{"items":[{"id":"CVE-2026-107856","published":"2026-10-09T21:17:03.387","modified":"2026-10-09T21:17:03.387","description":"CiviForm simplifies applications for government benefits programs by reusing applicant data across multiple benefit applications. Prior to 3.33.0, GET /admin/tiDash/editClientForm/:accountId verifies that the requester is a Trusted Intermediary but showEditClientForm performs a raw lookupAccount(accountId) without confirming that the citizen account belongs to the requester's trustedIntermediaryGroup. An authenticated Trusted Intermediary can enumerate accountId values and read the applicant display name, including the citizen's name and email address, for accounts outside the intermediary's group. This issue is fixed in version 3.33.0.","score":4.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-639"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Civiform","vendorCategory":"Other vendors","references":[{"url":"https://github.com/civiform/civiform/commit/ccfd84ff2d9ee6570a1b1524c7ae3a3732e1839e","label":"github.com","kind":"reference"},{"url":"https://github.com/civiform/civiform/pull/13635","label":"github.com","kind":"reference"},{"url":"https://github.com/civiform/civiform/releases/tag/v3.33.0","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107854","published":"2026-10-09T21:17:03.233","modified":"2026-10-09T21:17:03.233","description":"Jexactyl is a customisable game management panel and billing system. From 4.0.0 until 4.0.5, the POST /api/client/billing/free/process endpoint accepts a client-controlled server_id and loads the server without restricting the lookup to servers owned by the authenticated account. On installations with billing enabled, an authenticated user can renew or unsuspend another tenant's billable server when its renewal_date is non-null and more than seven days away, even without a subuser relationship to that server. This issue is fixed in version 4.0.5.","score":5.4,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-639"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Jexactyl","vendorCategory":"Other vendors","references":[{"url":"https://github.com/Jexactyl/Jexactyl/commit/356a5b46a18d483ae90c862e130b1969e6df0777","label":"github.com","kind":"reference"},{"url":"https://github.com/Jexactyl/Jexactyl/releases/tag/v4.0.5","label":"github.com","kind":"reference"},{"url":"https://github.com/Jexactyl/Jexactyl/security/advisories/GHSA-9xwv-p7r5-5h5p","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107852","published":"2026-10-09T21:17:03.080","modified":"2026-10-09T21:17:03.080","description":"Jexactyl is a customisable game management panel and billing system. Prior to 4.0.5, the POST /api/client/billing/stripe/process endpoint accepts a client-supplied Stripe Checkout Session when payment_status is paid but does not compare amount_total or currency with the referenced order and configured billing currency. On an instance where the billing module is enabled and a Stripe secret key is configured, an authenticated client can therefore complete a lower-value or mismatched-currency payment and cause the order to be processed, provisioning, renewing, upgrading, or unsuspending the purchased server for less than the required price. This issue is fixed in version 4.0.5.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-345"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Jexactyl","vendorCategory":"Other vendors","references":[{"url":"https://github.com/Jexactyl/Jexactyl/commit/fdee722c560ac13dc2d26271912203a6085dffe3","label":"github.com","kind":"reference"},{"url":"https://github.com/Jexactyl/Jexactyl/releases/tag/v4.0.5","label":"github.com","kind":"reference"},{"url":"https://github.com/Jexactyl/Jexactyl/security/advisories/GHSA-rf56-676w-hj4g","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107851","published":"2026-10-09T21:17:02.920","modified":"2026-10-09T21:17:02.920","description":"Contao is an Open Source CMS. From version 5.7.0 until 5.7.12, TableAccessVoter::hasAccessToModule() in core-bundle/src/Security/Voter/DataContainer/TableAccessVoter.php caches authorization decisions using only $tokenHash, a hash of the user's security token, and omits the table returned by getDataSource(). If one request first checks a table allowed to the user and then a different denied table, the voter can reuse the allowed result, while DefaultDataContainerVoter can convert an incorrect abstention into a grant. A low-privileged backend user can consequently read, create, update, or delete records in tables outside assigned module permissions, including tables containing member or newsletter-subscriber data. This issue is fixed in version 5.7.12.","score":4.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-524","CWE-863"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Contao","vendorCategory":"Other vendors","references":[{"url":"https://github.com/contao/contao/commit/9d6f582a4cc6a758ce11d1043fc9c0ba62c5f4c9","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/releases/tag/5.7.12","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/security/advisories/GHSA-5974-gfqc-wrcm","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107850","published":"2026-10-09T21:17:02.770","modified":"2026-10-09T21:17:02.770","description":"Contao is an Open Source CMS. From version 5.7.1 until 5.7.12, core-bundle/config/services.yaml registers the preview access voter as Contao\\CoreBundle\\Security\\Voter\\DataContainer\\PreviewAccessVoter although the shipped class is PreviewVoter. Symfony therefore omits voter autoconfiguration and removes the private service, so PreviewVoter::hasAccess() never enforces ownership. A non-admin backend user with the preview_link module can list every tl_preview_link record, obtain signed share URLs created by other users, and use them to view unpublished pages with showUnpublished despite lacking page permission. The advisory does not establish editing or deletion of foreign links. This issue is fixed in version 5.7.12.","score":4.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-639","CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Contao","vendorCategory":"Other vendors","references":[{"url":"https://github.com/contao/contao/commit/6b483d380a4b2dc61432c4c697e411508f93bf91","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/releases/tag/5.7.12","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/security/advisories/GHSA-q6wp-fr43-gm9v","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107848","published":"2026-10-09T21:17:02.617","modified":"2026-10-09T21:17:02.617","description":"Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, RequestTokenListener validates REQUEST_TOKEN only for POST requests, while the declarative GET guard runs only when an act parameter is present. Backend actions dispatched through the key parameter can therefore execute without a CSRF token when an authenticated backend user loads an attacker-controlled URL. Reachable actions remain limited to modules available to that user, and the advisory demonstrates destructive or state-changing actions rather than privilege escalation. This issue is fixed in versions 5.3.50 and 5.7.12.","score":3.5,"severity":"LOW","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-352"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Contao","vendorCategory":"Other vendors","references":[{"url":"https://github.com/contao/contao/commit/34dd27ee6739f10568d3d95d8784862255c925b4","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/releases/tag/5.7.12","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/security/advisories/GHSA-9ff2-p842-45wq","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78797","published":"2026-10-09T20:17:11.117","modified":"2026-10-09T20:17:11.117","description":"An issue in iStoreOS istoreos-24.10.7 and before allows a remote attacker to execute arbitrary code via the task_id in tasks-lib.lua.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Linkease","vendorCategory":"Other vendors","references":[{"url":"https://doc.linkease.com/zh/guide/istoreos/install_vmware.html","label":"doc.linkease.com","kind":"reference"},{"url":"https://fw.koolcenter.com/iStoreOS/x86_64_efi/","label":"fw.koolcenter.com","kind":"reference"},{"url":"https://github.com/PRISMI-Team/VulnDisclos/blob/main/Routers/iStoreOS/authorized-rce.md","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107845","published":"2026-10-09T20:17:10.457","modified":"2026-10-09T20:17:10.457","description":"Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under that user's session. Unpublished comments remain visible to moderators, so moderation does not prevent exposure. This issue is fixed in versions 5.3.50 and 5.7.12.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79","CWE-116"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Contao","vendorCategory":"Other vendors","references":[{"url":"https://github.com/contao/contao/commit/22505d5f79bc1a7f52e2cba5fddf6007e1f0408a","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/releases/tag/5.3.50","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/releases/tag/5.7.12","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107844","published":"2026-10-09T20:17:10.313","modified":"2026-10-09T20:17:10.313","description":"Contao is an Open Source CMS. From version 5.0.0 until 5.3.50 and 5.7.12, ImagesController joins the user-controlled {path} parameter to the configured image target directory with Path::join() but does not use Path::isBasePath() to verify that the canonical path remains inside that directory. An unauthenticated request containing encoded parent-directory segments can therefore return files under the project directory through BinaryFileResponse when their names use an extension allowed by contao.image.valid_extensions. The route can also reveal whether arbitrary paths exist, and debug responses can disclose absolute filesystem paths, but paths below the upload directory were not shown to be readable. This issue is fixed in versions 5.3.50 and 5.7.12.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-22"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Canonical","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://github.com/contao/contao/commit/867c055122fdf12220f973f862082037b695b9bd","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/releases/tag/5.3.50","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/releases/tag/5.7.12","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107843","published":"2026-10-09T20:17:10.167","modified":"2026-10-09T20:17:10.167","description":"Contao is an Open Source CMS. From version 4.1.0 until 5.3.50 and 5.7.12, ModuleRegistration::compile() enters its follow-up registration branch on any POST to a page containing the registration module without verifying FORM_SUBMIT or the preceding captcha result. resendActivationMail() can then invoke OptInToken::send() without rate limiting, allowing an unauthenticated attacker to cause repeated activation emails to be sent to an address with a pending registration and to determine whether that pending registration exists. The branch is reachable only when reg_activate is enabled and the target has an unconfirmed registration and opt-in token. This issue is fixed in versions 5.3.50 and 5.7.12.