π¨ CVE-2026-100821
Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
π@cveNotify
Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2071784. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-100822
Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2051115. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-100823
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
π@cveNotify
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 157.
π@cveNotify
bugzilla.mozilla.org
2054384 - (CVE-2026-100823) Download completion notification truncates long filenames from the end, hiding the file extension
RESOLVED (giorga) in Firefox for Android - Downloads. Last updated 2026-09-26.
π¨ CVE-2026-100824
Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2054767. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-100825
Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2057465. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-100826
Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2059222. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-100828
Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2066019. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-100829
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2066321. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-100830
Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2066770. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-100831
Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2067172. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.
π¨ CVE-2026-101267
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
π@cveNotify
A missing permission check allowed low-privileged users with access to an event but without access to the event's orders to extract some specific information. This information includes the number of attendees and the total revenue.
π@cveNotify
π¨ CVE-2026-101268
If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page.
π@cveNotify
If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's customer account. If the victim does not notice this, this might lead to their order details being stored into the attacker's account. The attack only works when the event is available on a different domain than the organizer page.
π@cveNotify
π¨ CVE-2026-101269
The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless.
π@cveNotify
The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless.
π@cveNotify
π¨ CVE-2026-101270
Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
π@cveNotify
Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
π@cveNotify
π¨ CVE-2026-101271
OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
π@cveNotify
OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) they are bound to is manually disabled.
π@cveNotify
π¨ CVE-2026-102437
OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.
π@cveNotify
OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.
π@cveNotify
GitHub
GitHub - esengine/DeepSeek-Reasonix: DeepSeek-native AI coding agent for your terminal. Engineered around prefix-cache stabilityβ¦
DeepSeek-native AI coding agent for your terminal. Engineered around prefix-cache stability β leave it running. - esengine/DeepSeek-Reasonix
π¨ CVE-2026-76875
PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.
π@cveNotify
PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityParserCreate function that allows attackers to corrupt memory by supplying a crafted XML document to applications that create external-entity sub-parsers without retaining a reference to the parent parser. The child parser retains a raw C back-pointer to the parent parser struct while PyPy's tracing garbage collector can free the parent's C struct, causing bundled libexpat to dereference the freed pointer on every parsed token, producing memory corruption.
π@cveNotify
π¨ CVE-2026-7192
A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a system reboot via a manipulated HTTP POST request directed at the endpoint β/js/common/do_cmd.jsβ endpoint containing an excessively long parameter, which overwrites the PC and RA registers.
π@cveNotify
A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to cause a denial of service (DoS) and a system reboot via a manipulated HTTP POST request directed at the endpoint β/js/common/do_cmd.jsβ endpoint containing an excessively long parameter, which overwrites the PC and RA registers.
π@cveNotify
www.incibe.es
Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment
INCIBE has coordinated the publication of two vulnerabilities β one of critical severity and one of hi
π¨ CVE-2026-7193
A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attacker connected to the same network to gain full root access to the device via the Telnet service (port 23) using static credentials.
π@cveNotify
A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attacker connected to the same network to gain full root access to the device via the Telnet service (port 23) using static credentials.
π@cveNotify
www.incibe.es
Multiple vulnerabilities in the T-CPE301K 4G Mini WiFi Router from Shenzhen Dbit Network Equipment
INCIBE has coordinated the publication of two vulnerabilities β one of critical severity and one of hi
π¨ CVE-2026-82973
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.
π@cveNotify
Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a remote unauthenticated attacker, when bearer-token authentication is not configured, to inject additional IMAP commands into an authenticated upstream mailbox connection via crafted folder, UID, or search values.
π@cveNotify
GitLab
v0.4.13: fix IMAP command injection in folder/uid/search (issue #1) (90e6b492) Β· Commits Β· Ciprian Mandache / docker-mailbox Β·β¦
The folder, uid and search values reaching the IMAP client were string-interpolated into IMAP commands and handed to imaplib, which does not sanitize arguments; a CR/LF (from a %0D%0A in...
π¨ CVE-2026-96869
Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
π@cveNotify
Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
π@cveNotify
bugzilla.mozilla.org
Access Denied
You are not authorized to access bug 2041248. To see this bug, you must
first log in to an account with the appropriate permissions.
first log in to an account with the appropriate permissions.