Skip to content
CVE

Vulnerabilities (CVE)

Actively exploited or maximum-severity vulnerabilities.

Actively exploitedCVSS 7.4

CVE-2026-18556Authentication bypass in N-able N-central

n-able:n-central
CyberSecurityCloudLinuxWindowsBackend

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

Analysis

N-able N-central permite omitir la autenticación a través de una ruta alternativa, otorgando acceso no autorizado a la consola de administración. Esta vulnerabilidad está siendo explotada activamente, lo que pone en riesgo la seguridad de todos los dispositivos gestionados. Es crucial aplicar las actualizaciones de seguridad para mitigar el riesgo de intrusión en la infraestructura.

Added to KEV: 2026-08-04View details
Actively exploitedCVSS 9.8

CVE-2026-9198Unauthenticated RCE in Langflow

langflow:langflow
PythonBackendIADataScienceMachineLearningDocker

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

Analysis

Langflow permite a atacantes no autenticados obtener privilegios de superusuario y ejecutar código arbitrario en el servidor. Esta vulnerabilidad está siendo explotada activamente y afecta a despliegues por defecto, comprometiendo totalmente el entorno donde se ejecutan tus flujos de IA.

Added to KEV: 2026-08-04View details
Actively exploitedCVSS 7.5EPSS 0.43

CVE-2026-34486Encryption bypass in Apache Tomcat

apache:tomcatredhat:jboss_web_serverredhat:enterprise_linuxredhat:enterprise_linux_els+3
JavaBackendCloudCyberSecurityLinuxDocker

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Analysis

Apache Tomcat presenta una vulnerabilidad que permite omitir el EncryptInterceptor, dejando datos sensibles sin cifrar durante su transmisión. Esta falla está siendo explotada activamente en ataques reales según el catálogo KEV de CISA. Se recomienda actualizar inmediatamente a las versiones 11.0.21, 10.1.54 o 9.0.117 para proteger la integridad de la información.

Added to KEV: 2026-08-04View details
Actively exploitedCVSS 8.1

CVE-2026-18577Authentication Bypass in N-able N-central

n-able:n-central
CyberSecurityCloudLinuxWindowsBackend

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-20…

Analysis

N-able N-central permite la omisión de autenticación y la toma de control de cuentas debido a un parche incompleto de una vulnerabilidad previa. El fallo está siendo explotado activamente en ataques reales para comprometer herramientas de gestión remota de infraestructura. Es fundamental actualizar a versiones superiores a la 2026.3.1 para mitigar el riesgo de acceso no autorizado.

Added to KEV: 2026-08-03View details
Actively exploitedCVSS 5.3

CVE-2026-20316Hard-coded credentials in Cisco Secure Firewall Management Center

cisco:secure_firewall_management_center
CyberSecurityCloudLinuxBackend

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affecte…

Analysis

Cisco Secure Firewall Management Center (FMC) presenta una vulnerabilidad de credenciales estáticas que permite a atacantes remotos no autenticados acceder al sistema y extraer datos sensibles. Esta falla se encuentra en la lista KEV de CISA por estar siendo explotada activamente en entornos reales. Se recomienda restringir el acceso a la interfaz de administración y actualizar el software inmediatamente.

Added to KEV: 2026-07-29View details
Actively exploitedCVSS 10.0

CVE-2026-16812Command injection in VeloCloud Orchestrator On-Prem

arista:velocloud_orchestrator
CyberSecurityCloudBackendLinux

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compr…

Analysis

VeloCloud Orchestrator On-Prem presenta una vulnerabilidad de inyección de comandos que permite a atacantes remotos ejecutar código y acceder a funciones internas privilegiadas. Esta falla está siendo explotada activamente y puede comprometer totalmente el orquestador y los datos que gestiona. Es imperativo actualizar las instalaciones locales para evitar el compromiso del host y la infraestructura de red gestionada.

Added to KEV: 2026-07-27View details
Actively exploitedCVSS 5.9

CVE-2025-68686Fortinet FortiOS Patch Bypass via Symbolic Link Persistency

fortinet:fortios
CyberSecurityCloudLinux

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mech…

Analysis

Esta vulnerabilidad en Fortinet FortiOS permite a un atacante remoto no autenticado evadir los parches de seguridad para persistencia mediante enlaces simbolicos. El fallo esta siendo explotado activamente en ataques reales y requiere que el sistema haya sido comprometido previamente a nivel de sistema de archivos. Es fundamental que quienes administran infraestructura de red actualicen sus firewalls para evitar que atacantes mantengan acceso persistente.

