CVE Notify
19.7K subscribers
4 photos
295K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-70583
Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-70585
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an authorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-71328
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-71332
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-71333
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-71334
Heap-based buffer overflow in Windows NFS Portmapper allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-71339
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-71340
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-66302
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-69646
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

🎖@cveNotify
🚨 CVE-2025-3271
Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS

🎖@cveNotify
🚨 CVE-2026-11838
Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System allows Input Data Manipulation.

This issue affects Library Reservation System: before v22.2.

🎖@cveNotify
🚨 CVE-2026-19733
Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Server Side Request Forgery.

This issue affects Library Information and Document Automation Program: before v22.2.

🎖@cveNotify
🚨 CVE-2026-72694
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.

🎖@cveNotify
🚨 CVE-2026-77847
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.

🎖@cveNotify
🚨 CVE-2026-71351
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-71352
Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-71353
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-72927
Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-72929
Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-72930
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.

🎖@cveNotify