🚨 CVE-2026-54992
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.
🎖@cveNotify
Heap-based buffer overflow in Windows Message Queuing Queue Manager allows an unauthorized attacker to execute code locally.
🎖@cveNotify
🚨 CVE-2026-54993
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
🎖@cveNotify
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code locally.
🎖@cveNotify
🚨 CVE-2026-50362
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
🎖@cveNotify
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
🎖@cveNotify
🚨 CVE-2026-50363
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-50365
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
🎖@cveNotify
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
🎖@cveNotify
🚨 CVE-2026-50366
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
🎖@cveNotify
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
🎖@cveNotify
🚨 CVE-2026-50367
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-50369
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
🎖@cveNotify
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
🎖@cveNotify
🚨 CVE-2026-50370
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
🎖@cveNotify
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
🎖@cveNotify
🚨 CVE-2026-50371
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-50372
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-12161
Improper input validation in the SSH Elevate Shell feature allows an authenticated user
with permission to create or modify a shared SSH entry to execute
arbitrary commands on a remote SSH host using stored elevation
credentials via a crafted alternate username and user interaction with
the Elevate Shell action.
This affects :
- Remote Desktop Manager 2026.2.5.0 through 2026.2.7.0
- Remote Desktop Manager 2026.1.23.0 and earlier
🎖@cveNotify
Improper input validation in the SSH Elevate Shell feature allows an authenticated user
with permission to create or modify a shared SSH entry to execute
arbitrary commands on a remote SSH host using stored elevation
credentials via a crafted alternate username and user interaction with
the Elevate Shell action.
This affects :
- Remote Desktop Manager 2026.2.5.0 through 2026.2.7.0
- Remote Desktop Manager 2026.1.23.0 and earlier
🎖@cveNotify
Devolutions
advisories
DEVO-2026-0018: Remote Desktop Manager is affected by multiple vulnerabilities. Severity: Medium. Review the details and update to a fixed version.
🚨 CVE-2026-10649
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
🎖@cveNotify
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
🎖@cveNotify
🚨 CVE-2026-3602
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.
🎖@cveNotify
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.
🎖@cveNotify
Ibm
Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection (CVE-2026…
IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection.
🚨 CVE-2026-50335
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-50336
Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-50347
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
🎖@cveNotify
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
🎖@cveNotify
🚨 CVE-2026-38753
A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
🎖@cveNotify
A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
🎖@cveNotify
🚨 CVE-2026-38752
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
🎖@cveNotify
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
🎖@cveNotify
🚨 CVE-2026-38754
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
🎖@cveNotify
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
🎖@cveNotify
🚨 CVE-2026-14971
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.
🎖@cveNotify
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.
🎖@cveNotify
Ibm
Security Bulletin: This PowerVM Novalink update is being released to address CVE-2026-14971
A vulnerability on PowerVM Novalink could allow an unintended or unauthorized operations under non-default conditions. PowerVM Novalink has addressed the applicable CVE.