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-204","CWE-770"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Contao","vendorCategory":"Other vendors","references":[{"url":"https://github.com/contao/contao/commit/2ea6117f9049db7221679251cfc41e67d941a74b","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/releases/tag/5.3.50","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/releases/tag/5.7.12","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107842","published":"2026-10-09T20:17:10.013","modified":"2026-10-09T20:17:10.013","description":"Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, ModuleSearch can disclose protected page titles, URLs, and indexed context snippets to unauthenticated visitors when contao.search.index_protected is changed from enabled to disabled. Authorization metadata is stored per row in tl_search, but disabling the setting removes the protected-row filter without deleting rows indexed while protection was enabled. The protected pages continue to return an authorization response, so this issue exposes search metadata and indexed text rather than bypassing page access. This issue is fixed in versions 5.3.50 and 5.7.12.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-200"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Contao","vendorCategory":"Other vendors","references":[{"url":"https://github.com/contao/contao/commit/572686a113bca60f92cf2d0496cf3a74d0b6b457","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/releases/tag/5.3.50","label":"github.com","kind":"reference"},{"url":"https://github.com/contao/contao/releases/tag/5.7.12","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78835","published":"2026-10-09T19:16:42.420","modified":"2026-10-09T19:16:42.420","description":"Rocket Software Rocket Remote Desktop 18.0.8583.1 is vulnerable to Insufficiently Protected Credentials.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Rocket","vendorCategory":"Other vendors","references":[{"url":"http://rocket.com","label":"rocket.com","kind":"reference"},{"url":"https://www.redteam-pentesting.de/en/advisories/rt-sa-2026-001/","label":"redteam-pentesting.de","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-75353","published":"2026-10-09T19:16:42.297","modified":"2026-10-09T19:16:42.297","description":"OpENer v2.3/ commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remtoe attacker to cause a denial of service","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"EIPStackGroup","vendorCategory":"Other vendors","references":[{"url":"https://github.com/EIPStackGroup/OpENer","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/issues/570","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-75352","published":"2026-10-09T19:16:42.167","modified":"2026-10-09T19:16:42.167","description":"OpENer v2.3/commit 76b95cf, contains an integer underflow in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"EIPStackGroup","vendorCategory":"Other vendors","references":[{"url":"https://github.com/EIPStackGroup/OpENer","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/issues/571","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-75351","published":"2026-10-09T19:16:42.047","modified":"2026-10-09T21:17:05.990","description":"OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-125"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"EIPStackGroup","vendorCategory":"Other vendors","references":[{"url":"https://github.com/EIPStackGroup/OpENer","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/issues/574","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-75350","published":"2026-10-09T18:17:14.037","modified":"2026-10-09T18:17:14.037","description":"EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in the GetAttributeList() implementation for the EtherNet/IP Get_Attribute_List service. This allows a remote attacker to cause a denial of service","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"EIPStackGroup","vendorCategory":"Other vendors","references":[{"url":"https://github.com/EIPStackGroup/OpENer","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/master/source/src/cip/cipcommon.c","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/master/source/src/enet_encap/cpf.c","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108096","published":"2026-10-09T18:17:06.410","modified":"2026-10-09T18:17:06.410","description":"Improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer in AWS Amplify API Category before 3.1.2 might allow an authenticated remote user to read records owned by other users of the same application via crafted queries.\n\n\n\nThis issue has been addressed in @aws-amplify/graphql-index-transformer  3.1.2 https://www.npmjs.com/package/@aws-amplify/graphql-index-transformer/v/3.1.2  (included in @aws-amplify/data-construct  1.17.4 https://www.npmjs.com/package/@aws-amplify/data-construct/v/1.17.4  and @aws-amplify/graphql-api-construct  1.21.4 https://www.npmjs.com/package/@aws-amplify/graphql-api-construct/v/1.21.4 ). We recommend upgrading to the latest version ensuring any forked or derivative code is patched to incorporate the new fixes and then redeploying their backend.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-639"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Amazon","vendorCategory":"Other vendors","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-133-aws/","label":"aws.amazon.com","kind":"reference"},{"url":"https://github.com/aws-amplify/amplify-category-api/security/advisories/GHSA-69c4-mvf5-5xm3","label":"github.com","kind":"reference"},{"url":"https://www.npmjs.com/package/@aws-amplify/data-construct/v/1.17.4","label":"npmjs.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107841","published":"2026-10-09T18:17:06.110","modified":"2026-10-09T19:16:41.900","description":"pacioli provides least-privilege governance and a governed agent broker for ERPNext. From version 0.9.6 until version 0.10.0, the pacioli-guard document-layer consent gate allows nested cancellation operations to ride any consent established by an enclosing governed act without checking whether the marker authorizes cancellation. A credential with API Key Scope.require_consent can submit a caller-controlled Sales Invoice or other supported document under a valid human-minted submit marker and reach Document.cancel() for a different pre-existing submitted document, bypassing the marker's document and act binding, single-use spend, and denial audit. The unauthorized cancellation can reverse the target document's ledger effect; principals without a consent-gated grant are not affected. This issue is fixed in version 0.10.0.","score":5.7,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-863"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"John Broadway","vendorCategory":"Other vendors","references":[{"url":"https://github.com/john-broadway/pacioli/commit/f3c7219f5dde6050bd7921e0ac55afd02771250c","label":"github.com","kind":"reference"},{"url":"https://github.com/john-broadway/pacioli/releases/tag/guard-v0.10.0","label":"github.com","kind":"reference"},{"url":"https://github.com/john-broadway/pacioli/security/advisories/GHSA-3hj7-6vmj-h8v4","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107840","published":"2026-10-09T18:17:05.953","modified":"2026-10-09T20:17:09.900","description":"yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacker can submit many unique methods and create metric series that the Prometheus registry never evicts. The resulting monotonic memory growth can OOM-kill the process, while the expanding registry also degrades /metrics scrape latency and can blind monitoring. This issue is fixed in version 14.7.0.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-400"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Jhaals","vendorCategory":"Other vendors","references":[{"url":"https://github.com/jhaals/yopass/commit/61e31ead04a4fc27ce80bed226af41c7c0426ccf","label":"github.com","kind":"reference"},{"url":"https://github.com/jhaals/yopass/commit/78d0c14f7085048130199662a2ec8a18ec8d6ebb","label":"github.com","kind":"reference"},{"url":"https://github.com/jhaals/yopass/pull/3773","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107839","published":"2026-10-09T18:17:05.797","modified":"2026-10-09T18:17:05.797","description":"ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology games. Prior to version 1.15.2, the AoE3 POST /game/cloud/getFileURL handler in the bundled game server has no request body size limit or cap on the attacker-controlled JSON names array and allocates response storage directly from the unbounded array length. A remote unauthenticated client can use the default self-registration flow and send an oversized request that causes excessive memory allocation, crashes or hangs the server process, disconnects active players, and keeps the service unavailable until it is restarted. This issue is fixed in version 1.15.2.