CVE Notify
19.6K subscribers
4 photos
338K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-82326
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes.

This issue affects Enocta Platform: through 2026-09-28.

🎖@cveNotify
🚨 CVE-2026-82928
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes.


This issue was fixed in version 3.0.30

🎖@cveNotify
🚨 CVE-2026-82929
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception.
This issue was fixed in version 3.0.30

🎖@cveNotify
🚨 CVE-2026-82932
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.


This issue was fixed in version 3.0.30

🎖@cveNotify
🚨 CVE-2026-82933
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions.


This issue was fixed in version 3.0.30

🎖@cveNotify
🚨 CVE-2026-82935
mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial of service on the device.
Vulnerable components were updated or hardened, if update was not possible in version 3.0.30

🎖@cveNotify
🚨 CVE-2026-82936
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack.


This issue was fixed in version 3.0.30

🎖@cveNotify
🚨 CVE-2026-86330
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.

🎖@cveNotify
🚨 CVE-2026-16481
A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox.

The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport automatically attaches an Authorization: Bearer header to every outbound request regardless of the destination host. An attacker can supply an arbitrary external URL to the pageURL parameter (either directly via the tool execution payload or implicitly via data-driven pagination tracking loops), leading Toolbox into sending its OAuth/service-account access token to an attacker-controlled listener. Depending on the configuration, this leaks either the end-user's token or the broader service-account access token (ADC), potentially exposing Protected Health Information (PHI) and secondary Google Cloud Platform services.

🎖@cveNotify
🚨 CVE-2026-69480
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-69481
Heap-based buffer overflow in Windows Enterprise App Management allows an authorized attacker to elevate privileges over a network.

🎖@cveNotify
🚨 CVE-2026-69482
Creation of temporary file in directory with insecure permissions in Windows Error Reporting allows an authorized attacker to perform tampering locally.

🎖@cveNotify
🚨 CVE-2026-69488
Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-69492
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-69493
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-69494
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-69495
Heap-based buffer overflow in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

🎖@cveNotify
🚨 CVE-2026-76674
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

🎖@cveNotify
🚨 CVE-2026-76675
A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.

🎖@cveNotify
🚨 CVE-2026-76676
Buffer overflow vulnerabilities exist in the underlying operating system of EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to execute arbitrary code if certain preconditions outside of the attacker's control are met. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system leading to complete system compromise.

🎖@cveNotify
🚨 CVE-2026-76677
A privilege escalation vulnerability exists in the API of EdgeConnect SD-WAN Gateways. Successful exploitation could allow a remote low-privileged authenticated user to achieve administrative privilege on the web-management interface leading to complete system compromise.

🎖@cveNotify