Added to KEV: 2026-07-27View details
Actively exploitedCVSS 9.1EPSS 0.71

CVE-2026-16232Authentication bypass in Check Point SmartConsole

checkpoint:multi-domain_security_managementcheckpoint:quantum_security_management
CyberSecurityCloudBackendLinux

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative pri…

Analysis

Una vulnerabilidad de bypass de autenticación en Check Point SmartConsole permite a un atacante remoto obtener privilegios administrativos completos sin necesidad de credenciales. Esto facilita la modificación de políticas de seguridad y configuraciones críticas del servidor de gestión. Esta vulnerabilidad está siendo explotada activamente en entornos reales según los reportes de CISA.

Added to KEV: 2026-07-22View details
Actively exploitedCVSS 9.8EPSS 0.76

CVE-2026-50522Remote Code Execution in Microsoft SharePoint

microsoft:sharepoint_server
WindowsCyberSecurityBackendCloud

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

Analysis

A critical deserialization vulnerability in Microsoft SharePoint allows unauthenticated attackers to execute arbitrary code remotely. Although the CVSS is 9.8, this primarily affects enterprise internal infrastructure rather than common developer stacks or web application frameworks.

Added to KEV: 2026-07-22View details
CVSS 10.0CVSS 10.0

CVE-2026-48331SSRF Privilege Escalation in Adobe Campaign Classic

BackendCyberSecurityCloud

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

Analysis

Adobe Campaign Classic presenta una vulnerabilidad crítica de SSRF que permite el escalamiento de privilegios sin interacción del usuario. Los atacantes pueden explotar este fallo para realizar peticiones no autorizadas y acceder a recursos internos de la infraestructura o servicios protegidos.

8/3/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-48330SQL Injection in Adobe Campaign Classic

BackendSqlCyberSecurity

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the curren…

Analysis

Adobe Campaign Classic presenta una vulnerabilidad crítica de inyección SQL que permite la ejecución de código arbitrario sin requerir interacción del usuario. Un atacante puede ejecutar comandos SQL para obtener acceso elevado o control total sobre la infraestructura de la aplicación. Al tener el puntaje máximo de severidad (CVSS 10.0), requiere atención inmediata por parte de los equipos que operan esta plataforma.

8/3/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-48323RCE in Adobe Campaign Classic via Template Injection

BackendJavaCloudSqlCyberSecurity

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An atta…

Analysis

Adobe Campaign Classic presenta una vulnerabilidad crítica de inyección en su motor de plantillas que permite la ejecución arbitraria de código. Un atacante puede explotar este fallo de forma remota y sin interacción del usuario para comprometer totalmente el servidor backend. Dada su puntuación de 10.0, es imperativo actualizar las instancias afectadas de inmediato.

8/3/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-69085Critical SQL Injection in SiYuan allows notebook modification

BackendSqlCyberSecurityDockerJavascriptLinux

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenated directly into SQL statements with no escaping or parameter…

Analysis

SiYuan presenta una vulnerabilidad de inyección SQL crítica en su API de búsqueda que permite a atacantes remotos leer o modificar el contenido de todas las libretas sin cifrar. Debido al uso de sentencias apiladas, un atacante puede comprometer la base de datos completa incluso sin estar autenticado si el modo de publicación está activo. Se recomienda actualizar inmediatamente a la versión 3.7.3 para evitar la pérdida o manipulación de información técnica y personal.

8/3/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-69084SQL Injection in SiYuan allows data manipulation

SqlBackendCyberSecurity

SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-write siyuan.db handle with no single-statement, read-only, or admin rest…

Analysis

SiYuan expone un endpoint que permite la ejecución de sentencias SQL arbitrarias directamente en su base de datos principal. Un atacante puede leer o modificar el contenido de todas las libretas de notas no cifradas de forma remota y sin necesidad de privilegios elevados. Es imperativo actualizar a la versión 3.7.3 para evitar la pérdida o alteración de información.

8/3/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-69083Unauthenticated SQL Injection in SiYuan

BackendSqlCyberSecurity

SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and publish RoleReader tokens. Attackers can execute arbitrary SQL on the…

Analysis

Una vulnerabilidad de inyección SQL en el endpoint de búsqueda de SiYuan permite a atacantes no autenticados leer, modificar o borrar datos de todos los notebooks. El fallo se debe a parámetros no saneados que permiten la ejecución de comandos SQL arbitrarios en la base de datos de activos. Es fundamental actualizar a la versión 3.7.3 para proteger la integridad y privacidad de la información almacenada.

