CVE Notify
19.6K subscribers
4 photos
306K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-66403
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected products may be retrieved.

🎖@cveNotify
🚨 CVE-2026-66404
DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affected products may be retrieved.

🎖@cveNotify
🚨 CVE-2026-66405
DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.

🎖@cveNotify
🚨 CVE-2026-66406
DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled.
A man-in-the-middle attack may allow to obtain and/or alter communications of the affected products. As a result, arbitrary code may be executed with the administrative privilege.

🎖@cveNotify
🚨 CVE-2026-66407
DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication.
The WebSocket private key may be retrieved through analyzing the traffic data via a man-in-the-middle attack, and communication contents may be altered.

🎖@cveNotify
🚨 CVE-2026-66408
The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords.
Physical access to an affected product may allow to obtain the password of the root account.

🎖@cveNotify
🚨 CVE-2026-66409
DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks.
The password may be analyzed and obtained to connect to the access point of an affected robot.

🎖@cveNotify
🚨 CVE-2026-66410
Android and iOS apps ECOVACS PRO App improperly validate server certificates.
Communication may be retrieved and/or altered.

🎖@cveNotify
🚨 CVE-2026-66411
DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications.
An unauthenticated attacker may connect and operate the affected robot.

🎖@cveNotify
🚨 CVE-2026-56619
HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controlled input.

🎖@cveNotify
🚨 CVE-2026-72506
VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a communication channel vulnerability. Users may be directed to a server (or service) controlled by an attacker, potentially resulting in the theft of input data or the display of incorrect results.

🎖@cveNotify
🚨 CVE-2026-59500
: Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

🎖@cveNotify
🚨 CVE-2026-59501
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

🎖@cveNotify
🚨 CVE-2026-59502
: Observable Discrepancy vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

🎖@cveNotify
🚨 CVE-2026-59503
: Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

🎖@cveNotify
🚨 CVE-2026-59504
: Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

🎖@cveNotify
🚨 CVE-2026-59505
: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

🎖@cveNotify
🚨 CVE-2026-59506
: Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

🎖@cveNotify
🚨 CVE-2026-59507
: Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions).

This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

🎖@cveNotify
🚨 CVE-2026-73626
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. Fixed in JupyterLab 4.6.2 and 4.5.10.

🎖@cveNotify