CVE Notify
19.7K subscribers
4 photos
288K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-83596
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

πŸŽ–@cveNotify
🚨 CVE-2026-76111
Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.

πŸŽ–@cveNotify
🚨 CVE-2026-79684
Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.

πŸŽ–@cveNotify
🚨 CVE-2026-58569
Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..

πŸŽ–@cveNotify
🚨 CVE-2026-58566
Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

πŸŽ–@cveNotify
🚨 CVE-2026-19766
An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to complete compromise of the AFC host.

πŸŽ–@cveNotify
🚨 CVE-2026-56143
Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render the affected node unavailable.

πŸŽ–@cveNotify
🚨 CVE-2026-72633
Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). An authenticated user holding only read-level Security feature access, and no Elasticsearch privileges, could stop the recurring Privilege Monitoring engine task for a Kibana space. Privileged user monitoring then stops producing data for that space while the engine continues to report a healthy state to operators.

πŸŽ–@cveNotify
🚨 CVE-2026-75604
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/next/src/server/lib/incremental-cache/file-system-cache.ts, a remote request can supply encoded Windows path separators that traverse outside the intended cache root and expose private build data, including the server-reference-manifest encryption key. Disclosure of that key can enable remote code execution in the affected application. This issue is fixed in versions 15.5.24 and 16.3.3.

πŸŽ–@cveNotify
🚨 CVE-2026-84653
Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with Overall/Manage permission to modify Appearance configuration options they should not have access to.

πŸŽ–@cveNotify
🚨 CVE-2026-84666
Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc and earlier allows overwriting the plugin's history recording configuration through Stapler data binding, allowing attackers to redirect history storage to an attacker-specified directory and modify history recording settings.

πŸŽ–@cveNotify
🚨 CVE-2023-20576
Insufficient Verification of Data Authenticity in AGESAβ„’ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.

πŸŽ–@cveNotify
🚨 CVE-2023-20577
A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.

πŸŽ–@cveNotify
🚨 CVE-2026-85169
n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without requiring it to be an own property and admitted reserved keys; against a primitive input value it returned a live host-prototype reference. An attacker with workflow-build privilege can walk the prototype chain to the Function constructor and compile/execute arbitrary code in the main n8n process, leading to remote code execution.

πŸŽ–@cveNotify
🚨 CVE-2026-85458
Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.

πŸŽ–@cveNotify
🚨 CVE-2026-65818
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

πŸŽ–@cveNotify
🚨 CVE-2026-70178
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

πŸŽ–@cveNotify
🚨 CVE-2026-70352
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

πŸŽ–@cveNotify