CVE Notify
19.7K subscribers
4 photos
301K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2026-0291
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prismaยฎ Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent.

The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-0292
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prismaยฎ Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic.

The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-0293
A vulnerability in Palo Alto Networks Prismaยฎ Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files.

The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-0294
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prismaยฎ Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges.

The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-0295
A race condition in the Palo Alto Networks GlobalProtectโ„ข client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.

The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-0296
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtectโ„ข app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.

The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-0297
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtectโ„ข app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-0298
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtectโ„ข app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.

The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-0299
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtectโ„ข app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.

The GlobalProtect app on iOS, Android, and Chrome OS is not affected.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-0301
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OSยฎ software enables an unauthenticated user with network access to obtain sensitive information.

Panorama is not impacted by this vulnerability.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-3835
The Prevent Direct Access โ€“ Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb->esc_like()`. This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin's file table and downloading any protected file.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-6470
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-73583
A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2025-62314
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2025-62315
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2025-62318
HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-19716
Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21832
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.

๐ŸŽ–@cveNotify