π¨ CVE-2026-64813
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
π@cveNotify
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
π@cveNotify
JetBrains
Fixed security issues
This page contains information about resolved security issues, including description, severity, assigned CVEs, and the product versions in which they were resolved.
π¨ CVE-2026-64815
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
π@cveNotify
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
π@cveNotify
JetBrains
Fixed security issues
This page contains information about resolved security issues, including description, severity, assigned CVEs, and the product versions in which they were resolved.
π¨ CVE-2026-65906
In JetBrains TeamCity before 2026.1.2, 2025.11.6 Ρode execution via Kotlin DSL sandbox escape was possible
π@cveNotify
In JetBrains TeamCity before 2026.1.2, 2025.11.6 Ρode execution via Kotlin DSL sandbox escape was possible
π@cveNotify
JetBrains
Fixed security issues
This page contains information about resolved security issues, including description, severity, assigned CVEs, and the product versions in which they were resolved.
π¨ CVE-2026-65907
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
π@cveNotify
In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
π@cveNotify
JetBrains
Fixed security issues
This page contains information about resolved security issues, including description, severity, assigned CVEs, and the product versions in which they were resolved.
π¨ CVE-2026-65908
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
π@cveNotify
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
π@cveNotify
JetBrains
Fixed security issues
This page contains information about resolved security issues, including description, severity, assigned CVEs, and the product versions in which they were resolved.
π¨ CVE-2026-47668
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.
π@cveNotify
DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.
π@cveNotify
GitHub
Release v7.1.9 Β· dbgate/dbgate
7.1.9
FIXED: writeQueryHistory function error #1432
FIXED: UUID parsing issues #1434, #1431
ADDED: Validation for function and file names, fixed security issues
CHANGED: Public DbGate cloud migrat...
FIXED: writeQueryHistory function error #1432
FIXED: UUID parsing issues #1434, #1431
ADDED: Validation for function and file names, fixed security issues
CHANGED: Public DbGate cloud migrat...
π¨ CVE-2026-6516
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
π@cveNotify
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
π@cveNotify
Manageengine
Unauthenticated Remote Code Execution Vulnerability (CVE-2026-6516) fixed in build 8606 | ManageEngine ADAudit Plus
An unauthenticated remote code execution vulnerability (CVE-2026-6516) has been fixed in ADAudit Plus build 8606.
π¨ CVE-2026-47669
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes files anywhere on the filesystem. In the default Docker deployment, DbGate runs as root and the `none` auth provider issues JWT tokens without credentials via `POST /auth/login`, so this is exploitable by any network-adjacent attacker. Version 7.1.9 fixes the issue.
π@cveNotify
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes files anywhere on the filesystem. In the default Docker deployment, DbGate runs as root and the `none` auth provider issues JWT tokens without credentials via `POST /auth/login`, so this is exploitable by any network-adjacent attacker. Version 7.1.9 fixes the issue.
π@cveNotify
GitHub
Release v7.1.9 Β· dbgate/dbgate
7.1.9
FIXED: writeQueryHistory function error #1432
FIXED: UUID parsing issues #1434, #1431
ADDED: Validation for function and file names, fixed security issues
CHANGED: Public DbGate cloud migrat...
FIXED: writeQueryHistory function error #1432
FIXED: UUID parsing issues #1434, #1431
ADDED: Validation for function and file names, fixed security issues
CHANGED: Public DbGate cloud migrat...
π¨ CVE-2026-47670
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.
π@cveNotify
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.
π@cveNotify
GitHub
Release v7.1.9 Β· dbgate/dbgate
7.1.9
FIXED: writeQueryHistory function error #1432
FIXED: UUID parsing issues #1434, #1431
ADDED: Validation for function and file names, fixed security issues
CHANGED: Public DbGate cloud migrat...
FIXED: writeQueryHistory function error #1432
FIXED: UUID parsing issues #1434, #1431
ADDED: Validation for function and file names, fixed security issues
CHANGED: Public DbGate cloud migrat...
π¨ CVE-2026-65703
FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution.
π@cveNotify
FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution.
π@cveNotify
FFmpeg Forgejo
avcodec/tdsc: unref the reference frame before reallocating on size change Β· fd3ee52fab
Fixes: out of array access
Fixes: tdsc_poc/ffmpeg-tdsc-linesize-report/poc.avi / gen_poc.py
Fixes: tdsc_resize_jpeg_oob.avi / tdsc-resize-stale-linesize-jpeg-oob-generate-poc.py
Fixes: p9xG4xGf9P7H
Fixes: HQL7a1WgTdHZ
Found-by: Cloud-LHY / Clouditera Securityβ¦
Fixes: tdsc_poc/ffmpeg-tdsc-linesize-report/poc.avi / gen_poc.py
Fixes: tdsc_resize_jpeg_oob.avi / tdsc-resize-stale-linesize-jpeg-oob-generate-poc.py
Fixes: p9xG4xGf9P7H
Fixes: HQL7a1WgTdHZ
Found-by: Cloud-LHY / Clouditera Securityβ¦
π¨ CVE-2026-65704
FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer.
π@cveNotify
FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer.
π@cveNotify
FFmpeg Forgejo
avformat/ty: don't let the Series2 AC3 trim underflow the packet size Β· de771bd527
Fixes: negative-size-param
Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py
Fixes: g0qeE6KvrjZi
Found-by: Adrian Junge (vurlo)
Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py
Fixes: g0qeE6KvrjZi
Found-by: Adrian Junge (vurlo)
π¨ CVE-2026-65705
FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening.
π@cveNotify
FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening.
π@cveNotify
FFmpeg Forgejo
avfilter/vf_floodfill: remove unneeded variables Β· f186c50cf5
Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
π¨ CVE-2026-65706
FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution.
