🚨 CVE-2026-15561
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.
🎖@cveNotify
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.
🎖@cveNotify
🚨 CVE-2026-15562
A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.
🎖@cveNotify
A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.
🎖@cveNotify
🚨 CVE-2026-15563
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
🎖@cveNotify
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.
🎖@cveNotify
🚨 CVE-2026-59131
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
🎖@cveNotify
No cwe for this issue in AMD Zen allows an authorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2026-59138
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
🎖@cveNotify
Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a network.
🎖@cveNotify
🚨 CVE-2026-61928
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
🎖@cveNotify
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
🎖@cveNotify
🚨 CVE-2026-62702
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
🎖@cveNotify
Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.
🎖@cveNotify
🚨 CVE-2026-62709
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
🎖@cveNotify
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2026-62714
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
🎖@cveNotify
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
🎖@cveNotify
🚨 CVE-2026-62730
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
🎖@cveNotify
Buffer over-read in Windows Wired AutoConfig Service allows an authorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2026-62775
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
🎖@cveNotify
Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2026-62798
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
🎖@cveNotify
Untrusted pointer dereference in Windows Win32K allows an authorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2026-62837
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-62887
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
🎖@cveNotify
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2026-62893
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
🎖@cveNotify
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
🎖@cveNotify
🚨 CVE-2026-62900
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-62915
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
🎖@cveNotify
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
🎖@cveNotify
🚨 CVE-2026-63531
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
🎖@cveNotify
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2026-64899
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
🎖@cveNotify
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2026-65660
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
🎖@cveNotify
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
🎖@cveNotify
🚨 CVE-2026-65769
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify