CVE Notify
19.7K subscribers
4 photos
299K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-83986
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-83987
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-83988
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-83989
Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.

🎖@cveNotify
🚨 CVE-2026-83990
Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-83991
Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.

🎖@cveNotify
🚨 CVE-2026-83992
Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-83995
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-83996
Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-83997
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-83998
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-83999
Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-84000
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-84003
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

🎖@cveNotify
🚨 CVE-2026-85360
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-85875
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-85877
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-85880
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-86074
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-controlled fetched content could influence that URL after a user injected it into the setup flow, causing authenticated requests, redirects, or probes to reach another origin. The affected logic includes packages/@n8n/instance-ai/src/tools/workflows/credential-utils.ts and the extractServiceOrigin origin derivation. This issue is fixed in versions 2.37.7 and 2.38.2.

🎖@cveNotify
🚨 CVE-2026-86670
A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to password hash with insufficient computational effort. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

🎖@cveNotify