π@cveNotify
FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte memcpy into a 17-byte heap allocation when processing the two-byte-per-sample interleaved chroma plane of a 17x16 NV12 frame, resulting in heap corruption and process crash with potential for code execution.
π@cveNotify
FFmpeg Forgejo
avfilter/vf_swaprect: size the temp row buffer for the widest plane Β· a7e38b617b
Fixes: out of array access
Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py
Fixes: VRAXYvKtmKa8
Found-by: Adrian Junge (vurlo) <adjun37@gmail.com>
Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py
Fixes: VRAXYvKtmKa8
Found-by: Adrian Junge (vurlo) <adjun37@gmail.com>
π¨ CVE-2026-54422
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
π@cveNotify
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
π@cveNotify
Launchpad
Bug #2155826 β[OSSA-2026-028] Ironic bootc deploy exposes operat...β : Bugs : Ironic
== Summary ==
In the Ironic bootc deployment path, Ironic forwards image authentication
material as oci_pull_secret to ironic-python-agent (IPA). IPA writes that secret
to /root/.config/containers/auth.json, then runs the tenant-selected bootc image
withβ¦
In the Ironic bootc deployment path, Ironic forwards image authentication
material as oci_pull_secret to ironic-python-agent (IPA). IPA writes that secret
to /root/.config/containers/auth.json, then runs the tenant-selected bootc image
withβ¦
π¨ CVE-2026-66138
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
π@cveNotify
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
π@cveNotify
Launchpad
Bug #2160050 β[OSSA-2026-027] Arbitrary command execution throug...β : Bugs : ironic-python-agent
--
[Tuomo Tanskanen (Ericsson Software Technology) and Dmitry Tantsur (Red Hat) from the Metal3.io security team have discovered a potential issue in Ironic using an AI-based security analysis tool. Here is the summary and the review by the submitter.]
β¦
[Tuomo Tanskanen (Ericsson Software Technology) and Dmitry Tantsur (Red Hat) from the Metal3.io security team have discovered a potential issue in Ironic using an AI-based security analysis tool. Here is the summary and the review by the submitter.]
β¦
π¨ CVE-2026-66139
OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
π@cveNotify
OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
π@cveNotify
Launchpad
Bug #2161254 β[OSSA-2026-029] Zaqar EXTRA-SPEC Header Bypasses K...β : Bugs : OpenStack Security Advisory
An unauthenticated network client can add "EXTRA-SPEC" to a Zaqar v2 request and avoid the Keystone authentication middleware. In the packaged configuration tested, the "messagecode" extra-spec handler performs no validation. The unauthenticated client canβ¦
π¨ CVE-2026-66140
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
π@cveNotify
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
π@cveNotify
π¨ CVE-2026-66141
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
π@cveNotify
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
π@cveNotify
π¨ CVE-2026-54422
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
π@cveNotify
In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.
π@cveNotify
Launchpad
Bug #2155826 β[OSSA-2026-028] Ironic bootc deploy exposes operat...β : Bugs : Ironic
== Summary ==
In the Ironic bootc deployment path, Ironic forwards image authentication
material as oci_pull_secret to ironic-python-agent (IPA). IPA writes that secret
to /root/.config/containers/auth.json, then runs the tenant-selected bootc image
withβ¦
In the Ironic bootc deployment path, Ironic forwards image authentication
material as oci_pull_secret to ironic-python-agent (IPA). IPA writes that secret
to /root/.config/containers/auth.json, then runs the tenant-selected bootc image
withβ¦
π¨ CVE-2026-16870
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim process later downloads, and impact would be limited to deployments where principals with different privilege levels share the same internal stage. A related out-of-bounds write in the same download path could allow memory corruption with attacker-controlled write primitives. An attacker may exploit this through a crafted initialization vector metadata field on a shared stage, and impact would be limited by the same stage-write precondition. Improper validation of connection parameters could allow an attacker-controlled input to redirect outbound authentication requests β including credentials and tokens β to an attacker-controlled endpoint. Impact is limited to embedding deployments where a lower-privileged principal can influence connection configuration while higher-privileged service credentials are in use. The fix is available in Snowflake libsnowflakeclient version 2.9.2. Users must manually upgrade.
π@cveNotify
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim process later downloads, and impact would be limited to deployments where principals with different privilege levels share the same internal stage. A related out-of-bounds write in the same download path could allow memory corruption with attacker-controlled write primitives. An attacker may exploit this through a crafted initialization vector metadata field on a shared stage, and impact would be limited by the same stage-write precondition. Improper validation of connection parameters could allow an attacker-controlled input to redirect outbound authentication requests β including credentials and tokens β to an attacker-controlled endpoint. Impact is limited to embedding deployments where a lower-privileged principal can influence connection configuration while higher-privileged service credentials are in use. The fix is available in Snowflake libsnowflakeclient version 2.9.2. Users must manually upgrade.
π@cveNotify
GitHub
Release Internal Release Β· snowflakedb/libsnowflakeclient
New features:
Added TOML connection configuration support (#1017)
Made the WIF attestation audience configurable β SNOW-3684659 (#1021)
Updated OpenSSL to 3.5.7 β SNOW-3121512 (#995)
Bug fixes:
...
Added TOML connection configuration support (#1017)
Made the WIF attestation audience configurable β SNOW-3684659 (#1021)
Updated OpenSSL to 3.5.7 β SNOW-3121512 (#995)
Bug fixes:
...
π¨ CVE-2026-8220
A vulnerability was detected in Devs Palace ERP Online up to 4.0.0. This affects an unknown function of the file /inventory/customer-save. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability was detected in Devs Palace ERP Online up to 4.0.0. This affects an unknown function of the file /inventory/customer-save. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify