CVE Notify
19.7K subscribers
4 photos
297K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-71339
Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-71340
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-66302
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-69646
Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.

🎖@cveNotify
🚨 CVE-2025-3271
Documentum Webtop versions prior to 16.7.1 software is vulnerable to an XSS

🎖@cveNotify
🚨 CVE-2026-11838
Missing authentication for critical function vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Reservation System allows Input Data Manipulation.

This issue affects Library Reservation System: before v22.2.

🎖@cveNotify
🚨 CVE-2026-19733
Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Server Side Request Forgery.

This issue affects Library Information and Document Automation Program: before v22.2.

🎖@cveNotify
🚨 CVE-2026-72694
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.

🎖@cveNotify
🚨 CVE-2026-77847
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.

🎖@cveNotify
🚨 CVE-2026-71351
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-71352
Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-71353
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-72927
Heap-based buffer overflow in Winsock allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-72929
Improper validation of integrity check value in Windows Installer allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-72930
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-72933
Heap-based buffer overflow in Microsoft WDAC OLE DB provider for SQL allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-72935
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-72936
Use after free in Windows SMB Client allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-72943
Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-72944
Heap-based buffer overflow in Windows Fax Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-72950
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

🎖@cveNotify