CVE Notify
19.7K subscribers
4 photos
303K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2026-20491
In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-20494
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-20495
In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-20496
In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-58062
In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18243
Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view print job previews.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18610
A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspx. The manipulation results in improper authentication. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-41453
Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and boolean-based blind injection techniques to extract the entire database contents, including user credential hashes, CRM records, and application configuration data.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-69153
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting mapโ€™s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2025-9291
A
certification validation weakness exists in communication between affected
Omada devices and cloud controllers. Certificate identity verification does not
adequately validate that a presented certificate corresponds to the expected
cloud controller hostname, which may allow certificate validation protections
to be bypassed under specific conditions.





Successful
exploitation may allow interception or modification of communication between
affected devices and cloud controllers.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-61523
WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is written verbatim to a publicly accessible PHP file with no content sanitization. Attackers can save a PHP webshell via the save_droplet handler to a predictable path inside the modules directory, enabling unauthenticated users to achieve remote code execution by making direct HTTP requests to the written file.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-61524
WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated administrators to achieve remote code execution by uploading a crafted ZIP archive containing a PHP webshell alongside a valid info.php metadata file. Attackers can place the malicious archive through the module installation interface, causing the application to extract the webshell into a web-accessible modules/ subdirectory where it becomes immediately executable by any unauthenticated user via direct HTTP request.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2025-15544
A cryptographic
weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated
with site management are transmitted using a weak hashing algorithm that does
not provide sufficient protection.









An attacker who
successfully intercepts adoption-related authentication traffic may be able to
recover valid credentials and gain unauthorized access to managed devices or
controller-managed environments.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2025-15627
A cryptographic
weakness exists in the Omada adoption protocol. 
The protocol relies on hard-coded cryptographic keys to establish trust and
protect authentication exchanges between controllers and managed devices during
device adoption.









An attacker may
be able to impersonate trusted controllers or managed devices and gain access
to sensitive adoption-related communications.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2025-15628
Affected
Omada devices rely on embedded certificates that are shared across deployments
to establish trust between controllers and managed devices.









An attacker
who obtains the embedded certificates may be able to impersonate trusted
controllers or devices and intercept affected communications.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2025-15629
A cryptographic
weakness exists in the Omada adoption protocol where session encryption keys
used to protect communications between controllers and managed devices may be
predictable due to insufficient entropy in session key generation.









An attacker
who successfully intercepts adoption-related communications may be able to recover
session encryption keys and decrypt affected communications.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2025-15630
A race
condition exists in the cloud-based Omada device adoption process when an
attacker may be able to interact with the adoption workflow before a legitimate
device completes registration, resulting in provisioning information being
delivered to an attacker.









Successful
exploitation may allow disclosure of provisioning information intended for a
legitimate device.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2025-15631
A
cryptographic weakness exists in affected Omada devices where site credentials
are protected using a legacy hashing algorithm that does not provide sufficient
protection.









An attacker
who obtains access to stored credential data may be able to recover valid credentials
to gain unauthorized access to affected devices or management environments.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18614
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18616
A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-38444
osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name.

๐ŸŽ–@cveNotify