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-400"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Luskaner","vendorCategory":"Other vendors","references":[{"url":"https://github.com/luskaner/ageLANServer/commit/1dd40166a59356865c0a4b1800f32d05dc8bec79","label":"github.com","kind":"reference"},{"url":"https://github.com/luskaner/ageLANServer/releases/tag/v1.15.2","label":"github.com","kind":"reference"},{"url":"https://github.com/luskaner/ageLANServer/security/advisories/GHSA-4jfq-pmq9-257h","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107838","published":"2026-10-09T18:17:05.640","modified":"2026-10-09T18:17:05.640","description":"RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver.c ignore a failure returned by _resp_init() when coap_build_reply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoap_token_ext is enabled, causing response initialization to fail while _get_file() or _get_directory() continues with stale response state. The path then reaches _calc_szx2() and its pdu->payload_len > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-252","CWE-617"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"RIOT OS","vendorCategory":"Other vendors","references":[{"url":"https://github.com/RIOT-OS/RIOT/commit/d3a47289c58d108575a19e623e4d3f647659e743","label":"github.com","kind":"reference"},{"url":"https://github.com/RIOT-OS/RIOT/pull/22745","label":"github.com","kind":"reference"},{"url":"https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-39j3-3v73-5mj2","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107837","published":"2026-10-09T18:17:05.483","modified":"2026-10-09T18:17:05.483","description":"RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, _receive() in sys/net/gnrc/network_layer/sixlowpan/gnrc_sixlowpan.c can route an undersized packet into SFF fragment handling after only a minimal payload check. The code then interprets the packet as a sixlowpan_frag_t or larger fragment header without verifying that the packet snip contains the required bytes. A remote attacker can send a malformed 6LoWPAN fragment that causes gnrc_sixlowpan_frag_recv() to read beyond the packet buffer, potentially disclosing memory and crashing the network stack. No fixed repository release is available as of this review.","score":8.2,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-125"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"RIOT OS","vendorCategory":"Other vendors","references":[{"url":"https://github.com/RIOT-OS/RIOT/commit/0cae205cd1d110e0b8fce094714598322d56ce2d","label":"github.com","kind":"reference"},{"url":"https://github.com/RIOT-OS/RIOT/pull/22504","label":"github.com","kind":"reference"},{"url":"https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-m8mc-q4p7-p8j3","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107836","published":"2026-10-09T18:17:05.310","modified":"2026-10-09T18:17:05.310","description":"RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanocoap/sock.c accepts a Block2 response when _block_cb() sees the expected block number without also verifying that the server-controlled szx and derived offset match the requested block geometry. A malicious CoAP server can return the expected block number with a larger block size, causing the derived offset to exceed the client slice offset and making ctx->offset - offset underflow in _2buf_slice(). The resulting buffer-relative calculation can read before the payload buffer and crash the client, causing denial of service and potentially exposing adjacent memory. No fixed release is available as of this review.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-125","CWE-191"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"RIOT OS","vendorCategory":"Other vendors","references":[{"url":"https://github.com/RIOT-OS/RIOT/commit/49b894cbe091510093273b98d92c4a17167d6839","label":"github.com","kind":"reference"},{"url":"https://github.com/RIOT-OS/RIOT/pull/22518","label":"github.com","kind":"reference"},{"url":"https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-x924-p5fq-26pc","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107835","published":"2026-10-09T18:17:05.157","modified":"2026-10-09T19:16:41.780","description":"OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Prior to 3.8.1, internal/cookies.ParseCookies in internal/cookies/cookies.go handles boundary ASCII control characters and control-only or empty cookie names differently from several backend cookie parsers. An unauthenticated attacker can craft a Cookie header so Coraza indexes or drops a cookie under a different name or value from the backend application, causing rules targeting REQUEST_COOKIES or REQUEST_COOKIES_NAMES to miss application-visible attacker data. Exploitation depends on the backend parser and affected rule scope, and interior control characters with inconsistent backend behavior are outside this advisory's remediation. This issue is fixed in version 3.8.1.","score":4,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-436"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Corazawaf","vendorCategory":"Other vendors","references":[{"url":"https://github.com/corazawaf/coraza/commit/0b940e197ad9983fb3aa36e84f1f81ff985461af","label":"github.com","kind":"reference"},{"url":"https://github.com/corazawaf/coraza/commit/9f8521398d1ff023b958fad0b944cac265763866","label":"github.com","kind":"reference"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.1","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107834","published":"2026-10-09T18:17:05.007","modified":"2026-10-09T18:17:05.007","description":"OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, the multipart loop in internal/bodyprocessors/multipart.go executes defer temp.Close() for every uploaded file part, so each temporary-file descriptor remains open until the complete request returns. An unauthenticated attacker can submit a multipart body containing many minimal file parts and exhaust the process file-descriptor table within the request-body size limit, causing os.CreateTemp failures, MULTIPART_STRICT_ERROR responses, blocked legitimate uploads, and process-wide inability to open files or sockets. This issue is fixed in version 3.8.0.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-400","CWE-772"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Corazawaf","vendorCategory":"Other vendors","references":[{"url":"https://github.com/corazawaf/coraza/commit/1bc39036e99c88e7de60cf8e6bb55ee4c311223c","label":"github.com","kind":"reference"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.0","label":"github.com","kind":"reference"},{"url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-rp9v-7xv3-r6g3","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107833","published":"2026-10-09T18:17:04.847","modified":"2026-10-09T18:17:04.847","description":"OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessResponse in internal/bodyprocessors/json.go passes the ignoreJSONRecursionLimit value of -1 to readJSON, while the recursive guard only stops at zero. A network attacker who can cause an application protected by Coraza to return deeply nested JSON can make response-body processing perform quadratic work, consuming one CPU core for seconds per response within the default ResponseBodyLimit. Request JSON processing is not affected by this specific path because it uses the configured request recursion limit, and exploitation requires response-body inspection to be enabled. This issue is fixed in version 3.8.0.","score":5.9,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-674"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Corazawaf","vendorCategory":"Other vendors","references":[{"url":"https://github.com/corazawaf/coraza/commit/cae3c7407e7b84372c207033de03f15f89bf351a","label":"github.com","kind":"reference"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.0","label":"github.com","kind":"reference"},{"url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-3c6w-j9xm-8h2h","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107826","published":"2026-10-09T18:17:04.673","modified":"2026-10-09T18:17:04.673","description":"OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and then call gjson.Valid on the complete raw body. An unauthenticated attacker can submit shallow values followed by an extremely deeply nested JSON tail that was not visited by the bounded walk, causing gjson.Valid to recurse without a depth bound and terminate the hosting process with an unrecoverable fatal stack overflow. The ProcessRequest and ProcessResponse JSON paths share the affected readJSON validation flow, and the payload can remain within recommended body-size and argument-count limits. This issue is fixed in version 3.8.1.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-674"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Corazawaf","vendorCategory":"Other vendors","references":[{"url":"https://github.com/corazawaf/coraza/commit/814e1898e083d2ff2ceb644382d0da17e930f93f","label":"github.com","kind":"reference"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.1","label":"github.com","kind":"reference"},{"url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-6gcq-wc29-5xf2","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107825","published":"2026-10-09T18:17:04.503","modified":"2026-10-09T18:17:04.503","description":"OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.0, ProcessURI in internal/corazawaf/transaction.go handles a url.ParseRequestURI failure by retaining the raw URI but leaving QUERY_STRING, ARGS_GET, ARGS_GET_NAMES, and the GET-derived portion of ARGS empty. An unauthenticated attacker can place control bytes in a URI passed directly by integrations such as coraza-spoa, coraza-proxy-wasm, custom FFI hosts, or WASM hosts, causing Coraza to omit query parameters that the downstream integration may still process and allowing rules targeting those variables to be bypassed. The bundled coraza/v3/http integration is not affected because Go net/http rejects such malformed request targets before calling Coraza. This issue is fixed in version 3.8.0.","score":4,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-20","CWE-436"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Corazawaf","vendorCategory":"Other vendors","references":[{"url":"https://github.com/corazawaf/coraza/commit/0321af96cef18fbafb40980cf075d7cc449a66fa","label":"github.com","kind":"reference"},{"url":"https://github.com/corazawaf/coraza/releases/tag/v3.8.0","label":"github.com","kind":"reference"},{"url":"https://github.com/corazawaf/coraza/security/advisories/GHSA-x26q-wvhg-fh4m","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107824","published":"2026-10-09T18:17:04.350","modified":"2026-10-09T18:17:04.350","description":"x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.1, x64dbg-MCP Server exposes all MCP debugger tools over HTTP and SSE without authentication while listening on 0.0.0.0 by default. Any unauthenticated network client that can reach the default port, 9094 for x64 or 9095 for x32, can execute arbitrary x64dbg commands, attach to processes by PID, read and write debuggee memory, and write files to arbitrary paths. This issue is fixed in version 1.1.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-306"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Duty1g","vendorCategory":"Other vendors","references":[{"url":"https://github.com/duty1g/x64dbg-mcp-server/commit/1aad0f88b9c27233d11dbccf08ca415eb5f49203","label":"github.com","kind":"reference"},{"url":"https://github.com/duty1g/x64dbg-mcp-server/commit/e1daba0038959f88d25ff3376b2a7f922ffeb448","label":"github.com","kind":"reference"},{"url":"https://github.com/duty1g/x64dbg-mcp-server/releases/tag/1.0","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107823","published":"2026-10-09T18:17:04.190","modified":"2026-10-09T18:17:04.190","description":"MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the MariaDB view FRM parser did not safely encode embedded newline characters in a username. An account with CREATE USER and CREATE VIEW WITH GRANT OPTION could create a crafted username containing additional view metadata, causing the parser to interpret part of the username as security metadata and potentially escalating database privileges. