π¨ CVE-2026-83596
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
π@cveNotify
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
π@cveNotify
Redhat
CVE-2026-83596 - Red Hat Customer Portal
CVE Details App
π¨ CVE-2026-76111
Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.
π@cveNotify
Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.
π@cveNotify
π¨ CVE-2026-79684
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.
π@cveNotify
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.
π@cveNotify
π¨ CVE-2026-58569
Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..
π@cveNotify
Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..
π@cveNotify
π¨ CVE-2026-58566
Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
π@cveNotify
Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
π@cveNotify
π¨ CVE-2026-52131
llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.
π@cveNotify
llama.cpp b5693 and before has a Reachable Assertion via the gguf_reader::read function.
π@cveNotify
Ph4nt0m
llama.cpp json-schema-to-grammar 무μ μ΄ μ¬κ· DoS
llama.cpp <=b5693μ common/json-schema-to-grammar.cppμ 무μ μ΄ μ¬κ·λ‘ μΈν΄ μλΉμ€ κ±°λΆ(DoS)μ μ·¨μ½ν©λλ€. POST /completions κ²½λ‘λ§ μν₯μ λ°μ΅λλ€.
π¨ CVE-2026-52132
llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.
π@cveNotify
llama.cpp through commit 97f06e9, when started with the --reranking flag, allows remote attackers to cause a denial of service (std::bad_alloc and HTTP 500) via a negative top_n value in a POST request to /rerank.
π@cveNotify
Ph4nt0m
llama.cpp /rerank μμ top_n μλΉμ€ κ±°λΆ
--reranking νλκ·Έλ‘ μ€νλ llama.cppλ POST /rerankμ μμ top_n κ°μ ν΅ν΄ μ격 μλΉμ€ κ±°λΆ (std::bad_alloc, HTTP 500)μ μ·¨μ½ν©λλ€.
π¨ CVE-2026-19766
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.
π@cveNotify
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.
π@cveNotify
π¨ CVE-2026-56143
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable.
π@cveNotify
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable.
π@cveNotify
Discuss the Elastic Stack
Elasticsearch 8.19.20, 9.3.0 Security Update (ESA-2026-47)
Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A userβ¦
π¨ CVE-2026-72633
Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators.
π@cveNotify
Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators.
π@cveNotify
Discuss the Elastic Stack
Kibana 9.4.6, 9.5.2 Security Update (ESA-2026-130)
Incorrect Authorization in Kibana Leading to Unauthorized Disabling of Privilege Monitoring Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLsβ¦
π¨ CVE-2026-75604
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/next/src/server/lib/incremental-cache/file-system-cache.ts, a remote request can supply encoded Windows path separators that traverse outside the intended cache root and expose private build data, including the server-reference-manifest encryption key. Disclosure of that key can enable remote code execution in the affected application. This issue is fixed in versions 15.5.24 and 16.3.3.
π@cveNotify
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/next/src/server/lib/incremental-cache/file-system-cache.ts, a remote request can supply encoded Windows path separators that traverse outside the intended cache root and expose private build data, including the server-reference-manifest encryption key. Disclosure of that key can enable remote code execution in the affected application. This issue is fixed in versions 15.5.24 and 16.3.3.
π@cveNotify
GitHub
[16.3.x] Fix ISR misses with backslashes in segments when deployed on⦠· vercel/next.js@968b9fc
β¦ Windows
https://github.com/vercel/next-js-mirror/pull/156
https://github.com/vercel/next-js-mirror/pull/156
π¨ CVE-2026-16647
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
π@cveNotify
Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.
π@cveNotify
Drupal.org
Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111
This module enables you to disable access to the /user/login form unless a secret key is provided. The module does not invalidate the relevant caches when login page access restrictions are enabled. As a result, previously cached login page responses mayβ¦
π¨ CVE-2026-84653
Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.
π@cveNotify
Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.
π@cveNotify
Jenkins Security Advisory 2026-09-02
Jenkins β an open source automation server which enables developers around the world to reliably build, test, and deploy their software
π¨ CVE-2026-84666
Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.
π@cveNotify
Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.
π@cveNotify
Jenkins Security Advisory 2026-09-02
Jenkins β an open source automation server which enables developers around the world to reliably build, test, and deploy their software
π¨ CVE-2023-20576
Insufficient Verification of Data Authenticity in AGESAβ’ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.
π@cveNotify
Insufficient Verification of Data Authenticity in AGESAβ’ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.
π@cveNotify
AMD
GPU Memory Leaks
π¨ CVE-2023-20577
A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
π@cveNotify
A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
π@cveNotify
AMD
GPU Memory Leaks
π¨ CVE-2026-85169
n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without requiring it to be an own property and admitted reserved keys; against a primitive input value it returned a live host-prototype reference. An attacker with workflow-build privilege can walk the prototype chain to the Function constructor and compile/execute arbitrary code in the main n8n process, leading to remote code execution.
π@cveNotify
n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without requiring it to be an own property and admitted reserved keys; against a primitive input value it returned a live host-prototype reference. An attacker with workflow-build privilege can walk the prototype chain to the Function constructor and compile/execute arbitrary code in the main n8n process, leading to remote code execution.
π@cveNotify
GitHub
Expression Sandbox Escape via $fromAI Prototype Leak Leads to Host RCE
## Impact
`$fromAI` resolved a caller-supplied placeholder name without requiring it to be an own property, and admitted reserved keys, against a primitive input value this returned a live host-pr...
`$fromAI` resolved a caller-supplied placeholder name without requiring it to be an own property, and admitted reserved keys, against a primitive input value this returned a live host-pr...
π¨ CVE-2026-85458
Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.
π@cveNotify
Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.
π@cveNotify
π¨ CVE-2026-65818
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
π@cveNotify
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
π@cveNotify
π¨ CVE-2026-70178
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
π@cveNotify
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
π@cveNotify
π¨ CVE-2026-70352
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
π@cveNotify
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
π@cveNotify