CVE Notify
19.7K subscribers
4 photos
298K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-19182
An incorrect authorization check in the v2 Alarm REST API in OpenNMS Meridian and Horizon allows a low-privileged authenticated user (ROLE_REST) to acknowledge, escalate, or clear alarms recorded as an arbitrary username, and, when also assigned ROLE_READONLY, to modify alarm state despite the read-only restriction. A credential check that should restrict these operations is guarded by an inverted condition, so it never executes for a real (non-blank) username. This can potentially allow an attacker to compromise the integrity of alarm state and audit records.



The solution is to upgrade to Meridian 2024.3.12, 2025.0.9 and Horizon 36.0.3 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.

πŸŽ–@cveNotify
🚨 CVE-2026-16455
In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exists whereby a lower privileged user can escalate privileges to administrative level due to unsafe calls to an execl function.

πŸŽ–@cveNotify
🚨 CVE-2026-18368
In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd
due to improper handling of Modbus TCP request data. A remote,
unauthenticated attacker with access to the affected service could
trigger a heap-based buffer overflow, resulting in a denial of service.

πŸŽ–@cveNotify
🚨 CVE-2026-16101
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below

πŸŽ–@cveNotify
🚨 CVE-2026-19291
Bluetooth re-pairing with an existing device can use a lower security level. RS9116W and SiWx91x impacted. See V3 in the BLERP paper linked below.

πŸŽ–@cveNotify
🚨 CVE-2026-19292
Re-pairing with a legitimate device can use a lower security level than
previous making brute-forcing the LTK easier. See V4 in the BLERP paper linked below.

πŸŽ–@cveNotify
🚨 CVE-2026-19293
SMP security request (from peripheral) does not include the maximum
encryption key size supported. Using a key with less than the maximum keysize
makes brute-forcing the key easier. See V6 in BLERP paper linked below.

πŸŽ–@cveNotify
🚨 CVE-2026-65932
The BT122 module stops advertising after receiving a plaintext 'pause enceryption response' message resulting in a denial of service. See vulnerability B-E2 in the related paper below.

πŸŽ–@cveNotify
🚨 CVE-2026-65933
A malformed Bluetooth connection request message can cause the BT122 to leak potentially sensitive information. See vulnerability B-E4 in the related paper below.

πŸŽ–@cveNotify
🚨 CVE-2026-65934
An unencrypted 'pause encryption request' message causes a denial of service in the BT122 module. 
See vulnerability B-E10 in the related paper below.

πŸŽ–@cveNotify
🚨 CVE-2026-65935
Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value. 
See vulnerability B-E3 in the related paper below.

πŸŽ–@cveNotify
🚨 CVE-2026-65936
A malformed Bluetooth connection request message can cause the RS9116W/SiWx917 to leak potentially sensitive information. 
See vulnerability B-E4 in the related paper below.

πŸŽ–@cveNotify
🚨 CVE-2026-74997
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.

πŸŽ–@cveNotify
🚨 CVE-2026-74998
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.

πŸŽ–@cveNotify
🚨 CVE-2026-75000
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HTML/CSS sanitization of the SVG animate "by" attribute may lead to remote image blocking bypass, which in turn may lead to information disclosure or privilege escalation.

πŸŽ–@cveNotify
🚨 CVE-2026-75002
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.

πŸŽ–@cveNotify
🚨 CVE-2026-75004
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using the managesieve plugin.

πŸŽ–@cveNotify
🚨 CVE-2026-75006
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to local network hosts. This issue exists because of insufficient fixes for CVE-2026-35540, CVE-2026-48843 and CVE-2026-62643.

πŸŽ–@cveNotify
🚨 CVE-2026-77640
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.

πŸŽ–@cveNotify
🚨 CVE-2026-77641
tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go undetected, causing the caller to write to the now-freed current leg and resulting in a crash. This is TROVE-2026-017.

πŸŽ–@cveNotify