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.","score":7.2,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-116","CWE-144"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"MariaDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/MariaDB/server/commit/8a642bc8103aadc6b2087d781ba8e1595616a2c4","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107822","published":"2026-10-09T18:17:04.030","modified":"2026-10-09T18:17:04.030","description":"MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB's ACL cache could generate the same database-privilege cache key for role and localhost user names that matched because both used an empty IP component. An attacker with CREATE USER could create the colliding principal and, when the original principal's database privileges were cached, exercise privileges assigned to the other account. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.","score":6.4,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-706","CWE-863"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"MariaDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/MariaDB/server/commit/67ea07dd3400004e4f7ae01bf977f4344bbe064b","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107821","published":"2026-10-09T18:17:03.860","modified":"2026-10-09T18:17:03.860","description":"MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB insufficiently validated counts, offsets, lengths, and field boundaries in FRM metadata while opening binary FRM files. An attacker able to place a crafted FRM file in the data directory could trigger out-of-bounds reads or writes, crash the server, or potentially execute code. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.","score":8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-1285"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"MariaDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/MariaDB/server/commit/3b1c2e58abab5571bec4ff52773ddc75b1738da9","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107820","published":"2026-10-09T18:17:03.703","modified":"2026-10-09T18:17:03.703","description":"x64dbg-MCP Server is a native Model Context Protocol (MCP) plugin for x64dbg that exposes the debugger's full functionality over HTTP. Prior to 1.2, src/core/mcp_server.zig parses an unbounded Content-Length value in parseContentLength() and uses it in unchecked usize addition in wsRecv() before token authentication. The server listens on 0.0.0.0 by default in affected versions. An unauthenticated network client can supply a near-maximum Content-Length value to trigger a runtime integer-overflow panic in Debug and ReleaseSafe builds, terminating the entire x64dbg process and its live debugging session. The overflowed value is used only in a comparison, so the impact is limited to denial of service rather than memory corruption or code execution. This issue is fixed in version 1.2.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-190"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Duty1g","vendorCategory":"Other vendors","references":[{"url":"https://github.com/duty1g/x64dbg-mcp-server/commit/0dd4204d37c81d8b605133dc48c14886eeac1562","label":"github.com","kind":"reference"},{"url":"https://github.com/duty1g/x64dbg-mcp-server/releases/tag/v1.2","label":"github.com","kind":"reference"},{"url":"https://github.com/duty1g/x64dbg-mcp-server/security/advisories/GHSA-4478-h5jv-647m","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107819","published":"2026-10-09T18:17:03.533","modified":"2026-10-09T18:17:03.533","description":"MariaDB Connector/C is a C and C++ client library for connecting applications to MariaDB and MySQL databases. From 3.4.1 until 3.4.10, the MariaDB Connector/C libmariadb Zero-Configuration SSL authentication-switch logic checked certificate trust failure but did not reject a TLS hostname verification mismatch before selecting a non-hashing authentication plugin. An active man-in-the-middle attacker with a valid certificate for another hostname could request mysql_clear_password and obtain the database password inside the attacker-controlled TLS connection. Other MariaDB connectors are not affected. This issue is fixed in version 3.4.10.","score":5.9,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-297"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"MariaDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/MariaDB/server/security/advisories/GHSA-fmq9-qjxj-qpf7","label":"github.com","kind":"reference"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-c/commit/e8c0a16d94ddf844668d684a7d42b37ac8e0fc02","label":"github.com","kind":"reference"},{"url":"https://github.com/mariadb-corporation/mariadb-connector-c/releases/tag/v3.4.10","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107818","published":"2026-10-09T18:17:03.373","modified":"2026-10-09T18:17:03.373","description":"MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster during the next service restart. A database user with FILE privilege and a secure-file-priv configuration permitting writes to /run/mysqld could create that file and inject attacker-controlled environment values into the restarted service. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.","score":8.4,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-15"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"MariaDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/MariaDB/server/commit/e3d62d4e78fd4941cef3f5053e6a50d0b32d740e","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107817","published":"2026-10-09T18:17:03.220","modified":"2026-10-09T18:17:03.220","description":"MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mysql_json plugin assumed that imported MySQL tables contained valid MySQL binary JSON data. A specially prepared MySQL table containing invalid JSON data could cause out-of-bounds reads, information disclosure, or a server crash. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.","score":4.4,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-125"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"MariaDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/MariaDB/server/commit/851f52470d470a96a66e0b7e5599f3b6c2e45907","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107816","published":"2026-10-09T18:17:03.060","modified":"2026-10-09T18:17:03.060","description":"MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the qc_info plugin could be confused by a query containing embedded null bytes. Reading information_schema.query_cache_info after such a query was cached could access data beyond the end of a heap-allocated buffer, potentially disclosing adjacent memory or crashing the server. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.","score":6.4,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-125"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"MariaDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/MariaDB/server/commit/0931994096b84ecc9ffc8eb3517c7e09e6e8631e","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-75597","published":"2026-10-09T17:16:48.550","modified":"2026-10-09T18:17:14.173","description":"pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the `/web/<path:filename>` route in `src/pyload/webui/app/blueprints/app_blueprint.py` renders Jinja2 templates without any authentication requirement. Every equivalent direct route (`/logs`, `/settings`, `/queue`, `/dashboard`, etc.) is protected by `@login_required`, but the underlying templates for all of these pages are accessible unauthenticated via this endpoint. Combined with an exception attribute typo in `src/pyload/webui/app/handlers.py` (`exc.desc` instead of `exc.description`), internal Jinja2 variable names are leaked in HTTP 500 response bodies to unauthenticated callers. An attacker can also enumerate all valid template names by observing 200 vs 500 response differentiation. Version 0.5.0b3.dev101 contains a patch.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-209","CWE-306"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Pyload","vendorCategory":"Other vendors","references":[{"url":"https://github.com/pyload/pyload/commit/e80c940cd604e60d93e3164429d4fc4aac54468d","label":"github.com","kind":"reference"},{"url":"https://github.com/pyload/pyload/security/advisories/GHSA-j92p-c242-7hfx","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-75347","published":"2026-10-09T17:16:48.403","modified":"2026-10-09T17:41:47.060","description":"EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired pointer dereference vulnerability in the EtherNet/IP Common Packet Format (CPF) handling logic. This allows a remote attacker to cause a denial of service.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"EIPStackGroup","vendorCategory":"Other vendors","references":[{"url":"https://github.com/EIPStackGroup/OpENer/blob/master/source/src/enet_encap/cpf.c","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/master/source/src/enet_encap/encap.c","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/master/source/src/ports/generic_networkhandler.c","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-55797","published":"2026-10-09T17:16:47.710","modified":"2026-10-09T18:17:08.530","description":"Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-78"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Argoproj","vendorCategory":"Other vendors","references":[{"url":"https://github.com/argoproj/argo-cd/commit/1e3ddd0b7250aa23f489956b5fab8c13d0493a9f","label":"github.com","kind":"reference"},{"url":"https://github.com/argoproj/argo-cd/commit/9b27aeb1a4fb15d11a0f01cad65dea1fdfc60205","label":"github.com","kind":"reference"},{"url":"https://github.com/argoproj/argo-cd/pull/15864","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-48484","published":"2026-10-09T17:16:47.487","modified":"2026-10-09T17:16:47.663","description":"pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memory with `file.read()`. This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-20","CWE-400"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Pyload","vendorCategory":"Other vendors","references":[{"url":"https://github.com/pyload/pyload/blob/8e447958b8a66c5899775e725a8b90bce6643004/src/pyload/webui/app/blueprints/api_blueprint.py#L73","label":"github.com","kind":"reference"},{"url":"https://github.com/pyload/pyload/commit/461cd66f30fa9e96453fb4d8c5c47467e452363c","label":"github.com","kind":"reference"},{"url":"https://github.com/pyload/pyload/security/advisories/GHSA-vq8p-m3wm-gv5f","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-42695","published":"2026-10-09T17:16:47.333","modified":"2026-10-09T17:29:54.233","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Flowplayer Video Player fv-wordpress-flowplayer allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.54.7212.