๐จ CVE-2026-0291
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prismaยฎ Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent.
The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.
๐@cveNotify
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prismaยฎ Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent.
The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome OS is not affected.
๐@cveNotify
Palo Alto Networks Product Security Assurance
CVE-2026-0291 Prisma Access Agent: Authenticated Limited File Deletion on Linux
An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prismaยฎ Access Agent on Linux platforms that enables a local low privileged user to delete system files in...
๐จ CVE-2026-0292
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prismaยฎ Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic.
The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
๐@cveNotify
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prismaยฎ Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic.
The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
๐@cveNotify
Palo Alto Networks Product Security Assurance
CVE-2026-0292 Prisma Access Agent: Local Security Inspection Bypass Vulnerability on Windows
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prismaยฎ Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing th...
๐จ CVE-2026-0293
A vulnerability in Palo Alto Networks Prismaยฎ Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files.
The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
๐@cveNotify
A vulnerability in Palo Alto Networks Prismaยฎ Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files.
The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
๐@cveNotify
Palo Alto Networks Product Security Assurance
CVE-2026-0293 Prisma Access Agent: Anti-Tamper Protection Bypass on Windows
A vulnerability in Palo Alto Networks Prismaยฎ Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to prote...
๐จ CVE-2026-0294
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prismaยฎ Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges.
The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.
๐@cveNotify
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prismaยฎ Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges.
The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.
๐@cveNotify
Palo Alto Networks Product Security Assurance
CVE-2026-0294 Prisma Access Agent: Local Privilege Escalation
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prismaยฎ Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges.
The Prisma Acc...
The Prisma Acc...
๐จ CVE-2026-0295
A race condition in the Palo Alto Networks GlobalProtectโข client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
๐@cveNotify
A race condition in the Palo Alto Networks GlobalProtectโข client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected.
๐@cveNotify
Palo Alto Networks Product Security Assurance
CVE-2026-0295 GlobalProtect App: Local Privilege Escalation via Race Condition on macOS
A race condition in the Palo Alto Networks GlobalProtectโข client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root.
The GlobalProtect app on Linux,...
The GlobalProtect app on Linux,...
๐จ CVE-2026-0296
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtectโข app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
๐@cveNotify
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtectโข app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
๐@cveNotify
Palo Alto Networks Product Security Assurance
CVE-2026-0296 GlobalProtect App: Improper Certificate Validation Bypass Vulnerability
Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtectโข app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application c...
๐จ CVE-2026-0297
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtectโข app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).
๐@cveNotify
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtectโข app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux).
๐@cveNotify
Palo Alto Networks Product Security Assurance
CVE-2026-0297 GlobalProtect App: Buffer Overflow Vulnerability during UDP Tunnel Handshake
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtectโข app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially exec...
๐จ CVE-2026-0298
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtectโข app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
๐@cveNotify
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtectโข app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client.
The GlobalProtect app on Linux, macOS, iOS, Android, and Chrome OS is not affected.
๐@cveNotify
Palo Alto Networks Product Security Assurance
CVE-2026-0298 GlobalProtect App: Code Execution Vulnerability in Windows Pre-Logon Access Provider (PLAP)
An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtectโข app on Windows devices which enables a man-in-the-m...
๐จ CVE-2026-0299
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtectโข app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
๐@cveNotify
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtectโข app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges.
The GlobalProtect app on iOS, Android, and Chrome OS is not affected.
๐@cveNotify
Palo Alto Networks Product Security Assurance
CVE-2026-0299 GlobalProtect App: Local Privilege Escalation Vulnerabilities
Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtectโข app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux....
๐จ CVE-2026-0301
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OSยฎ software enables an unauthenticated user with network access to obtain sensitive information.
Panorama is not impacted by this vulnerability.
๐@cveNotify
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OSยฎ software enables an unauthenticated user with network access to obtain sensitive information.
Panorama is not impacted by this vulnerability.
๐@cveNotify
Palo Alto Networks Product Security Assurance
CVE-2026-0301 PAN-OS: Information Disclosure Vulnerability in URL Filtering
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OSยฎ software enables an unauthenticated user with network access to obtain sensitive information.
Panora...
Panora...
๐จ CVE-2026-3835
The Prevent Direct Access โ Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb->esc_like()`. This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin's file table and downloading any protected file.
๐@cveNotify
The Prevent Direct Access โ Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without escaping wildcard characters via `$wpdb->esc_like()`. This makes it possible for unauthenticated attackers to bypass the private token requirement by supplying SQL wildcard characters (such as `%`) as the token value, matching any record in the plugin's file table and downloading any protected file.
๐@cveNotify
๐จ CVE-2026-6470
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
๐@cveNotify
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
๐@cveNotify
๐จ CVE-2026-73583
A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure.
๐@cveNotify
A flaw was found in sblim-sfcb. A local attacker with access to the system can exploit an unsafe deserialization vulnerability in the provider-manager's inter-process communication (IPC) message parsing. By sending a specially crafted message, the attacker can cause out-of-bounds memory access, leading to the termination of the provider-manager process and a denial of service. This could also potentially result in limited unintended information disclosure.
๐@cveNotify
Redhat
CVE-2026-73583 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2025-62314
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
HCL AION is affected by a vulnerability where certain endpoints lack sufficient anti-automation controls. Automated or scripted requests may be submitted without adequate rate limiting or challenge mechanisms, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL AION - Customer Support
HCL AION is affected by multiple security vulnerabilities.
๐จ CVE-2025-62315
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
HCL AION is affected by a vulnerability where certain input fields do not enforce sufficient server-side input validation. Unexpected or crafted input may be accepted by the application, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL AION - Customer Support
HCL AION is affected by multiple security vulnerabilities.
๐จ CVE-2025-62318
HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.
๐@cveNotify
HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages, potentially allowing sensitive information to be captured by an attacker-controlled page (JavaScript hijacking) under certain conditions.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL AION - Customer Support
HCL AION is affected by multiple security vulnerabilities.
๐จ CVE-2026-19716
Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account.
๐@cveNotify
Stored Cross-site Scripting (CWE-79) in the user management component in maalfer Pentestify before 1.1.1 allows an authenticated attacker to execute arbitrary JavaScript in the browser of another authenticated user via a crafted username, because the frontend escapes the username with escapeHTML() before interpolating it into the onclick attribute of the account deletion button, but the browser HTML-decodes attribute values before the JavaScript engine parses the handler, allowing an encoded single quote (') to break out of the string literal and inject arbitrary JavaScript that executes when the victim clicks the delete button for that account.
๐@cveNotify
GitHub
fix: patch username XSS and multipart DoS CVEs (v1.1.1) ยท ccyl13/Pentestify@714e05e
Username field was reflected into an inline onclick handler. escapeHTML()
protects HTML text context, but the browser HTML-decodes attribute values
before the JS engine runs them, so '...
protects HTML text context, but the browser HTML-decodes attribute values
before the JS engine runs them, so '...
๐จ CVE-2026-21832
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple security vulnerabilities affect HCL AION - Customer Support
HCL AION is affected by multiple security vulnerabilities.
๐จ CVE-2026-27345
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
๐@cveNotify
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Taxi Booking Manager for WooCommerce Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-27535
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
๐@cveNotify
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
๐@cveNotify
Patchstack
Broken Access Control in WordPress Solace Extra Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.
๐จ CVE-2026-27536
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
๐@cveNotify
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
๐@cveNotify
Patchstack
Cross Site Scripting (XSS) in WordPress MailChimp Subscribe Forms Plugin
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress, Drupal and Joomla security issues.