๐จ CVE-2026-63524
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-63529
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-63531
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-64906
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
๐@cveNotify
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-65768
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-65810
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
๐@cveNotify
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69278
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
๐@cveNotify
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
๐@cveNotify
๐จ CVE-2026-69320
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-70312
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-70313
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-70322
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-70336
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-70345
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-70346
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-70347
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-53798
rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files.
๐@cveNotify
rsync before 3.5.0 contains a privilege confusion vulnerability in the name-converter subprocess uid/gid mapping that allows local attackers to cause transferred files to be owned by root by influencing name-converter responses to return empty values. When the name-converter subprocess returns an empty response for a uid or gid lookup, rsync incorrectly interprets it as a successful resolution to uid/gid 0 (root) rather than a lookup failure, and if the name-converter also signals fake super-user status, rsync proceeds with root ownership assignments for transferred files.
๐@cveNotify
GitHub
Release v3.5.0 ยท RsyncProject/rsync
What's Changed
This is a major security release. For details see https://download.samba.org/pub/rsync/NEWS#3.5.0
Full Changelog: v3.4.4...v3.5.0
This is a major security release. For details see https://download.samba.org/pub/rsync/NEWS#3.5.0
Full Changelog: v3.4.4...v3.5.0
๐จ CVE-2026-53803
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
๐@cveNotify
rsync before 3.5.0 contains a symlink following vulnerability that allows local attackers to overwrite arbitrary files by placing a symlink at a predictable output path such as --log-file, --write-batch, or daemon-mode log and statistics paths. Attackers can exploit rsync's failure to reject symlinks during ancillary file writes to redirect output to arbitrary filesystem locations, achieving local privilege escalation on installations where rsync runs with elevated privileges such as setuid or privileged daemon configurations.
๐@cveNotify
GitHub
Release v3.5.0 ยท RsyncProject/rsync
What's Changed
This is a major security release. For details see https://download.samba.org/pub/rsync/NEWS#3.5.0
Full Changelog: v3.4.4...v3.5.0
This is a major security release. For details see https://download.samba.org/pub/rsync/NEWS#3.5.0
Full Changelog: v3.4.4...v3.5.0
๐จ CVE-2026-67614
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
๐@cveNotify
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service without any valid credentials and receive a root shell.
๐@cveNotify
Knowledge Base
Change Logs - Knowledge Base
Dated: 7th September 2026
๐จ CVE-2026-16967
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links.
๐@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to system objects due to a time-of-check to time-of-use (TOCTOU) race condition involving symbolic links.
๐@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Multiple SQL Vulnerabilities [CVE-2026-16908, CVE-2026-16967]
IBM i is vulnerable to multiple vulnerabilities [CVE-2026-16908, CVE-2026-16967] in SQL as described in the vulnerability details section.
๐จ CVE-2026-16975
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
๐@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to a heap-based buffer overflow.
๐@cveNotify
Ibm
Security Bulletin: IBM i is Affected By A Remote Code Execution Vulnerability [CVE-2026-16975]
IBM i is vulnerable to remote code execution due to a heap-based buffer overflow [CVE-2026-16975] as described in the vulnerability details section.
๐จ CVE-2026-16987
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
๐@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper validation of the LANG environment variable.
๐@cveNotify
Ibm
Security Bulletin: IBM i is Affected By An Improper Validation Vulnerability in PASE [CVE-2026-16987]
IBM i is vulnerable to elevated privileges due to improper validation [CVE-2026-16987] in Portable Application Solutions Environment (PASE) as described in the vulnerability details section.