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/fv-wordpress-flowplayer/vulnerability/wordpress-fv-flowplayer-video-player-plugin-7-5-54-7212-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108160","published":"2026-10-09T17:16:47.180","modified":"2026-10-09T20:17:10.767","description":"AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and server can serve a malicious update manifest and NSIS installer, which electron-updater installs without signature verification, executing code as the desktop user.","score":7.7,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-494"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Iflytek","vendorCategory":"Other vendors","references":[{"url":"https://github.com/iflytek/astron-rpa","label":"github.com","kind":"reference"},{"url":"https://github.com/iflytek/astron-rpa/blob/8b015bc1b15d23fbdc55c78ff1de9af4bb65fba6/frontend/packages/electron-app/electron-builder.json#L26","label":"github.com","kind":"reference"},{"url":"https://github.com/iflytek/astron-rpa/issues/894","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108159","published":"2026-10-09T17:16:47.027","modified":"2026-10-09T17:41:47.060","description":"AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed prompt-injection content in a web page so the model emits HTML event handlers invoking the unrestricted open-path IPC handler with shell metacharacters, executing commands as the desktop user.","score":7.7,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Iflytek","vendorCategory":"Other vendors","references":[{"url":"https://github.com/iflytek/astron-rpa","label":"github.com","kind":"reference"},{"url":"https://github.com/iflytek/astron-rpa/blob/8b015bc1b15d23fbdc55c78ff1de9af4bb65fba6/frontend/packages/web-app/src/components/SmartComponent/hooks/useChatContext.tsx#L203","label":"github.com","kind":"reference"},{"url":"https://github.com/iflytek/astron-rpa/issues/892","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108158","published":"2026-10-09T17:16:46.870","modified":"2026-10-09T17:41:47.060","description":"plugNmeet Server through 2.5.2 contains a path traversal vulnerability in the whiteboard conversion endpoint that allows any meeting participant to read server files via crafted filePath values. Attackers can supply ../ sequences so text or office documents are converted into page images, then fetch them unauthenticated through /download/uploadedFile/.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-22"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Mynaparrot","vendorCategory":"Other vendors","references":[{"url":"https://github.com/mynaparrot/plugNmeet-server","label":"github.com","kind":"reference"},{"url":"https://github.com/mynaparrot/plugNmeet-server/blob/961b4b01cdff655928fb4b4d50524b42a6b63ec1/pkg/models/file_convert.go#L143","label":"github.com","kind":"reference"},{"url":"https://hackmd.io/@haind/rJX-CmLjMe","label":"hackmd.io","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108157","published":"2026-10-09T17:16:46.703","modified":"2026-10-09T18:17:07.240","description":"Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can register a victim's unverified email on an enabled OAuth/OIDC provider, exploiting the missing email_verified check in GenericOidcProvider, to sign in as the victim including administrators while bypassing TOTP.","score":9.2,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-287"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Smp46","vendorCategory":"Other vendors","references":[{"url":"https://github.com/smp46/pingvin-share-x","label":"github.com","kind":"reference"},{"url":"https://github.com/smp46/pingvin-share-x/blob/de7ffecf9bfc4976993149a5c4c98efe35161424/backend/src/oauth/oauth.service.ts#L158-L175","label":"github.com","kind":"reference"},{"url":"https://github.com/smp46/pingvin-share-x/commit/07aa8c0a96030c439e9018ce94a2778bd37304e6","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108156","published":"2026-10-09T17:16:46.540","modified":"2026-10-09T17:41:47.060","description":"LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in the skills:delete IPC handler that trusts the openclawSourceDir value from a skill's _meta.json during uninstall. Attackers who convince a user to install a crafted skill can make uninstallation recursively delete arbitrary user-writable directories, such as the home directory, since the security scanner never inspects _meta.json.","score":6.9,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-73"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Netease Youdao","vendorCategory":"Other vendors","references":[{"url":"https://github.com/netease-youdao/LobsterAI","label":"github.com","kind":"reference"},{"url":"https://github.com/netease-youdao/LobsterAI/blob/791a352dee3b3d8c6f64edcaf229ce474a68f6c5/src/main/ipcHandlers/skills/handlers.ts#L60-L78","label":"github.com","kind":"reference"},{"url":"https://github.com/netease-youdao/LobsterAI/commit/82fdfe10d1b85d0ff734aa720e18c866b4be2406","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108119","published":"2026-10-09T17:16:46.400","modified":"2026-10-09T17:42:00.023","description":"A flaw was found in busybox. The tar applet's deferred link-creation handling for symlink and hardlink entries with unsafe-looking targets does not validate that the resolved destination remains inside the extraction directory once the deferred link is created. An attacker can craft a tar archive using a symlink target of exactly '..' combined with a deferred hardlink to create a new file outside the extraction directory, or reuse an extraction directory across two archives to replace an existing file outside it. If the archive is extracted with elevated privileges, this flaw can lead to privilege escalation or arbitrary code execution.","score":6.3,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-59"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Red Hat","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-108119","label":"access.redhat.com","kind":"reference"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2548611","label":"bugzilla.redhat.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108093","published":"2026-10-09T17:16:46.260","modified":"2026-10-09T17:42:00.023","description":"A flaw was found in GIMP. The XCF loader processes image-simulation-intent and image-simulation-bpc parasites without ensuring the parasite data is present before dereferencing it. Opening a specially crafted XCF file with a zero-size simulation parasite can cause a NULL pointer dereference and crash the GIMP application.","score":5.5,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-476"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Red Hat","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-108093","label":"access.redhat.com","kind":"reference"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2548607","label":"bugzilla.redhat.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107815","published":"2026-10-09T17:16:45.970","modified":"2026-10-09T17:41:29.727","description":"MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary check that permitted a one-byte null write beyond a stack buffer at an attacker-controlled offset. An authenticated user able to use the CONNECT engine could cause a crash and potentially remote code execution. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.","score":8.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-787"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"MariaDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/MariaDB/server/commit/b369925f6855d3e1f0ebcf453492724b99fda6f8","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2025-61560","published":"2026-10-09T17:16:41.183","modified":"2026-10-09T17:41:15.270","description":"A race condition vulnerability in the SessionManager of CNCF: Cloud Native Computing Foundation Argo CD v3.0.6 allows attackers to bypass rate limiting and perform a brute force attack via repeated crafted requests.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Argoproj","vendorCategory":"Other vendors","references":[{"url":"https://github.com/argoproj/argo-cd/","label":"github.com","kind":"reference"},{"url":"https://github.com/argoproj/argo-cd/security/advisories/GHSA-4439-h7jw-5cjj","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2016-20098","published":"2026-10-09T17:16:38.583","modified":"2026-10-09T20:17:08.603","description":"Moderator Toolbox (reddit-moderator-toolbox) before 4.0.14 contains a stored cross-site scripting vulnerability in the removalreasons module, which inserts subreddit toolbox wiki fields into popup HTML without encoding. Attackers who can edit the toolbox wiki page can plant JavaScript in fields like pmsubject, header, or reason titles to act with moderators' Reddit sessions.","score":5.1,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Toolbox Team","vendorCategory":"Other vendors","references":[{"url":"https://github.com/toolbox-team/reddit-moderator-toolbox","label":"github.com","kind":"reference"},{"url":"https://github.com/toolbox-team/reddit-moderator-toolbox/commit/26f45ba21d84cecb92b1a820896ad3bf5254376e","label":"github.com","kind":"reference"},{"url":"https://www.vulncheck.com/advisories/moderator-toolbox-before-4.0.14-stored-xss-via-removal-reasons-configuration","label":"vulncheck.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-90983","published":"2026-10-09T16:17:31.947","modified":"2026-10-09T18:17:15.213","description":"Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass.\n\nThis issue affects Hayat Mobile: from 3.3.0 before 3.4.0.","score":8.2,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-603"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1289","label":"siberguvenlik.gov.tr","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-75349","published":"2026-10-09T16:17:29.877","modified":"2026-10-09T16:40:29.800","description":"EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"EIPStackGroup","vendorCategory":"Other vendors","references":[{"url":"https://github.com/EIPStackGroup/OpENer","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/76b95cf/source/src/cip/cipconnectionmanager.c","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/76b95cf/source/src/cip/cipmessagerouter.c","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-75348","published":"2026-10-09T16:17:29.730","modified":"2026-10-09T18:17:13.893","description":"An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognized optional socket address information items of type 0x8000 or 0x8001 without first validating that the remaining CPF buffer contains the complete fixed sockaddr structure. This allows a remote attacker to cause a denial of service.