๐จ CVE-2026-63453
Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.
๐@cveNotify
Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.
๐@cveNotify
๐จ CVE-2026-63454
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
๐@cveNotify
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
๐@cveNotify
๐จ CVE-2026-64877
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
๐@cveNotify
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
๐@cveNotify
Tenableยฎ
[R1] Stand-alone Security Patch Available for Tenable Security Center Versions 6.6.0, 6.7.2 and 6.8.0: SC202607.1
Security Center leverages third-party software to help provide underlying functionality. Several of the third-party components (apache, OpenSSL, postgreSQL, PHP, redis) were found to contain vulnerabilities, and updated versions have been made available byโฆ
๐จ CVE-2026-50682
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
๐@cveNotify
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-50683
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
๐@cveNotify
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
๐@cveNotify
๐จ CVE-2026-50684
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
๐@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
๐@cveNotify
๐จ CVE-2026-50685
Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
๐@cveNotify
Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-50686
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-50689
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-50690
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
๐@cveNotify
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-50692
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-54115
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-54121
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-54124
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
๐@cveNotify
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-54125
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-54126
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
๐@cveNotify
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
๐@cveNotify
๐จ CVE-2026-54128
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
๐@cveNotify
Use after free in Windows DHCP Client allows an unauthorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-56159
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-56168
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
๐@cveNotify
Null pointer dereference in Windows SMB Server allows an authorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-56173
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-47423
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5.
๐@cveNotify
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside <selectedcontent> is returned. This issue is fixed in version 3.4.5.
๐@cveNotify
GitHub
release: 3.4.5 (#1382) ยท cure53/DOMPurify@011b0c7
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: - release: 3.4.5 (#1382) ยท cure53/DOMPurify@011b0c7