CVE Notify
19.7K subscribers
4 photos
301K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-63701
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

🎖@cveNotify
🚨 CVE-2026-63702
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

🎖@cveNotify
🚨 CVE-2026-66270
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

🎖@cveNotify
🚨 CVE-2026-66271
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

🎖@cveNotify
🚨 CVE-2026-66272
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

🎖@cveNotify
🚨 CVE-2026-63515
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-66807
Stack-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-70130
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-70338
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

🎖@cveNotify
🚨 CVE-2026-32153
Use after free in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-32202
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-48566
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-58643
Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-62241
clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as the default in .env.example. Because GET /api/v1/scans returns scan records containing userId values without authentication, a remote unauthenticated attacker can harvest a victim's userId, forge a valid HS256 cg_session cookie offline using the known secret, and call GET /api/v1/auth/me to obtain the victim's email address, subscription plan, and secret apiKey. The published clawvet npm package (CLI only) is not affected.

🎖@cveNotify
🚨 CVE-2026-63521
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-64910
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-65672
Heap-based buffer overflow in Windows Remote Access API allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-65679
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-65681
Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network.

🎖@cveNotify
🚨 CVE-2026-65777
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.

🎖@cveNotify
🚨 CVE-2026-65796
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

🎖@cveNotify