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-125"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"EIPStackGroup","vendorCategory":"Other vendors","references":[{"url":"https://github.com/EIPStackGroup/OpENer/blob/master/source/src/enet_encap/cpf.c","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/master/source/src/enet_encap/encap.c","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/master/source/src/enet_encap/endianconv.c","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-75346","published":"2026-10-09T16:17:29.590","modified":"2026-10-09T21:17:05.800","description":"An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-125"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"EIPStackGroup","vendorCategory":"Other vendors","references":[{"url":"https://github.com/EIPStackGroup/OpENer","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/master/source/src/cip/cipcommon.c","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/master/source/src/cip/cipidentity.c","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-75345","published":"2026-10-09T16:17:29.430","modified":"2026-10-09T17:07:31.693","description":"OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"EIPStackGroup","vendorCategory":"Other vendors","references":[{"url":"https://github.com/EIPStackGroup/OpENer/blob/76b95cf/source/src/cip/cipcommon.c","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/76b95cf/source/src/cip/cipmessagerouter.c","label":"github.com","kind":"reference"},{"url":"https://github.com/EIPStackGroup/OpENer/blob/76b95cf/source/src/cip/ciptcpipinterface.c","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108113","published":"2026-10-09T16:17:26.917","modified":"2026-10-09T16:17:27.067","description":"ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server user.","score":8.7,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-434"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Ilias","vendorCategory":"Other vendors","references":[{"url":"https://docu.ilias.de/go/blog/15821/950","label":"docu.ilias.de","kind":"reference"},{"url":"https://docu.ilias.de/go/blog/15821/951","label":"docu.ilias.de","kind":"reference"},{"url":"https://docu.ilias.de/go/blog/15821/952","label":"docu.ilias.de","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108112","published":"2026-10-09T16:17:26.767","modified":"2026-10-09T16:45:01.980","description":"ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability that allows authenticated users to delete other users' workflows via POST /workflow/del/{uuid}. Attackers can obtain workflow UUIDs from GET /workflow/search and supply them because softDelete() skips the PrivilegeUtil.checkAndGetByUuid() ownership check, removing owners' workflows.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Ageerle","vendorCategory":"Other vendors","references":[{"url":"https://github.com/ageerle/ruoyi-ai","label":"github.com","kind":"reference"},{"url":"https://github.com/ageerle/ruoyi-ai/blob/v3.1.0/ruoyi-modules/ruoyi-aiflow/src/main/java/org/ruoyi/workflow/controller/WorkflowController.java#L55-L59","label":"github.com","kind":"reference"},{"url":"https://github.com/ageerle/ruoyi-ai/blob/v3.1.0/ruoyi-modules/ruoyi-aiflow/src/main/java/org/ruoyi/workflow/service/WorkflowService.java#L204-L207","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108111","published":"2026-10-09T16:17:26.607","modified":"2026-10-09T18:17:06.857","description":"ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability in the GET /workflow/search endpoint that exposes other users' private workflows. Authenticated non-admin users can query this endpoint, which lacks owner or is_public filtering, to list enabled private workflows in the same tenant, including UUIDs and full node and edge configurations.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Ageerle","vendorCategory":"Other vendors","references":[{"url":"https://github.com/ageerle/ruoyi-ai","label":"github.com","kind":"reference"},{"url":"https://github.com/ageerle/ruoyi-ai/blob/v3.1.0/ruoyi-modules/ruoyi-aiflow/src/main/java/org/ruoyi/workflow/controller/WorkflowController.java#L121-L130","label":"github.com","kind":"reference"},{"url":"https://github.com/ageerle/ruoyi-ai/blob/v3.1.0/ruoyi-modules/ruoyi-aiflow/src/main/java/org/ruoyi/workflow/service/WorkflowService.java#L187-L202","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108110","published":"2026-10-09T16:17:26.440","modified":"2026-10-09T17:07:31.693","description":"MOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary object paths. Attackers who know a target's object path can send it to /api/documents/fetch or /api/documents/save-blueprint to read private documents and overwrite presentation blueprints.","score":7.6,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-639"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Himovo","vendorCategory":"Other vendors","references":[{"url":"https://github.com/himovo/movo","label":"github.com","kind":"reference"},{"url":"https://github.com/himovo/movo/blob/v0.2.3/services/chat-api/app/api/endpoints/documents.py#L237-L274","label":"github.com","kind":"reference"},{"url":"https://github.com/himovo/movo/blob/v0.2.3/services/chat-api/app/api/endpoints/documents.py#L91-L109","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107814","published":"2026-10-09T16:17:26.150","modified":"2026-10-09T17:16:45.853","description":"MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home directory. A database user with the FILE privilege could write startup dot-files such as .bash_profile into $HOME, and those files could execute when an administrator opened a login shell for the mysql account. Debian packages are not affected because they use /nonexistent as the account home. This issue is fixed in versions 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2.","score":8.4,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-732"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"MariaDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/MariaDB/server/commit/d842d6e994a8b0d67c280bf785a11357d6b316a2","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.11.19","label":"github.com","kind":"reference"},{"url":"https://github.com/MariaDB/server/releases/tag/mariadb-10.6.28","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107813","published":"2026-10-09T16:17:26.007","modified":"2026-10-09T18:17:02.927","description":"Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecureSession. An authenticated OTP-enabled user possessing a stolen or persisted JWT can therefore perform node CRUD, read or replace node credentials, change namespaces, and invoke nodes/reload_nginx or nodes/restart_nginx without a fresh second-factor step-up. This issue is an incomplete fix for CVE-2026-84315 and is fixed in version 2.5.0.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"0xJacky","vendorCategory":"Other vendors","references":[{"url":"https://github.com/0xJacky/nginx-ui/commit/a3999bd78a3b97ab22e6b5e9fd478ac57598a954","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h246-wpgf-vmq5","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107812","published":"2026-10-09T16:17:25.847","modified":"2026-10-09T20:17:09.743","description":"Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or network attacker able to alter both responses can supply a malicious executable and matching digest. An operator-triggered upgrade is required, and the application installs and runs the attacker-controlled code in the Nginx UI process context on the next upgrade. This issue is fixed in version 2.5.0.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-494"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"0xJacky","vendorCategory":"Other vendors","references":[{"url":"https://github.com/0xJacky/nginx-ui/commit/580585516dd87a8b176bcdac258db70c3b64b7ec","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-662p-52hx-cmh2","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107811","published":"2026-10-09T16:17:25.690","modified":"2026-10-09T16:38:57.820","description":"Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node authentication bypass can expose sensitive management operations, including configuration synchronization and service restart. This issue is fixed in version 2.5.0.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-200","CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"0xJacky","vendorCategory":"Other vendors","references":[{"url":"https://github.com/0xJacky/nginx-ui/commit/0ecbd106c37b5143be14880c9447a66135151512","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-32gc-wf3m-78w9","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107810","published":"2026-10-09T16:17:25.540","modified":"2026-10-09T16:38:57.820","description":"Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Nginx configuration path. An authenticated user who can create and restore backups can craft a valid backup that places a symlink in the staging tree and then writes a regular file through that link, even when both restore flags are false. This can persistently inject configuration or cause denial of service when the modified files are later consumed. This issue is fixed in version 2.5.0.","score":8.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-59","CWE-61"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"0xJacky","vendorCategory":"Other vendors","references":[{"url":"https://github.com/0xJacky/nginx-ui/commit/a467ed652591fc0cd1b466a1ec751b493faef9f7","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-p8v3-89rh-jxc7","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107809","published":"2026-10-09T16:17:25.387","modified":"2026-10-09T17:16:45.730","description":"Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do not universally require a CSRF token or perform Origin or Referer validation, a remote attacker can induce a logged-in administrator's browser to submit authenticated cross-site state-changing requests, including POST /api/configs. The attack requires an administrator account without OTP/Passkey or a target endpoint that does not require secure-session proof. The attacker cannot read the cross-origin response but can modify Nginx configuration, trigger reloads, or invoke other management operations reachable with the victim's session. This issue is fixed in version 2.5.0.