🚨 CVE-2026-48707
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP address blacklist check. This allows authenticated users to scan and access internal network services. Version 2.18.2 contains a fix.
🎖@cveNotify
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Server-Side Request Forgery (SSRF) vulnerability in the file upload functionality (`system/core/uploader.php` at lines 509-532). When the "upload from URL" feature follows an HTTP redirect, the redirected target URL bypasses the private IP address blacklist check. This allows authenticated users to scan and access internal network services. Version 2.18.2 contains a fix.
🎖@cveNotify
GitHub
Fix SSRF redirect/DNS rebinding · instantsoft/icms2@04b8fe0
Self-hosted Site Management System. Contribute to instantsoft/icms2 development by creating an account on GitHub.
🚨 CVE-2026-54611
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.
🎖@cveNotify
InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possible to upload a malicious component into the server, however, it won't be installed, but upload files will be executed. Normally all php files in upload folder are not executed, however, by uploading custom .htaccess it becomes possible. Version 2.18.2 contains a fix.
🎖@cveNotify
GitHub
Установка дополнений через временную директорию; отсутствует возможно… · instantsoft/icms2@44f3a9d
…сть доступа к распакованным файлам по URL; защита от Zip Slip; проверка и запрет символических ссылок (symlink) в ZIP-архивах; защита от Zip Bomb (лимит количества файлов, размера архива и размера...
🚨 CVE-2026-57098
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-57099
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
🎖@cveNotify
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
🎖@cveNotify
🚨 CVE-2026-62762
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
🎖@cveNotify
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
🎖@cveNotify
🚨 CVE-2026-67376
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
🎖@cveNotify
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
🎖@cveNotify
🚨 CVE-2026-67383
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-67386
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-67389
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-67629
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-67630
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-67641
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
🎖@cveNotify
Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network.
🎖@cveNotify
🚨 CVE-2026-67648
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-68777
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-68778
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-68779
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-68780
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-68784
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-68830
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
🎖@cveNotify
Improper link resolution before file access ('link following') in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2026-68843
Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally.
🎖@cveNotify
Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally.
🎖@cveNotify
🚨 CVE-2026-68849
Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally.
🎖@cveNotify
Out-of-bounds read in Windows Bluetooth Port Driver allows an authorized attacker to disclose information locally.
🎖@cveNotify