CVE Notify
19.6K subscribers
4 photos
340K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2026-58004
Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers.

This issue affects Trusted Firmware: through socfpga_v2.14.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-58005
Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers.

This issue affects Trusted Firmware: through socfpga_v2.14.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-58006
Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections.

This issue affects Trusted Firmware: through socfpga_v2.14.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-58007
Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections.

This issue affects Trusted Firmware: through socfpga_v2.14.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-58008
Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections.

This issue affects Trusted Firmware: through socfpga_v2.14.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-65422
A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback privileges to generate video thumbnails.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-6544
IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-77703
Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM).

This issue affects Liman Render Engine: from 1.0 before 1.2-75.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-77825
IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint (`GET /v1/admin/logs/file`). The path confinement check uses `str.startswith()` rather than proper boundary validation, allowing an authenticated admin to read `.log`, `.jsonl`, and `.json` files outside the configured `LOG_FOLDER` by supplying a filename that resolves into a sibling directory whose absolute path shares the log directory's string prefix.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-77874
IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection. A remote unauthenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81539
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81545
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81547
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81548
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81549
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81552
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of environment variables.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-82093
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to unsafe deserialization of untrusted data.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-82094
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-79758
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0 until 2.5.1, authenticated Termix users can access the server-stats API without per-host authorization. GET /status returns statuses for hosts the requester cannot access, GET /status/:id accepts an attacker-supplied numeric host identifier, and POST /clear-connections permits a regular user to clear the global SSH connection pool. The affected src/backend/ssh/server-stats.ts routes expose host online or offline state and lastChecked timestamps and can disrupt other users' active sessions or pooled connections. Unauthenticated requests remain blocked, but authentication alone does not preserve tenant isolation. This issue is fixed in version 2.5.1.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-92680
Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the Windows registry and does not apply sufficient cryptographic protection. An authenticated, non-administrative attacker could retrieve and unencrypt all credentials the target user has stored in Merge.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-79763
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0 until 2.5.1, the POST /users/totp/disable and POST /users/totp/backup-codes endpoints accept the account password as the sole reauthentication factor after a 2.4.0 refactor regressed the two-factor check introduced for CVE-2026-45749. In src/backend/database/routes/user-totp-routes.ts, verifyTotpReauth returns success when bcrypt.compare validates the password, while each endpoint chooses password or totp_code as an interchangeable credential. An attacker who has a victim's authenticated session and knows the password can disable TOTP or regenerate and invalidate backup codes without an authenticator or valid second factor, weakening the account to single-factor authentication. This issue is fixed in version 2.5.1.

๐ŸŽ–@cveNotify