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-352"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"0xJacky","vendorCategory":"Other vendors","references":[{"url":"https://github.com/0xJacky/nginx-ui/commit/a3999bd78a3b97ab22e6b5e9fd478ac57598a954","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-33rr-wq23-g6gg","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107808","published":"2026-10-09T16:17:25.237","modified":"2026-10-09T18:17:02.773","description":"Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is therefore issued a session after password verification, despite Enabled2FA reporting that the account has a second factor. An attacker who obtains the password can take over the account and reach administrative functionality without the registered passkey. This issue is fixed in version 2.5.0.","score":8.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-287","CWE-305","CWE-308"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"0xJacky","vendorCategory":"Other vendors","references":[{"url":"https://github.com/0xJacky/nginx-ui/commit/95cd21b70814e5d9a48a359aa238aeea1ac97429","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-45gv-9wjv-xh7p","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107807","published":"2026-10-09T16:17:25.087","modified":"2026-10-09T18:17:02.610","description":"Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Node-Secret header. The credential can consequently appear in access logs, proxy logs, browser history, Referer headers, configuration URLs, and deployment environment data. A party that obtains the secret can bypass normal password, JWT, session, and second-factor checks and obtain persistent administrative API access, including access to configuration and secret material. This issue is fixed in version 2.5.0.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-312","CWE-598"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"0xJacky","vendorCategory":"Other vendors","references":[{"url":"https://github.com/0xJacky/nginx-ui/commit/a3999bd78a3b97ab22e6b5e9fd478ac57598a954","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-pvgv-gcp7-v38g","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107783","published":"2026-10-09T16:17:24.820","modified":"2026-10-09T18:17:02.347","description":"Insertion of sensitive information into log file in AWS Tools for PowerShell before 5.0.306 might allow local users to recover an IAM user's cleartext AWS Management Console password from command output and log artifacts.\n\n\n\nTo remediate this issue, users should upgrade to version 5.0.306 or later. After upgrading, review PowerShell transcripts and log stores for previously disclosed passwords and rotate any affected IAM console passwords.","score":6.7,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-532"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Amazon","vendorCategory":"Other vendors","references":[{"url":"https://aws.amazon.com/security/security-bulletins/2026-132-aws/","label":"aws.amazon.com","kind":"reference"},{"url":"https://github.com/aws/aws-tools-for-powershell/releases/tag/5.0.306","label":"github.com","kind":"reference"},{"url":"https://github.com/aws/aws-tools-for-powershell/security/advisories/GHSA-q3x5-q6rm-c7p3","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104084","published":"2026-10-09T16:17:21.153","modified":"2026-10-09T20:17:09.050","description":"SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the time of demotion, can replay the stale token to obtain a new access token retaining the higher-privilege role (such as DomainAdmin or SysAdmin) until natural token expiry.","score":8.7,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-613"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Smartertools","vendorCategory":"Other vendors","references":[{"url":"https://www.smartertools.com/smartermail/release-notes/current#/9526:~:text=Build%209777%20(Oct%208%2C%202026)","label":"smartertools.com","kind":"reference"},{"url":"https://www.vulncheck.com/advisories/smartermail-build-9777-stale-jwt-role-claim-privilege-escalation-via-refresh-token","label":"vulncheck.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104083","published":"2026-10-09T16:17:20.993","modified":"2026-10-09T17:06:17.770","description":"SmarterMail before build 9777 contains a stored mutation cross-site scripting vulnerability that allows remote attackers to inject executable script by placing payloads inside a <style> element nested within MathML foreign content (<math><mtext><mglyph>), which the custom HTML sanitizer treats as inert CDATA text but browsers reparse as live markup. Attackers can deliver a crafted calendar (iCal) message containing an <img src=x onerror=...> payload that executes automatically in the recipient's webmail session at /interface/message-iframe when the message is opened, enabling script execution and data exfiltration unconstrained by the interface's permissive Content-Security-Policy.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Smartertools","vendorCategory":"Other vendors","references":[{"url":"https://www.smartertools.com/smartermail/release-notes/current#/9526:~:text=Build%209777%20(Oct%208%2C%202026)","label":"smartertools.com","kind":"reference"},{"url":"https://www.vulncheck.com/advisories/smartermail-build-9777-stored-mutation-xss-via-mathml-foreign-content","label":"vulncheck.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104082","published":"2026-10-09T16:17:20.833","modified":"2026-10-09T17:06:17.770","description":"SmarterMail before build 9777 contains a remote code execution vulnerability that allows an attacker holding a SysAdmin-scoped access token to bypass the Volume Mount script-directory containment control by provisioning a new mail domain with an arbitrary FileStore root path inside the trusted Scripts directory via the domain-put endpoint. Attackers can disclose the Scripts path through the AddOrUpdateMount endpoint, clear the upload extension blacklist via the global-mail endpoint, then upload a malicious script through the ordinary mail file-storage upload API so that saving a CommandMount triggers RunScript before validation, resulting in a reverse shell executing as the SmarterMail service account with SYSTEM-level privileges.","score":8.6,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-94"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Smartertools","vendorCategory":"Other vendors","references":[{"url":"https://www.smartertools.com/smartermail/release-notes/current#/9526:~:text=Build%209777%20(Oct%208%2C%202026)","label":"smartertools.com","kind":"reference"},{"url":"https://www.vulncheck.com/advisories/smartermail-build-9777-sysadmin-remote-code-execution-via-volume-mount","label":"vulncheck.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-102554","published":"2026-10-09T16:17:20.410","modified":"2026-10-09T18:17:01.380","description":"Allocation of resources without limits or throttling (CWE-770) during Java object deserialization in Google Guava versions 4.0 through 33.7.1 allows an attacker to cause a Denial of Service via OutOfMemoryError. When deserializing CompactHashMap, CompactHashSet, or MapMakerInternalMap instances, Guava eagerly allocates an array based on a caller-specified size parameter without throttling, permitting memory exhaustion from crafted serialization streams.","score":8.2,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-502","CWE-770"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Google","vendorCategory":"End User Compute","references":[{"url":"https://github.com/google/guava/commit/b931fe9d6d5cf00bc55714ad3308d086f71850fe","label":"github.com","kind":"reference"},{"url":"https://github.com/google/guava/releases/tag/v33.7.2","label":"github.com","kind":"reference"},{"url":"https://github.com/google/guava/security/advisories/GHSA-xxph-c9ww-hj94","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-95702","published":"2026-10-09T15:17:20.447","modified":"2026-10-09T16:35:35.900","description":"Use-after-free vulnerability in VFS in Google gVisor prior to release 20260831.0 on all platforms allows a local attacker with standard container privileges to achieve code execution in the host sentry process by double-freeing the backing MemoryFile from an in-sandbox overlay filesystem. The sentry process remains confined by host-level Linux seccomp and namespace boundaries.","score":8.5,"severity":"HIGH","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-415","CWE-416"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Google","vendorCategory":"End User Compute","references":[{"url":"https://github.com/google/gvisor/commit/25c75149bc0eeaa6a3a49b9bbe3473588b2af6df","label":"github.com","kind":"reference"},{"url":"https://github.com/google/gvisor/commit/90bc4fc36fe442257a06ba15df00371561c183ed","label":"github.com","kind":"reference"},{"url":"https://github.com/google/gvisor/commit/e4efb89c787ef15b09e68d561f1303380e1d5a77","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78796","published":"2026-10-09T15:17:15.947","modified":"2026-10-09T16:40:29.800","description":"An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remote attacker to execute arbitrary code via the www\\cgi-bin\\upgrade file","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"PRISMI Team","vendorCategory":"Other vendors","references":[{"url":"https://github.com/PRISMI-Team/VulnDisclos/blob/main/Routers/Netcore/unauthorized-rce.md","label":"github.com","kind":"reference"},{"url":"https://pastebin.com/vAh2kEeT","label":"pastebin.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78795","published":"2026-10-09T15:17:15.810","modified":"2026-10-09T18:17:14.903","description":"An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remote attacker to obtain sensitive information","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-200"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"B11","vendorCategory":"Other vendors","references":[{"url":"http://b11.com","label":"b11.com","kind":"reference"},{"url":"http://netcore.com","label":"netcore.com","kind":"reference"},{"url":"https://github.com/PRISMI-Team/VulnDisclos/blob/main/Routers/Netcore/sensitive-information-disclosure.md","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-39460","published":"2026-10-09T15:17:14.660","modified":"2026-10-09T17:29:33.410","description":"Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device through a TFTP transfer from the web interface. A TFTP transfer can be initiated through SNMP which does not require authentication.