π¨ CVE-2026-20334
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20334 are related to issues concerning improper adherence to coding standards that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-710.
π@cveNotify
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20334 are related to issues concerning improper adherence to coding standards that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-710.
π@cveNotify
Cisco
Cisco Security Advisory: Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewallβ¦
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Softwareβ¦
π¨ CVE-2026-76412
A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker to enable the remote diagnostics debugger service.
This vulnerability is due to an error when checking the privilege level of a user who is invoking remote diagnostics. An attacker could exploit this vulnerability by authenticating to the device, either through the web-based management interface or the REST API, and using the remote diagnostics debugger to grant a user elevated privileges. A successful exploit could allow the attacker to elevate privileges to root.
Notes:
To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
The CVSSv3.1 Attack Complexity is High due to the multistage process required to fully exploit this vulnerability.
π@cveNotify
A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker to enable the remote diagnostics debugger service.
This vulnerability is due to an error when checking the privilege level of a user who is invoking remote diagnostics. An attacker could exploit this vulnerability by authenticating to the device, either through the web-based management interface or the REST API, and using the remote diagnostics debugger to grant a user elevated privileges. A successful exploit could allow the attacker to elevate privileges to root.
Notes:
To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
The CVSSv3.1 Attack Complexity is High due to the multistage process required to fully exploit this vulnerability.
π@cveNotify
Cisco
Cisco Security Advisory: Cisco Secure Firewall Management Center Software Vulnerabilities
Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access and perform session forgery or session impersonation.
For more information about these vulnerabilities, see the Details sectionβ¦
For more information about these vulnerabilities, see the Details sectionβ¦
π¨ CVE-2026-76424
A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device.
This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path. A successful exploit could allow the attacker to upload files to arbitrary locations and execute arbitrary commands as root on the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
π@cveNotify
A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device.
This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path. A successful exploit could allow the attacker to upload files to arbitrary locations and execute arbitrary commands as root on the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
π@cveNotify
Cisco
Cisco Security Advisory: Cisco Identity Services Engine Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XMLβ¦
π¨ CVE-2026-76460
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.
This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
π@cveNotify
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.
This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
π@cveNotify
Cisco
Cisco Security Advisory: Cisco Identity Services Engine Authentication Bypass Vulnerability
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.
This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit thisβ¦
This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit thisβ¦
π¨ CVE-2026-50603
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.
π@cveNotify
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected information or perform unauthorized actions.
π@cveNotify
Acer Community
Security Advisory: Hard-coded encryption key vulnerability in Acer Agent Service for NitroSense and PredatorSense (CVE-2026-50603)β¦
Vulnerability Details A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstancesβ¦
π¨ CVE-2026-86311
The Photo Gallery by 10Web β Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
π@cveNotify
The Photo Gallery by 10Web β Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
π@cveNotify
π¨ CVE-2026-92839
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the userβs session.
π@cveNotify
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the userβs session.
π@cveNotify
Canva
Canva Trust & Security Portal | Powered by SafeBase
See how Canva manages their security program with SafeBase.
π¨ CVE-2025-59607
Memory Corruption when copying large input data exceeds normal allocation limits.
π@cveNotify
Memory Corruption when copying large input data exceeds normal allocation limits.
π@cveNotify
π¨ CVE-2026-24073
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
π@cveNotify
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
π@cveNotify
π¨ CVE-2026-24074
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
π@cveNotify
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
π@cveNotify
π¨ CVE-2026-24075
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
π@cveNotify
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
π@cveNotify
π¨ CVE-2026-24081
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
π@cveNotify
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
π@cveNotify
π¨ CVE-2026-25275
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
π@cveNotify
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
π@cveNotify
π¨ CVE-2026-25278
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
π@cveNotify
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
π@cveNotify
π¨ CVE-2026-25280
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
π@cveNotify
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
π@cveNotify
π¨ CVE-2026-25281
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
π@cveNotify
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
π@cveNotify
π¨ CVE-2026-25282
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
π@cveNotify
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
π@cveNotify
π¨ CVE-2026-25283
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
π@cveNotify
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
π@cveNotify
π¨ CVE-2026-25284
Information Disclosure when a pointer is reused after being deallocated.
π@cveNotify
Information Disclosure when a pointer is reused after being deallocated.
π@cveNotify
π¨ CVE-2026-25290
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
π@cveNotify
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
π@cveNotify