8/3/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-67308Shell Injection in Wazuh GitHub Actions Workflows

CyberSecurityCloudBackend

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inje…

Analysis

Los flujos de trabajo de Wazuh son vulnerables a una inyección de shell en GitHub Actions al procesar archivos VERSION.json maliciosos en pull requests. Un atacante puede ejecutar comandos arbitrarios en los runners y extraer secretos sensibles como GITHUB_TOKEN y credenciales de AWS.

8/1/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-18452Hard-coded API key in Rich Source DMS+

HardwareCyberSecurityBackend

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.

Analysis

DMS+ (Non-Mobile) de Rich Source contiene una vulnerabilidad de credenciales embebidas que permite a atacantes remotos no autenticados tomar control total de los dispositivos afectados mediante una llave de API fija. Debido a que la clave es estática y universal para todas las instalaciones, cualquier sistema expuesto puede ser comprometido de forma administrativa sin conocimiento previo.

7/31/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-66803RCE via Improper Access Control in Azure Cosmos DB

microsoft:azure_cosmos_db
CloudBackendNosqlCyberSecurity

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

Analysis

Una vulnerabilidad crítica de control de acceso en Azure Cosmos DB permite a un atacante no autorizado ejecutar código de forma remota a través de la red. Este fallo afecta directamente a las aplicaciones que utilizan este motor NoSQL en la nube, comprometiendo la seguridad del backend y la integridad del entorno de ejecución.

7/30/2026View details
AI-recommendedCVSS 9.3widely_deployed_infra

CVE-2026-47876Guest-to-Host VM Escape (RCE) in VMware ESXi

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploi…

Analysis

Vulnerabilidad de escape de maquina virtual en VMware ESXi que permite a un atacante con privilegios de administrador en una VM ejecutar codigo en el host fisico. Afecta al adaptador de red VMXNET3 y compromete la integridad de todo el hipervisor.

7/30/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-48449Arbitrary code execution in Adobe Campaign Classic

BackendSqlCyberSecurityCloud

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user inte…

Analysis

Adobe Campaign Classic presenta una vulnerabilidad de autorizacion incorrecta que permite la ejecucion remota de codigo arbitrario sin requerir interaccion del usuario. Un atacante puede tomar control del proceso con los privilegios de la aplicacion, comprometiendo la integridad del servidor de marketing y sus bases de datos asociadas. Se recomienda actualizar inmediatamente debido a que el fallo posee la calificacion de severidad maxima.

7/30/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-67429Arbitrary file write in Flyto2 Core

IABackendPythonCyberSecurityMachineLearningLinux

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its…

Analysis

Flyto2 Core permite la escritura de archivos arbitrarios en el sistema al omitir las restricciones del sandbox en sus módulos de descarga y automatización. Un atacante puede controlar la ruta de salida para sobrescribir archivos críticos del servidor o inyectar código malicioso en cualquier ubicación accesible por el proceso.

7/29/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-16326Session token exposure in consul-mcp-server

BackendCloudCyberSecurityGoKubernetesDocker

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. T…

Analysis

Consul-mcp-server no logra aislar correctamente el estado de las sesiones, permitiendo que el token de autenticación de un cliente sea reutilizado por otros de forma involuntaria. Esta vulnerabilidad en el modo stateless permite el acceso no autorizado a recursos protegidos de Consul mediante el secuestro de credenciales entre peticiones.

7/29/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-54735SSRF in Prebid Server allows access to internal services

BackendCyberSecurityCloudGoJava

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound reques…

Analysis

Prebid Server es vulnerable a ataques de falsificación de solicitudes del lado del servidor (SSRF) debido a una validación insuficiente en los parámetros de los adaptadores de postores. Un atacante puede manipular estos parámetros para forzar al servidor a realizar peticiones a destinos no deseados, exponiendo potencialmente servicios internos o endpoints sensibles en tu red privada. Se recomienda actualizar a la versión 4.4.0 para corregir esta vulnerabilidad de severidad crítica.

7/29/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-58162Arbitrary certificate generation in Apache Traffic Server

apache:traffic_server
BackendCloudCyberSecurityDockerKubernetesLinux

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 throu…

Analysis

El plugin certifier de Apache Traffic Server permite la generacion de certificados digitales basados en el SNI controlado por un atacante. Este fallo de validacion permite comprometer la integridad de las comunicaciones TLS y suplantar identidades en la infraestructura de red. Se recomienda actualizar inmediatamente a las versiones 9.2.15 o 10.1.4.

7/29/2026View details
AI-recommendedCVSS 9.3widely_deployed_infra

CVE-2026-58155Critical Request Smuggling in Apache Traffic Server

BackendCyberSecurityCloudKubernetesDockerLinux

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from…

Analysis

Apache Traffic Server (ATS) is vulnerable to critical request smuggling and policy bypass. Attackers can exploit improper header name truncation to bypass security filters or alias headers, potentially compromising the integrity of backend communications.

7/29/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-58150Request Smuggling in Apache Traffic Server

BackendCyberSecurityCloudLinuxDockerKubernetes

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.…

Analysis

Apache Traffic Server es vulnerable a Request Smuggling debido a un manejo incorrecto de la cabecera Transfer-Encoding en conexiones HTTP/2. Un atacante puede explotar este fallo para eludir firewalls de aplicaciones web, envenenar la caché del servidor o interceptar sesiones de usuarios legítimos. Es imperativo actualizar a las versiones 9.2.15 o 10.1.4 para mitigar este riesgo crítico con severidad máxima.

7/29/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-57834Request Smuggling in Apache Traffic Server

BackendCloudCyberSecurityLinuxDockerKubernetes

Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are rec…

Analysis

Apache Traffic Server permite ataques de Request Smuggling debido al manejo incorrecto de mensajes con codificación chunked. Un atacante puede manipular peticiones para evadir controles de seguridad o envenenar el caché del servidor, afectando a otros usuarios. Se recomienda actualizar a las versiones 9.2.15 o 10.1.4.

7/29/2026View details
AI-recommendedCVSS 9.3widely_deployed_infra

CVE-2026-41920Improper Access Control in Apache Traffic Server

BackendCyberSecurityCloudLinuxDocker

Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.1.15 or 10.…

Analysis

A critical access control vulnerability in Apache Traffic Server could allow attackers to bypass security restrictions on your edge proxy or cache. If you use ATS as a reverse proxy or CDN component, upgrade to version 9.1.15 or 10.1.4 immediately.

7/29/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-33267Remote Code Execution in Apache Traffic Server

BackendCloudLinuxCyberSecurity

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 1…

Analysis

Apache Traffic Server presenta una vulnerabilidad crítica de validación de entrada que permite a un atacante no autenticado comprometer totalmente el servidor. Este componente se utiliza habitualmente como proxy inverso y caché en infraestructuras de alto tráfico. Es fundamental actualizar a las versiones 9.2.15 o 10.1.4 para evitar posibles ataques de ejecución de código remoto.

7/29/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-16498Token leakage in terraform-mcp-server

CloudBackendIACyberSecurity

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode that may allow one user's Terraform token to be used to execute tool ca…

Analysis

El servidor terraform-mcp-server presenta una vulnerabilidad crítica de reutilización de credenciales entre diferentes usuarios en su modo de transporte HTTP. Un atacante podría obtener y utilizar tokens de Terraform ajenos para ejecutar comandos y modificar infraestructura en nombre de otros usuarios. Se recomienda actualizar inmediatamente a la versión 1.1.0 para mitigar este riesgo.

7/28/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-11756Deserialization RCE in 3DEXPERIENCE Station Launcher

CyberSecurityBackendWindowsJava

A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could lead to an unauthenticated remote code…

Analysis

La aplicación Station Launcher de la plataforma 3DEXPERIENCE permite la ejecución remota de código sin autenticación debido a una vulnerabilidad de deserialización de datos. Un atacante puede comprometer totalmente el sistema de forma remota sin necesidad de credenciales ni interacción previa del usuario. Se recomienda actualizar inmediatamente las instalaciones del ecosistema R2023x a R2026x para mitigar este riesgo crítico.

7/28/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64535Critical UAF in Linux Kernel (NVMe/TCP)

LinuxBackendCloudDockerCyberSecurity

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix potential UAF when ddgst mismatch Shivam Kumar found via vulnerability testing: When data digest is enabled on an NVMe/TCP connection a…

Analysis

Vulnerabilidad de tipo Use-After-Free (UAF) con impacto crítico (CVSS 9.8) en la implementación de NVMe sobre TCP del kernel de Linux. Un atacante remoto podría provocar un fallo del sistema o ejecución de código mediante el envío de paquetes malformados durante transferencias de datos.

7/27/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64534Critical UAF and Deadlock in Linux kernel nvmet-tcp

LinuxBackendCloudCyberSecurityCDocker

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path In nvmet_tcp_try_recv_ddgst(), when a data digest mismatch is detected, nvme…

Analysis

A critical vulnerability in the Linux kernel NVMe-over-TCP target module (nvmet-tcp) allows for a use-after-free condition and system deadlock via network packets. This could lead to remote code execution or persistent denial of service in environments utilizing NVMe storage over fabrics.

7/27/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64530Critical Networking Vulnerability in Linux Kernel

CyberSecurityCloudBackendKubernetesDockerLinux

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation…

Analysis

A critical vulnerability has been identified in the Linux kernel networking subsystem (Traffic Control) involving improper handling of socket buffers. This flaw can lead to a use-after-free condition when processing specifically crafted out-of-order network fragments, potentially allowing for remote exploitation or system crashes.

7/26/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-66012RCE and credential theft in SiYuan via missing authorization

JavascriptTypescriptBackendCyberSecurityLinux

SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This expose…

Analysis

SiYuan versiones anteriores a la v3.7.2 presenta una vulnerabilidad de falta de autorización en el endpoint /mcp cuando el servidor Publish está en modo anónimo. Un atacante remoto no autenticado puede manipular archivos en todo el espacio de trabajo, extraer tokens de acceso y ejecutar código arbitrario mediante la instalación de plugins maliciosos. Este fallo compromete totalmente la integridad y confidencialidad del servidor de notas y gestión de conocimiento.

7/25/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64523Critical vulnerability in Linux Kernel net/handshake

LinuxDockerKubernetesCloudBackendCyberSecurity

In the Linux kernel, the following vulnerability has been resolved: net/handshake: Take a long-lived file reference at submit handshake_nl_accept_doit() needs the file pointer backing req->hr_sk->sk_socket to survive t…

Analysis

A critical vulnerability (CVSS 9.8) has been identified in the Linux kernel's handshake netlink interface. It involves improper management of socket file references, which can lead to use-after-free memory corruption and potentially allow for privilege escalation or system compromise.

7/25/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64459Critical RCE/DoS vulnerability in Linux kernel TCP stack

LinuxBackendCloudKubernetesDockerCyberSecurity

In the Linux kernel, the following vulnerability has been resolved: tcp: restore RCU grace period in tcp_ao_destroy_sock Commit 51e547e8c89c ("tcp: Free TCP-AO/TCP-MD5 info/keys without RCU") removed the call_rcu() cal…

Analysis

A critical vulnerability was found in the Linux kernel TCP stack involving TCP-AO/MD5 key destruction. An attacker could potentially trigger memory corruption or a system crash via network packets, affecting any Linux-based server using these TCP security options.

7/25/2026View details
AI-recommendedCVSS 9.1widely_deployed_infra

CVE-2026-64450Critical Out-of-bounds Read in Linux Kernel TIPC

In the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read in broadcast Gap ACK blocks A broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its data area. tipc_get_g…

Analysis

Vulnerabilidad critica en el protocolo TIPC del kernel de Linux que permite una lectura fuera de limites y corrupcion de memoria. Un atacante podria explotar esto mediante paquetes de red para comprometer la integridad del sistema.

7/25/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64439Use-after-free vulnerability in Linux kernel (krb5)

LinuxBackendCloudKubernetesDockerCyberSecurity

In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - filter out async aead implementations at alloc krb5_aead_encrypt(), krb5_aead_decrypt() in rfc3961_simplified.c and rfc8009_encrypt(),…

Analysis

A critical use-after-free vulnerability has been identified in the Linux kernel Kerberos 5 crypto implementation. The flaw occurs when handling asynchronous encryption, potentially allowing kernel-level memory corruption or exploitation via networked authentication services.

7/25/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64399Remote file overwrite in Linux kernel (ksmbd)

LinuxCyberSecurityBackendCloud

In the Linux kernel, the following vulnerability has been resolved: ksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE The FSCTL_DUPLICATE_EXTENTS_TO_FILE arm of smb2_ioctl() overwrites the destination fi…

Analysis

A vulnerability in the Linux kernel SMB server (ksmbd) allows remote attackers to bypass permission checks and overwrite files, even on shares marked as read-only. This poses a severe risk of data corruption and potential system compromise for environments using in-kernel SMB services.

