π¨ CVE-2026-62817
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
π@cveNotify
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
π@cveNotify
π¨ CVE-2026-62820
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
π@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-62823
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
π@cveNotify
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.
π@cveNotify
π¨ CVE-2026-62878
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
π@cveNotify
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-62893
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
π@cveNotify
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-65675
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
π@cveNotify
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network.
π@cveNotify
π¨ CVE-2026-65789
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
π@cveNotify
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-69278
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
π@cveNotify
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
π@cveNotify
π¨ CVE-2026-69306
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
π@cveNotify
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
π@cveNotify
π¨ CVE-2026-69320
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
π@cveNotify
Improper neutralization of special elements used in an os command ('os command injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-70335
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
π@cveNotify
Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-65937
In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.
π@cveNotify
In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.
π@cveNotify
Progress
WhatsUp Gold Security Bulletin August 2026 - Progress Community
Critical Security Alert Bulletin β August 2026 β (CVE-2026-65937, CVE-2026-65938, CVE-2026-65939, CVE-2026-65940, CVE-2026-65941)
π¨ CVE-2026-65938
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
π@cveNotify
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API allows any authenticated user to invoke restricted actions.
π@cveNotify
Progress
WhatsUp Gold Security Bulletin August 2026 - Progress Community
Critical Security Alert Bulletin β August 2026 β (CVE-2026-65937, CVE-2026-65938, CVE-2026-65939, CVE-2026-65940, CVE-2026-65941)
π¨ CVE-2026-65939
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
π@cveNotify
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within the IIS web root.
π@cveNotify
Progress
WhatsUp Gold Security Bulletin August 2026 - Progress Community
Critical Security Alert Bulletin β August 2026 β (CVE-2026-65937, CVE-2026-65938, CVE-2026-65939, CVE-2026-65940, CVE-2026-65941)
π¨ CVE-2026-65940
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
π@cveNotify
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
π@cveNotify
Progress
WhatsUp Gold Security Bulletin August 2026 - Progress Community
Critical Security Alert Bulletin β August 2026 β (CVE-2026-65937, CVE-2026-65938, CVE-2026-65939, CVE-2026-65940, CVE-2026-65941)
π¨ CVE-2026-65941
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
π@cveNotify
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.
π@cveNotify
Progress
WhatsUp Gold Security Bulletin August 2026 - Progress Community
Critical Security Alert Bulletin β August 2026 β (CVE-2026-65937, CVE-2026-65938, CVE-2026-65939, CVE-2026-65940, CVE-2026-65941)
π¨ CVE-2026-49096
Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error prevented the affected case from being displayed. An authenticated user holding privileges to comment on a case could store such a comment, after which that case became inaccessible to every user who opened it until the stored comment was removed.
π@cveNotify
Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitized when the comment was later formatted for display, and the resulting unhandled error prevented the affected case from being displayed. An authenticated user holding privileges to comment on a case could store such a comment, after which that case became inaccessible to every user who opened it until the stored comment was removed.
π@cveNotify
Discuss the Elastic Stack
Kibana 8.19.20, 9.3.5, 9.4.2 Security Update (ESA-2026-136)
Uncaught Exception in Kibana Cases Leading to Denial of Service Uncaught Exception (CWE-248) in Kibana Cases can lead to denial of service via Input Data Manipulation (CAPEC-153). Malformed link syntax stored in a case comment was not rejected or sanitizedβ¦
π¨ CVE-2026-72630
Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was evaluated against the integration recorded on the stored policy rather than against the replacement integration supplied with the update. An authenticated user holding only the Elastic Defend endpoint policy management privilege was therefore able to convert an endpoint policy they administer into a policy for a different integration, and to supply that integration's configuration at the same time.
π@cveNotify
Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integration policies for one specific integration. When an existing integration policy was updated, that restriction was evaluated against the integration recorded on the stored policy rather than against the replacement integration supplied with the update. An authenticated user holding only the Elastic Defend endpoint policy management privilege was therefore able to convert an endpoint policy they administer into a policy for a different integration, and to supply that integration's configuration at the same time.
π@cveNotify
Discuss the Elastic Stack
Kibana 8.19.20, 9.4.5, 9.5.1 Security Update (ESA-2026-127)
Incorrect Authorization in Kibana Fleet Leading to Privilege Escalation Description: Incorrect Authorization (CWE-863) in Kibana Fleet can lead to privilege escalation via Privilege Abuse (CAPEC-122). Fleet restricts some callers to managing integrationβ¦
π¨ CVE-2026-72631
Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Elasticsearch API key issued to Elastic Agents enrolled in the corresponding agent policy. The resulting key allows new documents to be inserted and index mappings to be extended for specific indices. The key does not allow reading, updating, or deleting existing documents
π@cveNotify
Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policy may optionally declare extra data streams that the integration writes to, which Fleet adds to the Elasticsearch API key issued to Elastic Agents enrolled in the corresponding agent policy. The resulting key allows new documents to be inserted and index mappings to be extended for specific indices. The key does not allow reading, updating, or deleting existing documents
π@cveNotify
Discuss the Elastic Stack
Kibana 9.4.5, 9.5.1 Security Update (ESA-2026-128)
Improper Privilege Management in Kibana Fleet Leading to Over-Scoped Elastic Agent API Keys Description: Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC-233). An integration policyβ¦
π¨ CVE-2026-16137
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
π@cveNotify
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
π@cveNotify
Sharefile
ShareFile Storage Zones Controller (SZC) Service Disruption Guidance, Login Issues, and Access Information
This article addresses common questions related to the ShareFile Storage Zones Controller (SZC) service disruption notification, including whether the email communication is legitimate, why ShareFile access may be unavailable, login and authentication issuesβ¦
π¨ CVE-2026-16138
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.
π@cveNotify
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.
π@cveNotify
Sharefile
ShareFile Storage Zones Controller (SZC) Service Disruption Guidance, Login Issues, and Access Information
This article addresses common questions related to the ShareFile Storage Zones Controller (SZC) service disruption notification, including whether the email communication is legitimate, why ShareFile access may be unavailable, login and authentication issuesβ¦