π¨ CVE-2026-83959
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
π@cveNotify
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
π@cveNotify
Adobe
Adobe Security Bulletin
Security updates available for Adobe Substance 3D - Sampler | APSB26-121
π¨ CVE-2026-65818
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
π@cveNotify
Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.
π@cveNotify
π¨ CVE-2026-70178
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
π@cveNotify
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
π@cveNotify
π¨ CVE-2026-80098
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
π@cveNotify
Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.
π@cveNotify
π¨ CVE-2026-18858
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
π@cveNotify
IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
π@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Obtaining Sensitive Information Vulnerability in OpenSSH [CVE-2026-18858]
IBM i is vulnerable to obtaining sensitive information from a privileged file [CVE-2026-18858] in OpenSSH as described in the vulnerability details section.
π¨ CVE-2026-19299
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.
π@cveNotify
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.
π@cveNotify
Ibm
Security Bulletin: Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, andβ¦
Langflow contains multiple authenticated path-traversal vulnerabilities that allow an attacker to read arbitrary files accessible to the Langflow server process, bypassing the LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true security control. The ChatInput component'sβ¦
π¨ CVE-2026-19304
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.
π@cveNotify
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.
π@cveNotify
Ibm
Security Bulletin: Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multipleβ¦
Langflow contains multiple Server-Side Request Forgery vulnerabilities across several components where authenticated users can supply attacker-controlled URLs or database connection strings that reach internal network hosts without adequate validation. Theβ¦
π¨ CVE-2026-19649
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials.
π@cveNotify
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of database credentials.
π@cveNotify
Ibm
Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs.
π¨ CVE-2026-13297
IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.
π@cveNotify
IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.
π@cveNotify
π¨ CVE-2026-16689
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.
π@cveNotify
IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacker to obtain sensitive information due to improper logging of credentials.
π@cveNotify
Ibm
Security Bulletin: IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs
IBM App Connect Enterprise and IBM Integration Bus for z/OS Adapter nodes are vulnerable to multiple CVEs.
π¨ CVE-2026-17057
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
π@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.
π@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Denial of Service Vulnerabilities in NFS [CVE-2026-17057, CVE-2026-17207]
IBM i is vulnerable to denial of service due to missing authentication and a buffer overflow [CVE-2026-17057, CVE-2026-17207] in Network File System (NFS) as described in the vulnerability details section.
π¨ CVE-2026-17274
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.
π@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predictable server seeds.
π@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Multiple Vulnerabilities in Debug Server
IBM i is vulnerable to multiple vulnerabilities [CVE-2026-16826, CVE-2026-17499, CVE-2026-17273, CVE-2026-17259, CVE-2026-18076, CVE-2026-17274, CVE-2026-17270, CVE-2026-18073] in Debug Server as described in the vulnerability details section.
π¨ CVE-2026-17622
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
π@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
π@cveNotify
Ibm
Security Bulletin: Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledgeβ¦
Langflow uses filesystem path construction as part of several components and API endpoints, including the Directory component, the Knowledge Base connector ingestion endpoint, and the Knowledge Base flow component. In the Directory component, user-suppliedβ¦
π¨ CVE-2026-17631
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
π@cveNotify
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
π@cveNotify
Ibm
Security Bulletin: Langflow OSS is affected by server-side request forgery due to missing URL validation in flow components
Langflow uses outbound HTTP request functionality as part of several flow components, including components for LM Studio, Home Assistant, DeepSeek, xAI, Glean, HuggingFace Inference API, Ollama, LiteLLM, and Docling Serve. These components accept user-suppliedβ¦
π¨ CVE-2026-18221
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
π@cveNotify
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.
π@cveNotify
Ibm
Security Bulletin: IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [CVE-2026-18175β¦
IBM i is vulnerable to manipulation of database transactions due to improper authorization [CVE-2026-18175] and allowing unathorized access due to improper validation [CVE-2026-18221] in Distributed Data Management (DDM) / Distributed Relational Databaseβ¦
π¨ CVE-2026-53756
Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter is directly interpolated into SQL queries without any filtering. The vulnerability is reachable through the auth cookie validation path, where $username is extracted from the cookie and passed unfiltered into SQL β guarded only by an HMAC signature that requires AUTH_KEY to forge. This issue has been patched in version 2.6.16.