7/25/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64397Use-After-Free RCE in Linux Kernel ksmbd

LinuxBackendCyberSecurityCloudDockerC

In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_dat…

Analysis

A critical use-after-free vulnerability was identified in the Linux kernel's ksmbd (SMB) module. Attackers can trigger this via concurrent directory queries, potentially leading to remote code execution (RCE) at the kernel level.

7/25/2026View details
AI-recommendedCVSS 9.1widely_deployed_infra

CVE-2026-64393Critical permission bypass in Linux ksmbd

In the Linux kernel, the following vulnerability has been resolved: ksmbd: run set info with opener credentials SMB2 SET_INFO handlers call path-based VFS helpers after checking the access mask granted to the SMB handl…

Analysis

Se ha identificado una vulnerabilidad crítica en el componente ksmbd del kernel de Linux. El fallo permite que las solicitudes SMB2 SET_INFO evadan ciertas verificaciones de permisos al utilizar credenciales incorrectas, lo que podría resultar en un escalamiento de privilegios o acceso no autorizado a archivos.

7/25/2026View details
AI-recommendedCVSS 9.1widely_deployed_infra

CVE-2026-64392Permission bypass in Linux ksmbd during file deletion

LinuxBackendCyberSecurityDockerCloud

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for delete-on-close Delete-on-close can be completed by deferred or durable handle teardown, where no request work is av…

Analysis

A vulnerability in the Linux kernel's ksmbd (SMB server) allows attackers to bypass filesystem permission checks. When a file is marked for deletion on close, the kernel may use internal worker credentials instead of the user's credentials, potentially allowing unauthorized file deletion.

7/25/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64391Critical RCE in Linux kernel SMB server (ksmbd)

LinuxBackendCloudDockerKubernetesCyberSecurity

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use opener credentials for ADS I/O Alternate data streams are stored as xattrs. Unlike regular file I/O, their read and write paths therefore c…

Analysis

A critical vulnerability was found in the Linux kernel SMB server (ksmbd). The flaw involves improper credential handling for Alternate Data Streams, which can lead to unauthorized access or remote code execution on systems running this service.

7/25/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64387Double-free vulnerability in Linux kernel SMB client

LinuxCyberSecurityCloudDockerKubernetesBackend

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_que…

Analysis

A critical double-free vulnerability has been identified in the Linux kernel SMB client. An attacker-controlled SMB server could exploit this during directory query replays to cause memory corruption or potentially execute arbitrary code on the client system.

7/25/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64385Double-free in Linux kernel SMB client

LinuxCyberSecurityCloudBackendDockerC

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioc…

Analysis

A critical double-free vulnerability in the Linux kernel SMB client (SMB2_ioctl) allows for potential memory corruption and system crashes. This affects Linux systems mounting remote SMB shares, posing a risk of remote code execution or privilege escalation.

7/25/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64384Double-free vulnerability in Linux kernel SMB client

LinuxBackendCloudDockerKubernetesC

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notif…

Analysis

A critical double-free vulnerability has been identified in the Linux kernel SMB client. An attacker controlling a malicious SMB server could potentially execute arbitrary code at the kernel level when a Linux system attempts to connect or process change notifications.

7/25/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64355Out-of-bounds access in Linux kernel via XDP

LinuxCloudBackendKubernetesDockerCyberSecurity

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject fragmented frames in devmap Devmap broadcast redirects clone the packet for all but the last destination. For native XDP, that clone path…

Analysis

A critical vulnerability has been identified in the Linux kernel networking stack involving eBPF and XDP. Remote attackers could potentially trigger out-of-bounds memory access by sending crafted fragmented network packets, leading to system instability or kernel-level compromise.

7/25/2026View details
AI-recommendedCVSS 9.1widely_deployed_infra

CVE-2026-64319Critical vulnerability in Linux kernel NVMe-oF target

LinuxBackendCyberSecurityCloudCHardware

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-…

Analysis

A critical vulnerability in the Linux kernel NVMe-over-Fabrics (NVMe-oF) target code allows a remote attacker to trigger out-of-bounds heap reads via crafted authentication messages. This impacts systems acting as NVMe storage targets using DHCHAP authentication, potentially leading to memory corruption or kernel exploitation.

7/25/2026View details
AI-recommendedCVSS 9.8widely_deployed_infra

CVE-2026-64268Critical buffer overflow in Linux kernel (RDMA/siw)

LinuxBackendCloudCyberSecurityC

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Respon…

Analysis

A critical vulnerability in the Linux kernel RDMA Soft-iWARP (siw) driver allows a remote attacker to cause kernel-level memory corruption. By sending crafted network segments, a connected peer can overflow buffers, potentially leading to a full system compromise or a remote crash.

