🚨 CVE-2026-14587
Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of rejecting the protocol message and closing the channel.
Because the same unread bytes remain at the front of the decoder buffer, appending a terminating byte later does not recover the connection. The decoder re-reads the same first 32 continuation bytes, returns without producing a handshake-finalization message, and leaves the channel open.
This can be triggered before authentication by any client that can reach the Bolt connector.
🎖@cveNotify
Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends a selected protocol version followed by 32 continuation bytes in the capability mask, the decoder resets the reader index and waits for more bytes instead of rejecting the protocol message and closing the channel.
Because the same unread bytes remain at the front of the decoder buffer, appending a terminating byte later does not recover the connection. The decoder re-reads the same first 32 continuation bytes, returns without producing a handshake-finalization message, and leaves the channel open.
This can be triggered before authentication by any client that can reach the Bolt connector.
🎖@cveNotify
🚨 CVE-2026-21766
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications using the default login portlet.
🎖@cveNotify
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. Under certain very specific use cases and specific configurations, sensitive information may be written to web server logs. This only affects applications using the default login portlet.
🎖@cveNotify
Hcl-Software
Security Bulletin: HCL Digital Experience and Digital Experience Compose insufficiently protects credentials - Customer Support
The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects
🚨 CVE-2026-57279
Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product.
🎖@cveNotify
Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product.
🎖@cveNotify
jvn.jp
JVN#72334274: Cybozu Garoon vulnerable to cross-site scripting
Japan Vulnerability Notes
🚨 CVE-2026-64940
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console.
🎖@cveNotify
Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any operations available from the management console.
🎖@cveNotify
jvn.jp
JVN#99975039: Permissive regular expression vulnerability in Tegalog -Fumy Otegaru Memo Logger-
Japan Vulnerability Notes
🚨 CVE-2026-66403
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.
🎖@cveNotify
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.
🎖@cveNotify
jvn.jp
JVNVU#92804348: Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Japan Vulnerability Notes
🚨 CVE-2026-66404
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.
🎖@cveNotify
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.
🎖@cveNotify
jvn.jp
JVNVU#92804348: Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Japan Vulnerability Notes
🚨 CVE-2026-66405
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
🎖@cveNotify
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.
🎖@cveNotify
jvn.jp
JVNVU#92804348: Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Japan Vulnerability Notes
🚨 CVE-2026-66406
DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled.
A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.
🎖@cveNotify
DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled.
A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.
🎖@cveNotify
jvn.jp
JVNVU#92804348: Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Japan Vulnerability Notes
🚨 CVE-2026-66407
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication.
The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
🎖@cveNotify
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication.
The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.
🎖@cveNotify
jvn.jp
JVNVU#92804348: Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Japan Vulnerability Notes
🚨 CVE-2026-66408
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.
Physical access to an affected product may allow to obtain the password of the root account.
🎖@cveNotify
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.
Physical access to an affected product may allow to obtain the password of the root account.
🎖@cveNotify
jvn.jp
JVNVU#92804348: Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Japan Vulnerability Notes
🚨 CVE-2026-66409
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.
The password may be analyzed and obtained to connect to the access point of an affected robot.
🎖@cveNotify
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.
The password may be analyzed and obtained to connect to the access point of an affected robot.
🎖@cveNotify
jvn.jp
JVNVU#92804348: Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Japan Vulnerability Notes
🚨 CVE-2026-66410
Android and iOS apps ECOVACS PRO App improperly validate server certificates.
Communication may be retrieved and/or altered.
🎖@cveNotify
Android and iOS apps ECOVACS PRO App improperly validate server certificates.
Communication may be retrieved and/or altered.
🎖@cveNotify
jvn.jp
JVNVU#92804348: Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Japan Vulnerability Notes
🚨 CVE-2026-66411
DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications.
An unauthenticated attacker may connect and operate the affected robot.
🎖@cveNotify
DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications.
An unauthenticated attacker may connect and operate the affected robot.
🎖@cveNotify
jvn.jp
JVNVU#92804348: Multiple vulnerabilities in DEEBOT PRO M1, DEEBOT PRO K1VAC and ECOVACS PRO App
Japan Vulnerability Notes
🚨 CVE-2026-56620
HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting.
🎖@cveNotify
HCL BigFix Mobile is vulnerable to information disclosure due to improper handling of exceptions and verbose error reporting.
🎖@cveNotify
Hcl-Software
Security Bulletin: Multiple vulnerabilities affect HCL BigFix Mobile - Customer Support
Multiple security vulnerabilities have been identified in HCL BigFix Mobile.
🚨 CVE-2026-56619
HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input.
🎖@cveNotify
HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input.
🎖@cveNotify
Hcl-Software
Security Bulletin: Multiple vulnerabilities affect HCL BigFix Mobile - Customer Support
Multiple security vulnerabilities have been identified in HCL BigFix Mobile.
🚨 CVE-2026-72506
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.
🎖@cveNotify
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.
🎖@cveNotify
jvn.jp
JVN#00941257: VoiceTra vulnerable to incorrectly specified destination in a communication channel
Japan Vulnerability Notes
🚨 CVE-2026-59500
: Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
🎖@cveNotify
: Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
🎖@cveNotify
🚨 CVE-2026-59501
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
🎖@cveNotify
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
🎖@cveNotify
🚨 CVE-2026-59502
: Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
🎖@cveNotify
: Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
🎖@cveNotify
🚨 CVE-2026-59503
: Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
🎖@cveNotify
: Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
🎖@cveNotify
🚨 CVE-2026-59504
: Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
🎖@cveNotify
: Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).
This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.
🎖@cveNotify