π@cveNotify
Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection in User_Model::getUserDataByLogin(). The $account parameter is directly interpolated into SQL queries without any filtering. The vulnerability is reachable through the auth cookie validation path, where $username is extracted from the cookie and passed unfiltered into SQL β guarded only by an HMAC signature that requires AUTH_KEY to forge. This issue has been patched in version 2.6.16.
π@cveNotify
GitHub
fix(user_model): escape input and add docblock Β· emlog/emlog@92b6eea
add database input escaping to sanitize user input, preventing SQL injection, and add a PHPDoc comment to document the method
π¨ CVE-2026-53757
Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's subdirectory structure is checked. An attacker can overwrite arbitrary files on the server filesystem, including config.php for immediate RCE. At time of publication, there are no publicly known patches.
π@cveNotify
Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP entries via ZipArchive::extractTo() without validating entry paths for ../ traversal sequences. Only the first entry's subdirectory structure is checked. An attacker can overwrite arbitrary files on the server filesystem, including config.php for immediate RCE. At time of publication, there are no publicly known patches.
π@cveNotify
GitHub
Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE
### Summary
The `emUnZip()` function extracts all ZIP entries via `ZipArchive::extractTo()` without validating entry paths for `../` traversal sequences. Only the first entry's subdirectory st...
The `emUnZip()` function extracts all ZIP entries via `ZipArchive::extractTo()` without validating entry paths for `../` traversal sequences. Only the first entry's subdirectory st...
π¨ CVE-2026-57159
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur in the SDP negotiator when the remote payload-type map maintenance feature is enabled. assign_pt_and_update_map() in pjmedia/src/pjmedia/sdp_neg.c uses payload-type numbers taken from a remote SDP offer or answer to index fixed-size internal tables without sufficient bounds validation, so a crafted remote SDP can cause memory access outside those tables. The practical impact is memory corruption and denial of service; code execution is not demonstrated. This path is only reached when PJMEDIA_SDP_NEG_MAINTAIN_REMOTE_PT_MAP is enabled. The default is disabled, so default builds are not affected; the feature is an interoperability option that integrating products may enable. This issue has been patched via commit 673b978.
π@cveNotify
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 673b978, a remote out-of-bounds read and write can occur in the SDP negotiator when the remote payload-type map maintenance feature is enabled. assign_pt_and_update_map() in pjmedia/src/pjmedia/sdp_neg.c uses payload-type numbers taken from a remote SDP offer or answer to index fixed-size internal tables without sufficient bounds validation, so a crafted remote SDP can cause memory access outside those tables. The practical impact is memory corruption and denial of service; code execution is not demonstrated. This path is only reached when PJMEDIA_SDP_NEG_MAINTAIN_REMOTE_PT_MAP is enabled. The default is disabled, so default builds are not affected; the feature is an interoperability option that integrating products may enable. This issue has been patched via commit 673b978.
π@cveNotify
GitHub
Merge commit from fork Β· pjsip/pjproject@673b978
assign_pt_and_update_map() parses payload type numbers from remote
SDP a=rtpmap, a=fmtp, RED redundancy references, and the media format
list, then uses "pt - START_DYNAMIC_PT" to...
SDP a=rtpmap, a=fmtp, RED redundancy references, and the media format
list, then uses "pt - START_DYNAMIC_PT" to...
π¨ CVE-2026-57160
PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic array headers (such as Allow, Require, Supported, and Unsupported). Under certain output-buffer boundary conditions the function can write one byte past the end of the buffer. This is reachable mainly in applications that parse and re-serialize incoming SIP requests β for example a proxy, SBC, or B2BUA β where a remote peer can influence the serialized message. The out-of-bounds write is a single fixed byte; code execution and information disclosure are not demonstrated, and in typical pool-based allocations the byte falls within allocation slack. This issue has been patched via commit d6a0e7f.
