🚨 CVE-2026-48399
Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
🎖@cveNotify
Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction.
🎖@cveNotify
Adobe
Adobe Security Bulletin
Security updates available for Adobe Campaign Classic | APSB26-120
🚨 CVE-2026-10709
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
🎖@cveNotify
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
🎖@cveNotify
Autodesk
Autodesk Access | Formerly Autodesk Desktop App | Autodesk
Autodesk Access simplifies the update experience. Quickly and easily install updates for your desktop products from the app. Download now for free.
🚨 CVE-2026-10710
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
🎖@cveNotify
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
🎖@cveNotify
Autodesk
Autodesk Access | Formerly Autodesk Desktop App | Autodesk
Autodesk Access simplifies the update experience. Quickly and easily install updates for your desktop products from the app. Download now for free.
🚨 CVE-2026-18806
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality.
This issue affects pardus-image-writer: before 1.0.4.
🎖@cveNotify
External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality.
This issue affects pardus-image-writer: before 1.0.4.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-18650
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation.
This issue affects Liman MYS: from 2.2.3 before 2.3.1.
🎖@cveNotify
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation.
This issue affects Liman MYS: from 2.2.3 before 2.3.1.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-61514
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary control protocol header to access live video streams, control pan and tilt motors, activate audio functions, and remotely restart the device.
🎖@cveNotify
Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the unvalidated Session field in the proprietary control protocol header to access live video streams, control pan and tilt motors, activate audio functions, and remotely restart the device.
🎖@cveNotify
🚨 CVE-2026-67198
Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or MakeTableReq with no data field to trigger unwrap() calls on None values at nine distinct sites, causing the process to abort with SIGABRT.
🎖@cveNotify
Perspective 5.0.0 contains a denial-of-service vulnerability in the VirtualServer protocol dispatcher that allows unauthenticated remote attackers to crash the server process by sending malformed or incomplete protobuf messages. Attackers can send well-formed requests such as ViewToArrowReq with no viewport set or MakeTableReq with no data field to trigger unwrap() calls on None values at nine distinct sites, causing the process to abort with SIGABRT.
🎖@cveNotify
Christbowel
From One Row of Data to a Root Shell: Five CVEs in Perspective 5.0.0 | Security Research
Offensive Security Researcher — CVE author & bug hunter.
🚨 CVE-2026-18773
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A vulnerability was detected in NousResearch hermes-agent up to 2026.6.5. Affected by this issue is the function _check_slash_access of the file gateway/run.py of the component Quick Command Handler. The manipulation results in incorrect authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
Gist
hermes-agent: Hermes gateway quick commands bypass admin-only slash command restrictions
hermes-agent: Hermes gateway quick commands bypass admin-only slash command restrictions - hermes-agent-Hermes-gateway-quick-commands-bypass-admin-only-slash-command-restrictions.md
🚨 CVE-2026-21366
Memory corruption while processing a packet with a size close to the maximum allowed value.
🎖@cveNotify
Memory corruption while processing a packet with a size close to the maximum allowed value.
🎖@cveNotify
🚨 CVE-2026-24076
Memory Corruption when processing registry values with incorrect types using a direct query method.
🎖@cveNotify
Memory Corruption when processing registry values with incorrect types using a direct query method.
🎖@cveNotify
🚨 CVE-2026-24077
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
🎖@cveNotify
Information Disclosure when processing wireless network channel switch information with improperly formatted length fields.
🎖@cveNotify
🚨 CVE-2026-24078
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
🎖@cveNotify
Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.
🎖@cveNotify
🚨 CVE-2026-24079
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
🎖@cveNotify
Cryptographic Issue while processing registration requests with malformed or missing authentication parameters.
🎖@cveNotify
🚨 CVE-2026-24080
Memory Corruption when handling malformed request parameters in the fingerprint TA.
🎖@cveNotify
Memory Corruption when handling malformed request parameters in the fingerprint TA.
🎖@cveNotify
🚨 CVE-2026-24083
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
🎖@cveNotify
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
🎖@cveNotify
🚨 CVE-2026-24084
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
🎖@cveNotify
Weak configuration when UE does not verify the consistency of its additional security capabilities with the replayed capabilities.
🎖@cveNotify
🚨 CVE-2026-25288
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
🎖@cveNotify
Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.
🎖@cveNotify
🚨 CVE-2026-25289
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
🎖@cveNotify
Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.
🎖@cveNotify
🚨 CVE-2026-25292
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
🎖@cveNotify
Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.
🎖@cveNotify
🚨 CVE-2026-69100
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend server.
🎖@cveNotify
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend server.
🎖@cveNotify
GitHub
fix: lamp-cloud 模板 Groovy 脚本执行导致远程代码执行漏洞 · dromara/lamp-cloud@84b0c27
close: 408
🚨 CVE-2026-69110
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionally delete any video by ID through the unauthenticated DELETE /api/short-video/:videoId endpoint.
🎖@cveNotify
OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints. Attackers can retrieve intermediate audio, video artifacts, and subtitles belonging to other users' jobs, and additionally delete any video by ID through the unauthenticated DELETE /api/short-video/:videoId endpoint.
🎖@cveNotify
GitHub
Fix path traversal in profile operations (#55) · Microck/opencode-studio@1f4d7a7
Reject profile names containing path separators or traversal sequences to prevent arbitrary filesystem delete/create/symlink. Binds server to 127.0.0.1.
Fixes #54
Fixes #54