CVE Notify
19.6K subscribers
4 photos
338K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2026-103050
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - MassMessage extension allows Stored XSS.

This issue affects Mediawiki - MassMessage extension: before 1.46.1, 1.45.5, 1.43.10.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-103051
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS.

This issue affects Mediawiki - CentralNotice extension: before 1.46.1, 1.45.5, 1.43.10.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-13046
A deserialization of untrusted data vulnerability in WatchGuard Fireware OS's SAML single sign-on session handling (samld) allows an attacker who has already obtained the ability to write files on the appliance to execute arbitrary code in the context of the samld service by causing samld to load a maliciously crafted session file.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-13224
A path traversal vulnerability in the Fireware OS WebUI management agent allows an authenticated administrator to read or list arbitrary files on the local filesystem by sending a specially crafted management request.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18105
An uncontrolled resource consumption vulnerability in Fireware OS's diagnostic tasks feature allows a low-privileged, authenticated user to cause a denial of service of the system's diagnostic tools by repeatedly starting and aborting a specially crafted diagnostic task through the web UI.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-18145
A stack-based buffer overflow vulnerability in the spamBlocker (spamd) service of WatchGuard Fireware OS allows an authenticated attacker with administrator privileges to crash the service or potentially execute arbitrary code by sending a specially crafted management request.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-81433
A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted DHCP packet.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-86101
An improper authorization vulnerability in WatchGuard Fireware OS's SAML login process allows a remote, authenticated SAML user with access only to the Access Portal to obtain unauthorized Mobile VPN with SSL access through a specially crafted request.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-86104
An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-86105
An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a different resource which they are authorized to access.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-86128
A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-86131
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-86132
An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-86133
An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a denial of service.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-86136
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-90441
A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitrary files accessible to the daemon by submitting a specially crafted management API request.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-100303
TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes and categories. Authenticated non-admin users can add, modify, or delete themes and theme categories affecting forms owned by other users.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-48482
GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form import with a crafted illustration or scene identifier that traverses outside the intended custom-asset directory. The imported file can be written to an executable server location, allowing a malicious script to be invoked remotely. This issue is fixed in version 11.0.8.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-53626
GLPI is a free asset and IT management software package. From 11.0.5 until 11.0.8, under certain conditions, permission logic can grant access to a document without confirming that the document is linked to the targeted item. A user can use an unrelated item that the user is permitted to view to read a document linked to an inaccessible item. This issue is fixed in version 11.0.8.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-53628
GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable two-factor authentication for user accounts outside the administrator's entity scope. The affected user-account administration flow did not consistently enforce the target user's entity-scoped update permission. This issue is fixed in versions 11.0.8 and 10.0.26.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-97896
A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Functionality. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. Upgrading to version 2.2.6 is able to resolve this issue. The identifier of the patch is b9836530ec9f5ef0f51653bb0cbbc47ef7184f51. It is advisable to upgrade the affected component.

๐ŸŽ–@cveNotify