๐จ CVE-2026-73584
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.
๐@cveNotify
A flaw was found in sblim-sfcb. A local, low-privileged attacker can exploit a race condition during privileged instance migration by manipulating a temporary file in the `/tmp` directory. By repeatedly recreating a symbolic link, the attacker can redirect privileged output to an arbitrary file. This can lead to privileged file corruption or a denial of service (DoS) on the system.
๐@cveNotify
Redhat
CVE-2026-73584 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-73585
A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections.
๐@cveNotify
A flaw was found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to perform a symlink attack. By creating a symlink in a world-writable directory, an attacker can redirect privileged writes to an arbitrary file during script execution in a privileged context. This can lead to the overwrite of root-owned files, potentially disrupting system services or operation. Exploitation is conditional on the script running with elevated privileges and may be mitigated by sticky-directory symlink protections.
๐@cveNotify
Redhat
CVE-2026-73585 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2025-71393
SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass the recursion limit by chaining native and JavaScript function calls to trigger infinite recursion and exhaust server memory.
๐@cveNotify
SurrealDB before 2.2.2 with scripting enabled fails to properly enforce recursion limits when native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass the recursion limit by chaining native and JavaScript function calls to trigger infinite recursion and exhaust server memory.
๐@cveNotify
GitHub
Memory exhaustion via nested functions and scripts
In order to prevent DoS situations due to infinite recursions, SurrealDB implements a limit of nested calls for both native functions and embedded JavaScript functions.
However, in SurrealDB ins...
However, in SurrealDB ins...
๐จ CVE-2025-71394
SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system. Attackers with root, namespace, or database level privileges can point analyzers to arbitrary file paths and exfiltrate content from two-column tab-separated files.
๐@cveNotify
SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system. Attackers with root, namespace, or database level privileges can point analyzers to arbitrary file paths and exfiltrate content from two-column tab-separated files.
๐@cveNotify
GitHub
Local file read of 2-column TSV files via analyzers
An authenticated system user at the root, namespace, or database levels can use the `DEFINE ANALYZER` statement to point to arbitrary file locations on the file system, and should the file be tab s...
๐จ CVE-2025-71396
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting capability is explicitly enabled (via --allow-scripting or --allow-all). An authenticated attacker can submit long-running JavaScript functions to exhaust server resources and cause a denial of service. Scripting is disabled by default.
๐@cveNotify
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 does not enforce a default execution-time limit on embedded JavaScript scripting functions when the scripting capability is explicitly enabled (via --allow-scripting or --allow-all). An authenticated attacker can submit long-running JavaScript functions to exhaust server resources and cause a denial of service. Scripting is disabled by default.
๐@cveNotify
GitHub
No JavaScript script function default timeout could facilitate DoS
Through enabling the scripting capability. SurrealDB allows for advanced functions with complicated logic, by allowing embedded functions to be written in JavaScript.
These functions are bounded...
These functions are bounded...
๐จ CVE-2026-14973
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
๐@cveNotify
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
๐@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities in IBM Desktop App
Multiple vulnerabilities were addressed in IBM Aspera Desktop App v1.1.0.
๐จ CVE-2026-11980
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
๐@cveNotify
IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
๐@cveNotify
Ibm
Security Bulletin: Multiple vulnerabilities in IBM Desktop App
Multiple vulnerabilities were addressed in IBM Aspera Desktop App v1.1.0.
๐จ CVE-2026-61355
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-61356
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-61357
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Application Information Services allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-61358
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-61367
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Missing authentication for critical function in Windows Remote Desktop Services allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-61921
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
๐@cveNotify
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
๐@cveNotify
๐จ CVE-2026-61927
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-61934
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-70306
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
๐@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
๐@cveNotify
๐จ CVE-2026-70321
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
๐@cveNotify
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-70324
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-70326
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-70355
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-68968
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces to `1`); FastAPI resolves dependencies before endpoint validation, so the two acted on different Dags. An authenticated user holding edit permission on any single Dag could therefore read, pause and cancel backfills belonging to any other Dag, including moving another Dag's queued runs to `failed`. No non-default configuration is required and backfill ids are sequential, so finding a target is trivial. Users are advised to upgrade to apache-airflow 3.3.1 or later, which parses the backfill id with the same type the routes declare.
๐@cveNotify
Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts values `int()` rejects (`1.0` coerces to `1`); FastAPI resolves dependencies before endpoint validation, so the two acted on different Dags. An authenticated user holding edit permission on any single Dag could therefore read, pause and cancel backfills belonging to any other Dag, including moving another Dag's queued runs to `failed`. No non-default configuration is required and backfill ids are sequential, so finding a target is trivial. Users are advised to upgrade to apache-airflow 3.3.1 or later, which parses the backfill id with the same type the routes declare.
๐@cveNotify
GitHub
Resolve backfill_id in the access dependency with the type the routes declare by potiuk ยท Pull Request #70889 ยท apache/airflow
The backfill routes declare backfill_id: NonNegativeInt, but
requires_access_backfill parsed the raw path value with int() and swallowed
the failure. Those two parsers do not agree.
The divergence
...
requires_access_backfill parsed the raw path value with int() and swallowed
the failure. Those two parsers do not agree.
The divergence
...