๐จ CVE-2026-13601
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
๐@cveNotify
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
๐@cveNotify
๐จ CVE-2026-12912
A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).
๐@cveNotify
A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).
๐@cveNotify
๐จ CVE-2026-58641
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
๐@cveNotify
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-63524
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-63529
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-63531
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-64906
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
๐@cveNotify
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-65768
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-65810
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
๐@cveNotify
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69278
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
๐@cveNotify
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
๐@cveNotify
๐จ CVE-2026-69320
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-70312
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-70313
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-70322
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-70336
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-70345
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-70346
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-70347
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-53798
rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files.
๐@cveNotify
rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files.
๐@cveNotify
GitHub
Release v3.5.0 ยท RsyncProject/rsync
What's Changed
This is a major security release. For details see https://download.samba.org/pub/rsync/NEWS#3.5.0
Full Changelog: v3.4.4...v3.5.0
This is a major security release. For details see https://download.samba.org/pub/rsync/NEWS#3.5.0
Full Changelog: v3.4.4...v3.5.0
๐จ CVE-2026-53803
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
๐@cveNotify
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
๐@cveNotify
GitHub
Release v3.5.0 ยท RsyncProject/rsync
What's Changed
This is a major security release. For details see https://download.samba.org/pub/rsync/NEWS#3.5.0
Full Changelog: v3.4.4...v3.5.0
This is a major security release. For details see https://download.samba.org/pub/rsync/NEWS#3.5.0
Full Changelog: v3.4.4...v3.5.0
๐จ CVE-2026-67614
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
๐@cveNotify
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
๐@cveNotify
Knowledge Base
Change Logs - Knowledge Base
Dated: 7th September 2026