π@cveNotify
PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflow can occur in pjsip_generic_array_hdr_print() in pjsip/src/pjsip/sip_msg.c, the function that serializes generic array headers (such as Allow, Require, Supported, and Unsupported). Under certain output-buffer boundary conditions the function can write one byte past the end of the buffer. This is reachable mainly in applications that parse and re-serialize incoming SIP requests β for example a proxy, SBC, or B2BUA β where a remote peer can influence the serialized message. The out-of-bounds write is a single fixed byte; code execution and information disclosure are not demonstrated, and in typical pool-based allocations the byte falls within allocation slack. This issue has been patched via commit d6a0e7f.
π@cveNotify
GitHub
Merge commit from fork Β· pjsip/pjproject@d6a0e7f
When printing a generic array header (e.g. Allow, Require, Supported,
Unsupported), the ": " delimiter following the header name was written
with two unchecked stores. copy_advanc...
Unsupported), the ": " delimiter following the header name was written
with two unchecked stores. copy_advanc...
π¨ CVE-2026-57164
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB-UTIL HTTP client (http_client.c) when buffering an HTTP response body. This affects applications that use the PJLIB-UTIL HTTP client to receive a whole response body at once (a completion callback with no incremental on_data_read callback). When growing the response buffer, an incorrect size calculation based on the server-supplied Content-Length can leave the buffer too small, causing response data to be written past the end of the allocation. A malicious or man-in-the-middle HTTP server can trigger this with a crafted response; impact may range from unexpected application termination to memory corruption. Applications that consume the response incrementally (via on_data_read), or that only connect to trusted servers, are not affected. This issue has been patched via commit 8d5956a.
π@cveNotify
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer overflow exists in the PJLIB-UTIL HTTP client (http_client.c) when buffering an HTTP response body. This affects applications that use the PJLIB-UTIL HTTP client to receive a whole response body at once (a completion callback with no incremental on_data_read callback). When growing the response buffer, an incorrect size calculation based on the server-supplied Content-Length can leave the buffer too small, causing response data to be written past the end of the allocation. A malicious or man-in-the-middle HTTP server can trigger this with a crafted response; impact may range from unexpected application termination to memory corruption. Applications that consume the response incrementally (via on_data_read), or that only connect to trusted servers, are not affected. This issue has been patched via commit 8d5956a.
π@cveNotify
GitHub
Merge commit from fork Β· pjsip/pjproject@8d5956a
http_on_data_read() in http_client.c grew the response buffer by a
single doubling, which is insufficient when the server sends a body
larger than twice the (attacker-supplied) Content-Length used ...
single doubling, which is insufficient when the server sends a body
larger than twice the (attacker-supplied) Content-Length used ...
π¨ CVE-2026-57165
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 628b716, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when redrawing the command line during history recall (handle_up_down() in cli_telnet.c). This affects only applications that enable the telnet CLI front-end (same gating as the related CLI issue). The line-redraw sequence for a recalled history entry can accumulate more data than a fixed-size stack buffer holds, which may lead to application termination. Exploitation requires access to the unauthenticated telnet CLI, which already permits arbitrary CLI commands, so the additional impact is limited. Applications that do not enable the telnet CLI front-end are not affected. This issue has been patched via commit 628b716.
π@cveNotify
PJSIP is a free and open source multimedia communication library written in C. Prior to commit 628b716, a stack buffer overflow exists in the PJLIB-UTIL telnet CLI front-end when redrawing the command line during history recall (handle_up_down() in cli_telnet.c). This affects only applications that enable the telnet CLI front-end (same gating as the related CLI issue). The line-redraw sequence for a recalled history entry can accumulate more data than a fixed-size stack buffer holds, which may lead to application termination. Exploitation requires access to the unauthenticated telnet CLI, which already permits arbitrary CLI commands, so the additional impact is limited. Applications that do not enable the telnet CLI front-end are not affected. This issue has been patched via commit 628b716.
π@cveNotify
GitHub
Merge commit from fork Β· pjsip/pjproject@628b716
handle_up_down() in cli_telnet.c accumulated cur_pos + 2*rcmd->len +
history->slen bytes into a fixed PJ_CLI_MAX_CMDBUF stack buffer with no
bound check. Size the buffer for the worst...
history->slen bytes into a fixed PJ_CLI_MAX_CMDBUF stack buffer with no
bound check. Size the buffer for the worst...