CVE Notify
19.7K subscribers
4 photos
301K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-65794
Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-65795
No cwe for this issue in Windows DNS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-65796
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-65797
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-65798
Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-65799
Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-65814
Heap-based buffer overflow in Windows Storage Port Driver allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-66799
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-66802
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-68819
Buffer over-read in Windows Network File System allows an unauthorized attacker to deny service over a network.

🎖@cveNotify
🚨 CVE-2026-68820
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-70304
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-70306
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-70307
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-70330
Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-70344
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-70345
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-70346
Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-71331
Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attestation Service allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2025-7195
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/passwd file to 664 during build time. Developers who used Operator-SDK before 0.15.2 to scaffold their operator may still be impacted by this if the insecure user_setup script is still being used to build new container images.

In affected images, the /etc/passwd file is created during build time with group-writable permissions and a group ownership of root (gid=0). An attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.

🎖@cveNotify
🚨 CVE-2026-19955
A vulnerability was detected in TrailDB 0.6. Impacted is the function tdb_open of the file /src/tdb.c of the component TOC Validation. The manipulation results in out-of-bounds read. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

🎖@cveNotify