7/25/2026View details
AI-recommendedCVSS 9.1widely_deployed_infra

CVE-2026-64257Critical vulnerability in Linux kernel SMB2 client

LinuxBackendCyberSecurityCloudDockerC

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject overlapping data areas in SMB2 responses Commit 53b7c271f06b ("smb: client: restrict implied bcc[0] exemption to responses without…

Analysis

A critical vulnerability has been identified in the Linux kernel SMB2 client. The flaw allows for the bypass of data length checks when processing crafted responses from a malicious server, which could lead to kernel-level exploitation for systems using CIFS/SMB mounts.

7/25/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-58630Privilege escalation in Azure App Service

CloudBackendCyberSecurity

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

Analysis

Esta vulnerabilidad en Azure App Service permite que un atacante no autorizado eleve sus privilegios a través de la red debido a un control de acceso inadecuado. Al afectar directamente el entorno donde se ejecutan aplicaciones y APIs, un atacante podría comprometer la seguridad de toda la infraestructura desplegada en el servicio. Con una puntuación de 10.0, requiere atención inmediata para quienes operan sobre la plataforma de nube de Microsoft.

7/24/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-57106SSRF and privilege escalation in Data Quality

BackendDataScienceSqlNosqlCyberSecurity

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

Analysis

Esta vulnerabilidad de Server-Side Request Forgery (SSRF) en Data Quality permite a un atacante no autorizado elevar privilegios a través de la red. Al explotar este fallo de severidad máxima, un atacante puede realizar peticiones desde el servidor para comprometer recursos internos y evadir controles de seguridad.

7/24/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-56163Privilege escalation in Azure Kubernetes Service

KubernetesCloudDockerCyberSecurityBackend

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Analysis

Microsoft Azure Kubernetes Service presenta una falta de autenticación que permite a un atacante remoto elevar sus privilegios en el clúster sin autorización previa. Este fallo compromete la seguridad de la infraestructura de contenedores y permite el control administrativo de los recursos afectados a través de la red.

7/24/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-62825Privilege escalation in Azure Key Vault

CloudBackendCyberSecurityKubernetesDocker

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

Analysis

Esta vulnerabilidad crítica en Azure Key Vault permite a un atacante no autorizado elevar privilegios de forma remota debido a una falla en el proceso de autenticación. Al ser un servicio central para el manejo de secretos y llaves, el impacto pone en riesgo la integridad de toda la infraestructura backend y los datos sensibles almacenados. Es imperativo revisar las configuraciones de acceso para mitigar este riesgo de severidad máxima.

7/24/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-58275Privilege escalation in Azure DNS

CloudCyberSecurityBackend

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

Analysis

Azure DNS presenta una vulnerabilidad crítica que permite a un atacante elevar privilegios de forma remota debido a una falla en la validación de autorización. Esta falla permite el control no autorizado de registros DNS, facilitando la interceptación de tráfico o la toma de control de dominios en la infraestructura de la nube. Con un puntaje de 10.0, es imperativo que quienes operan servicios en Azure revisen sus configuraciones de seguridad.

7/24/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-56191Authentication bypass in Microsoft Exchange Online

CyberSecurityCloudBackendWindows

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

Analysis

Esta vulnerabilidad crítica de autenticación en Microsoft Exchange Online permite que un atacante no autorizado realice manipulaciones de datos a través de la red sin necesidad de credenciales. Con un puntaje CVSS de 10.0, el fallo compromete totalmente la integridad de los servicios de correo y colaboración en la nube. Es imperativo revisar las configuraciones de seguridad y acceso en infraestructuras que dependan de este ecosistema.

7/24/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-42933OT segmentation bypass in Pronetiqs IntraVUE

CyberSecurityHardwareBackend

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

Analysis

Pronetiqs IntraVUE presenta una vulnerabilidad de proxy no intencionado que permite a un atacante evadir la segmentación de red en entornos industriales (OT). Con una severidad máxima de 10.0, este fallo facilita el acceso a sistemas críticos aislados mediante el uso del software como intermediario.

