๐จ CVE-2026-50362
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
๐@cveNotify
Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-50363
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-50365
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
๐@cveNotify
Improper authentication in Windows RPC API allows an unauthorized attacker to elevate privileges over an adjacent network.
๐@cveNotify
๐จ CVE-2026-50366
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
๐@cveNotify
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-50367
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Incorrect access of indexable resource ('range error') in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-50369
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-50370
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
๐@cveNotify
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
๐@cveNotify
๐จ CVE-2026-50371
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-50372
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Buffer over-read in Windows Redirected Drive Buffering allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-12161
Improper input validation in the SSH Elevate Shell feature allows an authenticated user
with permission to create or modify a shared SSH entry to execute
arbitrary commands on a remote SSH host using stored elevation
credentials via a crafted alternate username and user interaction with
the Elevate Shell action.
This affects :
- Remote Desktop Manager 2026.2.5.0 through 2026.2.7.0
- Remote Desktop Manager 2026.1.23.0 and earlier
๐@cveNotify
Improper input validation in the SSH Elevate Shell feature allows an authenticated user
with permission to create or modify a shared SSH entry to execute
arbitrary commands on a remote SSH host using stored elevation
credentials via a crafted alternate username and user interaction with
the Elevate Shell action.
This affects :
- Remote Desktop Manager 2026.2.5.0 through 2026.2.7.0
- Remote Desktop Manager 2026.1.23.0 and earlier
๐@cveNotify
Devolutions
advisories
DEVO-2026-0018: Remote Desktop Manager is affected by multiple vulnerabilities. Severity: Medium. Review the details and update to a fixed version.
๐จ CVE-2026-10649
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
๐@cveNotify
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
๐@cveNotify
๐จ CVE-2026-3602
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.
๐@cveNotify
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 is vulnerable to SQL injection. A remote attacker could socially engineer a user into accidentally creating files they may not be aware of.
๐@cveNotify
Ibm
Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection (CVE-2026โฆ
IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection.
๐จ CVE-2026-50335
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Improper access control in Windows Operating Systems allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-50336
Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Media allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-50347
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
๐@cveNotify
Heap-based buffer overflow in Windows Data dll allows an unauthorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-38753
A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
๐@cveNotify
A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
๐@cveNotify
๐จ CVE-2026-38752
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
๐@cveNotify
A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
๐@cveNotify
๐จ CVE-2026-38754
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
๐@cveNotify
A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
๐@cveNotify
๐จ CVE-2026-14971
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.
๐@cveNotify
IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions.
๐@cveNotify
Ibm
Security Bulletin: This PowerVM Novalink update is being released to address CVE-2026-14971
A vulnerability on PowerVM Novalink could allow an unintended or unauthorized operations under non-default conditions. PowerVM Novalink has addressed the applicable CVE.
๐จ CVE-2026-15069
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during web page generation.
๐@cveNotify
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to improper neutralization of input during web page generation.
๐@cveNotify
Ibm
Security Bulletin: Multiple Vulnerabilities in IBM Engineering AI hub.
Multiple vulnerabilities were addressed in IBM Engineering AI Hub version 1.3.0.
๐จ CVE-2026-45704
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php and bundles/CustomReportsBundle/src/Tool/Config/Listing/Dao.php, allowing a low-privileged backend user with the reports permission to directly request an unshared report such as poc-secret-report by name and read report name, grouping information, display and icon metadata, data source configuration, column configuration, and sharing settings even when shareGlobally is false. This issue is fixed in versions 11.5.17 (LTS) and 12.3.6.
๐@cveNotify
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses inconsistent authorization between the report listing endpoint and the report detail endpoint in bundles/CustomReportsBundle/src/Controller/Reports/CustomReportController.php and bundles/CustomReportsBundle/src/Tool/Config/Listing/Dao.php, allowing a low-privileged backend user with the reports permission to directly request an unshared report such as poc-secret-report by name and read report name, grouping information, display and icon metadata, data source configuration, column configuration, and sharing settings even when shareGlobally is false. This issue is fixed in versions 11.5.17 (LTS) and 12.3.6.
๐@cveNotify
GitHub
[Security] Enhance Custom Report controller actions (#19099) ยท pimcore/pimcore@1893ff1
* fix
* refactor
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* manual fix
* manual fix
---------
Co-authored-by: C...
* refactor
* Apply suggestions from code review
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
* manual fix
* manual fix
---------
Co-authored-by: C...