CVE Notify
19.6K subscribers
4 photos
312K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-15556
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.

🎖@cveNotify
🚨 CVE-2026-15560
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.

🎖@cveNotify
🚨 CVE-2026-15561
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

🎖@cveNotify
🚨 CVE-2026-15562
A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.

🎖@cveNotify
🚨 CVE-2026-15563
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

🎖@cveNotify
🚨 CVE-2026-59131
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-59138
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.

🎖@cveNotify
🚨 CVE-2026-61928
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.

🎖@cveNotify
🚨 CVE-2026-62702
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.

🎖@cveNotify
🚨 CVE-2026-62709
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-62714
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.

🎖@cveNotify
🚨 CVE-2026-62730
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-62775
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-62798
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-62837
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-62887
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-62893
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-62900
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-62915
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

🎖@cveNotify
🚨 CVE-2026-63531
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-64899
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

🎖@cveNotify