7/23/2026View details
CVSS 10.0CVSS 10.0

CVE-2025-71389Unauthenticated RCE in Cal.com via Next.js RSC

ReactJavascriptTypescriptBackendFrontendCyberSecurity

Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled i…

Analysis

Cal.com presenta una vulnerabilidad de ejecución remota de código (RCE) sin autenticación que permite a un atacante tomar control total del servidor mediante peticiones manipuladas a los React Server Components. El fallo reside en una dependencia de Next.js que deserializa entrada no confiable durante el procesamiento en el servidor, comprometiendo la infraestructura sin necesidad de interacción del usuario. Es fundamental actualizar a la versión 5.9.9 o superior para mitigar este riesgo de severidad máxima.

7/23/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-6516Unauthenticated RCE in ManageEngine ADAudit Plus

CyberSecurityBackendWindows

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

Analysis

Zohocorp ManageEngine ADAudit Plus presenta una vulnerabilidad critica de ejecucion remota de codigo sin autenticacion a traves de su API de agentes. Un atacante puede tomar control total del servidor afectado sin necesidad de credenciales previas aprovechando este fallo de inyeccion de comandos. Dada su gravedad de 10.0 en la escala CVSS, es imperativo actualizar a la version 8606 para proteger la infraestructura de auditoria de Active Directory.

7/23/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-47668Remote Code Execution via Code Injection in DbGate

JavascriptTypescriptSqlNosqlBackendCyberSecurity

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `…

Analysis

DbGate permite la ejecución remota de código (RCE) mediante la inyección de comandos en el parámetro functionName de sus scripts JSON. Debido a que los datos de entrada se concatenan directamente en código JavaScript ejecutado por un proceso hijo de Node.js, un atacante puede tomar control total del servidor que aloja el administrador de bases de datos. Se recomienda actualizar inmediatamente a la versión 7.1.9 para mitigar este riesgo crítico.

7/23/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-64813Unauthorized settings modification in JetBrains IntelliJ IDEA

jetbrains:intellij_idea
JavaBackendCyberSecurityCloud

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

Analysis

JetBrains IntelliJ IDEA presenta una vulnerabilidad crítica que permite la modificación no autorizada de configuraciones durante sesiones de desarrollo remoto. Con una puntuación CVSS de 10.0, este fallo permite a un atacante comprometer la integridad del entorno de trabajo y el código fuente. Se recomienda actualizar a la versión 2026.2 o superior inmediatamente para mitigar este riesgo.

7/23/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-64812Input injection in JetBrains IntelliJ IDEA

jetbrains:intellij_idea
JavaBackendPythonCyberSecurity

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Analysis

Esta vulnerabilidad en JetBrains IntelliJ IDEA permite la inyección de comandos no autorizada durante sesiones de Remote Development. Un atacante puede manipular el entorno de desarrollo sin necesidad de autenticación previa, comprometiendo la integridad del código y la infraestructura conectada. Es fundamental actualizar a la versión 2026.2 para mitigar este riesgo de severidad máxima.

7/23/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-59555Arbitrary File Deletion in Participants Database

PhpBackendCyberSecurity

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

Analysis

Esta vulnerabilidad en el plugin Participants Database para WordPress permite que un atacante sin autenticación elimine archivos arbitrarios del servidor. Al tratarse de una falla de Path Traversal con calificación crítica de 10.0, un atacante podría comprometer la integridad del sitio web eliminando archivos de configuración o datos vitales. Es imperativo actualizar el plugin a la versión más reciente para proteger la instalación.

7/23/2026View details
CVSS 10.0CVSS 10.0

CVE-2026-60366Remote Takeover in Oracle Platform Security for Java

oracle:platform_security_for_java
JavaBackendCyberSecurityCloud

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitabl…

Analysis

Esta vulnerabilidad crítica en Oracle Platform Security for Java permite a un atacante no autenticado tomar el control total del servidor a través de peticiones HTTP. Al afectar componentes centrales de Oracle Fusion Middleware, un compromiso exitoso permite el acceso total a la infraestructura y otros servicios vinculados. Es imperativo actualizar las versiones afectadas de inmediato dado su puntaje de severidad máximo de 10.0.

7/22/2026View details
AI-recommendedCVSS 9.3widely_deployed_infra

CVE-2026-50252DNS Cache Poisoning in NLnet Labs Unbound

nlnetlabs:unbound
BackendCyberSecurityCloudLinuxDockerKubernetes

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend…

Analysis

A critical vulnerability in the Unbound DNS resolver allows remote attackers to perform DNS cache poisoning attacks. By undermining UDP source port randomization, an attacker can redirect traffic intended for legitimate domains to malicious servers. This affects most installations using default settings.

7/22/2026View details
HomeEventsBlogResourcesCoursesTeam