CVE Notify
19.6K subscribers
4 photos
338K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-20334
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20334 are related to issues concerning improper adherence to coding standards that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-710.

πŸŽ–@cveNotify
🚨 CVE-2026-76412
A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker to enable the remote diagnostics debugger service.

This vulnerability is due to an error when checking the privilege level of a user who is invoking remote diagnostics. An attacker could exploit this vulnerability by authenticating to the device, either through the web-based management interface or the REST API, and using the remote diagnostics debugger to grant a user elevated privileges. A successful exploit could allow the attacker to elevate privileges to root.
Notes:

To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
The CVSSv3.1 Attack Complexity is High due to the multistage process required to fully exploit this vulnerability.

πŸŽ–@cveNotify
🚨 CVE-2026-76424
A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device.

This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path. A successful exploit could allow the attacker to upload files to arbitrary locations and execute arbitrary commands as root on the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.

πŸŽ–@cveNotify
🚨 CVE-2026-76460
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.

This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

πŸŽ–@cveNotify
🚨 CVE-2026-50603
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.

πŸŽ–@cveNotify
🚨 CVE-2026-86311
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

πŸŽ–@cveNotify
🚨 CVE-2026-92839
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.

πŸŽ–@cveNotify
🚨 CVE-2025-59607
Memory Corruption when copying large input data exceeds normal allocation limits.

πŸŽ–@cveNotify
🚨 CVE-2026-24073
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.

πŸŽ–@cveNotify
🚨 CVE-2026-24074
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

πŸŽ–@cveNotify
🚨 CVE-2026-24075
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

πŸŽ–@cveNotify
🚨 CVE-2026-24081
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

πŸŽ–@cveNotify
🚨 CVE-2026-25261
Memory corruption while processing rear sensor IOCTL calls.

πŸŽ–@cveNotify
🚨 CVE-2026-25275
Transient DOS when processing authentication frames with invalid FILS information element header lengths.

πŸŽ–@cveNotify
🚨 CVE-2026-25278
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.

πŸŽ–@cveNotify
🚨 CVE-2026-25280
Memory corruption when processing escape handling flow with insufficient user buffer sizes.

πŸŽ–@cveNotify
🚨 CVE-2026-25281
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.

πŸŽ–@cveNotify
🚨 CVE-2026-25282
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

πŸŽ–@cveNotify
🚨 CVE-2026-25283
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

πŸŽ–@cveNotify
🚨 CVE-2026-25284
Information Disclosure when a pointer is reused after being deallocated.

πŸŽ–@cveNotify
🚨 CVE-2026-25290
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

πŸŽ–@cveNotify