π¨ CVE-2026-19182
An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also assigned ROLE_READONLY, to modify alarm state despite the read-only restriction. A credential check that should restrict these operations is guarded by an inverted condition, so it never executes for a real (non-blank) username. This can potentially allow an attacker to compromise the integrity of alarm state and audit records.
The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
π@cveNotify
An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also assigned ROLE_READONLY, to modify alarm state despite the read-only restriction. A credential check that should restrict these operations is guarded by an inverted condition, so it never executes for a real (non-blank) username. This can potentially allow an attacker to compromise the integrity of alarm state and audit records.
The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
π@cveNotify
GitHub
NMS-20030: Fix v2 alarm rest api access issue by cgorantla Β· Pull Request #8755 Β· OpenNMS/opennms
External References
Jira (Issue Tracker): https://opennms.atlassian.net/browse/NMS-20030
Jira (Issue Tracker): https://opennms.atlassian.net/browse/NMS-20030
π¨ CVE-2026-16455
In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function.
π@cveNotify
In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function.
π@cveNotify
Teltonika Networks: Industrial IoT Routers & Gateways
Security Centre
Visit Teltonika Networks' security centre for updates and reporting on security vulnerabilities, emphasising commitment to your IoT solutions.
π¨ CVE-2026-18368
In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd
due to improper handling of Modbus TCP request data. A remote,
unauthenticated attacker with access to the affected service could
trigger a heap-based buffer overflow, resulting in a denial of service.
π@cveNotify
In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd
due to improper handling of Modbus TCP request data. A remote,
unauthenticated attacker with access to the affected service could
trigger a heap-based buffer overflow, resulting in a denial of service.
π@cveNotify
Teltonika Networks: Industrial IoT Routers & Gateways
Security Centre
Visit Teltonika Networks' security centre for updates and reporting on security vulnerabilities, emphasising commitment to your IoT solutions.
π¨ CVE-2026-16101
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
π@cveNotify
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
π@cveNotify
π¨ CVE-2026-19291
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
π@cveNotify
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.
π@cveNotify
π¨ CVE-2026-19292
Re-pairing with a legitimate device can use a lower security level than
previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
π@cveNotify
Re-pairing with a legitimate device can use a lower security level than
previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.
π@cveNotify
π¨ CVE-2026-19293
SMP security request (from peripheral) does not include the maximum
encryption key size supported. Using a key with less than the maximum keysize
makes brute-forcing the key easier. See V6 in BLERP paper linked below.
π@cveNotify
SMP security request (from peripheral) does not include the maximum
encryption key size supported. Using a key with less than the maximum keysize
makes brute-forcing the key easier. See V6 in BLERP paper linked below.
π@cveNotify
π¨ CVE-2026-65932
The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below.
π@cveNotify
The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below.
π@cveNotify
π¨ CVE-2026-65933
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
π@cveNotify
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.
π@cveNotify
π¨ CVE-2026-65934
An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.
See vulnerability B-E10 in the related paper below.
π@cveNotify
An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module.
See vulnerability B-E10 in the related paper below.
π@cveNotify
π¨ CVE-2026-65935
Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.
See vulnerability B-E3 in the related paper below.
π@cveNotify
Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.
See vulnerability B-E3 in the related paper below.
π@cveNotify
π¨ CVE-2026-65936
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.
See vulnerability B-E4 in the related paper below.
π@cveNotify
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information.
See vulnerability B-E4 in the related paper below.
π@cveNotify
π¨ CVE-2026-74997
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
π@cveNotify
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
π@cveNotify
GitHub
Fix RCE via cmd_learn driver of markasjunk plugin Β· roundcube/roundcubemail@14044f8
The Roundcube Webmail suite. Contribute to roundcube/roundcubemail development by creating an account on GitHub.
π¨ CVE-2026-74998
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
π@cveNotify
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
π@cveNotify
GitHub
Add basic validation for content proxied by the css proxy Β· roundcube/roundcubemail@62d33c8
The Roundcube Webmail suite. Contribute to roundcube/roundcubemail development by creating an account on GitHub.
π¨ CVE-2026-74999
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
π@cveNotify
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.
π@cveNotify
GitHub
Fix stored XSS in "Add to address book" action Β· roundcube/roundcubemail@2d2a960
The Roundcube Webmail suite. Contribute to roundcube/roundcubemail development by creating an account on GitHub.
π¨ CVE-2026-75000
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
π@cveNotify
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.
π@cveNotify
GitHub
Release Roundcube Webmail 1.6.18 Β· roundcube/roundcubemail
This is a security update to the version 1.6 of Roundcube Webmail.
It provides fixes to recently reported security vulnerabilities:
Add basic validation for content proxied by the css proxy
Fix SS...
It provides fixes to recently reported security vulnerabilities:
Add basic validation for content proxied by the css proxy
Fix SS...
π¨ CVE-2026-75002
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
π@cveNotify
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
π@cveNotify
GitHub
Fix IMAP command injection via mail search and LITERAL+ byte-count de⦠· roundcube/roundcubemail@404d43f
β¦synchronization
π¨ CVE-2026-75004
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
π@cveNotify
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.
π@cveNotify
GitHub
Release Roundcube Webmail 1.6.18 Β· roundcube/roundcubemail
This is a security update to the version 1.6 of Roundcube Webmail.
It provides fixes to recently reported security vulnerabilities:
Add basic validation for content proxied by the css proxy
Fix SS...
It provides fixes to recently reported security vulnerabilities:
Add basic validation for content proxied by the css proxy
Fix SS...
π¨ CVE-2026-75006
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
π@cveNotify
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.
π@cveNotify
GitHub
Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 a⦠· roundcube/roundcubemail@7e10ca0
β¦nd fe80::/10 nets
π¨ CVE-2026-77640
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.
π@cveNotify
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.
π@cveNotify
π¨ CVE-2026-77641
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go undetected, causing the caller to write to the now-freed current leg and resulting in a crash. This is TROVE-2026-017.
π@cveNotify
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go undetected, causing the caller to write to the now-freed current leg and resulting in a crash. This is TROVE-2026-017.
π@cveNotify