome Proxy Use-After-Free Vulnerability

CVE ID :CVE-2026-84324
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84349 - Google Chrome Use-After-Free Vulnerability

CVE ID :CVE-2026-84349
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84326 - Google Chrome V8 Uninitialized Resource Vulnerability

CVE ID :CVE-2026-84326
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84333 - Google Chrome Dawn Use-After-Free Vulnerability

CVE ID :CVE-2026-84333
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84351 - Google Chrome GPU Buffer Overflow

CVE ID :CVE-2026-84351
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84325 - Google Chrome DataTransfer Improper Input Validation

CVE ID :CVE-2026-84325
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84328 - Google Chrome FileSystem Authorization Bypass

CVE ID :CVE-2026-84328
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84347 - Google Chrome WebRTC Use-After-Free Vulnerability

CVE ID :CVE-2026-84347
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84323 - Google Chrome FileSystem Missing Authorization Vulnerability

CVE ID :CVE-2026-84323
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84355 - Google Chrome Navigation Incorrect Authorization

CVE ID :CVE-2026-84355
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84358 - Google Chrome Downloads Improper Privilege Management Address Bar Spoofing

CVE ID :CVE-2026-84358
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-84332 - Google Chrome SiteSettings Authorization Bypass

CVE ID :CVE-2026-84332
Published : Sept. 1, 2026, 11:42 p.m. | 27 minutes ago
Description :Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...