🚨 CVE-2026-83986
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-83987
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-83988
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-83989
Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
🎖@cveNotify
Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.
🎖@cveNotify
🚨 CVE-2026-83990
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-83991
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
🎖@cveNotify
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.
🎖@cveNotify
🚨 CVE-2026-83992
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
🎖@cveNotify
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
🎖@cveNotify
🚨 CVE-2026-83995
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-83996
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-83997
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
🎖@cveNotify
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
🎖@cveNotify
🚨 CVE-2026-83998
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
🎖@cveNotify
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
🎖@cveNotify
🚨 CVE-2026-83999
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-84000
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
🎖@cveNotify
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
🎖@cveNotify
🚨 CVE-2026-84003
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
🎖@cveNotify
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
🎖@cveNotify
🚨 CVE-2026-85360
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-85875
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
🎖@cveNotify
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2026-85877
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
🎖@cveNotify
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
🎖@cveNotify
🚨 CVE-2026-85880
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-86074
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-controlled fetched content could influence that URL after a user injected it into the setup flow, causing authenticated requests, redirects, or probes to reach another origin. The affected logic includes packages/@n8n/instance-ai/src/tools/workflows/credential-utils.ts and the extractServiceOrigin origin derivation. This issue is fixed in versions 2.37.7 and 2.38.2.
🎖@cveNotify
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-controlled fetched content could influence that URL after a user injected it into the setup flow, causing authenticated requests, redirects, or probes to reach another origin. The affected logic includes packages/@n8n/instance-ai/src/tools/workflows/credential-utils.ts and the extractServiceOrigin origin derivation. This issue is fixed in versions 2.37.7 and 2.38.2.
🎖@cveNotify
GitHub
Release n8n@2.37.7 · n8n-io/n8n
2.37.7 (2026-09-02)
🚨 CVE-2026-86669
A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
GitHub
GitHub - aircheng-org/iWebShop-5: iWebShop是一款基于PHP语言及MYSQL数据库开发的B2B2C多用户商城系统,支持自营和多商家入驻、集成微信商城、手机商城、移动端APP商城、三级分销、电商直播、微信小程序,它…
iWebShop是一款基于PHP语言及MYSQL数据库开发的B2B2C多用户商城系统,支持自营和多商家入驻、集成微信商城、手机商城、移动端APP商城、三级分销、电商直播、微信小程序,它可以承载大数据量且性能优良,代码支持二次开发是电商建站首选。 - aircheng-org/iWebShop-5
🚨 CVE-2026-86670
A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
GitHub
GitHub - aircheng-org/iWebShop-5: iWebShop是一款基于PHP语言及MYSQL数据库开发的B2B2C多用户商城系统,支持自营和多商家入驻、集成微信商城、手机商城、移动端APP商城、三级分销、电商直播、微信小程序,它…
iWebShop是一款基于PHP语言及MYSQL数据库开发的B2B2C多用户商城系统,支持自营和多商家入驻、集成微信商城、手机商城、移动端APP商城、三级分销、电商直播、微信小程序,它可以承载大数据量且性能优良,代码支持二次开发是电商建站首选。 - aircheng-org/iWebShop-5