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-522"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-01.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01","label":"cisa.gov","kind":"reference"},{"url":"https://www.hms-networks.com/","label":"hms-networks.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-39453","published":"2026-10-09T15:17:14.500","modified":"2026-10-09T17:29:33.410","description":"Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.","score":8.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-617"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-01.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01","label":"cisa.gov","kind":"reference"},{"url":"https://www.hms-networks.com/","label":"hms-networks.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-33367","published":"2026-10-09T15:17:14.340","modified":"2026-10-09T17:29:33.410","description":"SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-306"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-01.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01","label":"cisa.gov","kind":"reference"},{"url":"https://www.hms-networks.com/","label":"hms-networks.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-33272","published":"2026-10-09T15:17:14.173","modified":"2026-10-09T17:29:33.410","description":"A malicious user with physical access to the device can boot the switch from factory settings without authentication, use the default administrative credentials to obtain administrative access, and save changes to the configuration file so that they persist next time the switch boots normally.","score":6.8,"severity":"MEDIUM","attackVector":"PHYSICAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-288"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-01.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01","label":"cisa.gov","kind":"reference"},{"url":"https://www.hms-networks.com/","label":"hms-networks.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-32645","published":"2026-10-09T15:17:14.017","modified":"2026-10-09T17:29:33.410","description":"Default factory credentials with administrative access are enabled and persist even after configuring other administrator accounts.","score":9.2,"severity":"CRITICAL","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-798"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-01.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01","label":"cisa.gov","kind":"reference"},{"url":"https://www.hms-networks.com/","label":"hms-networks.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-29797","published":"2026-10-09T15:17:13.843","modified":"2026-10-09T17:29:33.410","description":"No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to the device. Additionally, anyone with the same software can scan a network for N-Tron devices and push/pull firmware without authenticating by using SNMP/TFTP.","score":8.4,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-494"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-01.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01","label":"cisa.gov","kind":"reference"},{"url":"https://www.hms-networks.com/","label":"hms-networks.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-28745","published":"2026-10-09T15:17:13.670","modified":"2026-10-09T17:29:33.410","description":"Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-257"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-01.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-01","label":"cisa.gov","kind":"reference"},{"url":"https://www.hms-networks.com/","label":"hms-networks.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-15340","published":"2026-10-09T15:17:13.510","modified":"2026-10-09T17:29:33.410","description":"lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-120"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-279-02.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-279-02","label":"cisa.gov","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108125","published":"2026-10-09T15:17:12.600","modified":"2026-10-09T18:17:07.113","description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author.\n\nThis issue affects wp-post-author version 4.0.0 prior to 4.1.0.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Tenable","vendorCategory":"Other vendors","references":[{"url":"https://www.tenable.com/security/research/tra-2026-62","label":"tenable.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108124","published":"2026-10-09T15:17:12.200","modified":"2026-10-09T18:17:07.000","description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in wp-post-author.\n\nThis issue affects wp-post-author before 4.1.0.","score":4.9,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Tenable","vendorCategory":"Other vendors","references":[{"url":"https://www.tenable.com/security/research/tra-2026-61","label":"tenable.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108109","published":"2026-10-09T15:17:12.047","modified":"2026-10-09T18:17:06.727","description":"PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-307"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Hotspotbilling","vendorCategory":"Other vendors","references":[{"url":"https://github.com/hotspotbilling/phpnuxbill","label":"github.com","kind":"reference"},{"url":"https://github.com/hotspotbilling/phpnuxbill/blob/2025.3.13/system/controllers/forgot.php#L41","label":"github.com","kind":"reference"},{"url":"https://github.com/hotspotbilling/phpnuxbill/commit/c3c2a92d468af91136d747b75142ed72f10320cc","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108108","published":"2026-10-09T15:17:11.887","modified":"2026-10-09T16:45:01.980","description":"PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::chap_verify() returns true when the supplied response does not match. Attackers who know a valid customer or PPPoE username can log in through MikroTik hotspot or PPPoE CHAP with any incorrect password to obtain network access and consume that customer's plan.","score":7.1,"severity":"HIGH","attackVector":"ADJACENT","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-287"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Hotspotbilling","vendorCategory":"Other vendors","references":[{"url":"https://github.com/hotspotbilling/phpnuxbill","label":"github.com","kind":"reference"},{"url":"https://github.com/hotspotbilling/phpnuxbill/blob/2025.3.13/system/autoload/Password.php#L48","label":"github.com","kind":"reference"},{"url":"https://github.com/hotspotbilling/phpnuxbill/security/advisories/GHSA-6f62-x25v-9686","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108107","published":"2026-10-09T15:17:11.713","modified":"2026-10-09T16:45:01.980","description":"PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Hotspotbilling","vendorCategory":"Other vendors","references":[{"url":"https://github.com/hotspotbilling/phpnuxbill","label":"github.com","kind":"reference"},{"url":"https://github.com/hotspotbilling/phpnuxbill/blob/2025.3.13/radius.php#L277","label":"github.com","kind":"reference"},{"url":"https://github.com/hotspotbilling/phpnuxbill/security/advisories/GHSA-q8ch-r8cv-q579","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108106","published":"2026-10-09T15:17:11.550","modified":"2026-10-09T17:06:17.770","description":"Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.uncompress, uncompressString, SnappyInputStream or SnappyFramedInputStream to force allocations up to 2 GB, causing OutOfMemoryError and denial of service.","score":8.7,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-789"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Xerial","vendorCategory":"Other vendors","references":[{"url":"https://github.com/xerial/snappy-java","label":"github.com","kind":"reference"},{"url":"https://github.com/xerial/snappy-java/blob/v1.1.10.8/src/main/java/org/xerial/snappy/Snappy.java#L517","label":"github.com","kind":"reference"},{"url":"https://github.com/xerial/snappy-java/commit/943c6043a292568575e8347af4507d015e802c75","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108105","published":"2026-10-09T15:17:11.380","modified":"2026-10-09T18:17:06.590","description":"Open5GS through 2.8.0 contains a reachable assertion vulnerability in mme_gn_handle_sgsn_context_request() that allows remote unauthenticated attackers to crash the MME via malformed SGSN Address IEs. Attackers sending GTPv1-C traffic from a configured SGSN address with a known UE IMSI or P-TMSI can supply an invalid address length to terminate open5gs-mmed, denying service to all subscribers.","score":8.2,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-617"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Open5gs","vendorCategory":"Other vendors","references":[{"url":"https://github.com/open5gs/open5gs","label":"github.com","kind":"reference"},{"url":"https://github.com/open5gs/open5gs/blob/v2.8.0/src/mme/mme-gn-handler.c#L208-L217","label":"github.com","kind":"reference"},{"url":"https://github.com/open5gs/open5gs/commit/346ce7a5e5cf2812bac3af042b5afba35bcf4f89","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108104","published":"2026-10-09T15:17:11.210","modified":"2026-10-09T17:06:17.770","description":"Xerial snappy-java from 1.1.7.4 before 1.1.10.10 contains a double release vulnerability in SnappyFramedInputStream that returns pooled buffers twice when replacement allocation fails. Attackers can supply framed data with a large declared chunk length to trigger OutOfMemoryError, causing shared backing arrays that expose or overwrite other streams' decompressed data.","score":6.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-415"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Xerial","vendorCategory":"Other vendors","references":[{"url":"https://github.com/xerial/snappy-java","label":"github.com","kind":"reference"},{"url":"https://github.com/xerial/snappy-java/blob/v1.1.10.9/src/main/java/org/xerial/snappy/SnappyFramedInputStream.java#L243","label":"github.com","kind":"reference"},{"url":"https://github.com/xerial/snappy-java/commit/139a53090a6662298924fd75d21f4769b4a219ea","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108103","published":"2026-10-09T15:17:11.043","modified":"2026-10-09T15:17:11.163","description":"Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_dropped_dl_traffic_threshold() that allows remote unauthenticated attackers to read past IE buffers via short IEs. Attackers can send PFCP Session Establishment or Modification Requests to the UPF on UDP port 8805 with DLPA and DLBY flags set, potentially crashing the UPF.","score":6.9,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-125"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Open5gs","vendorCategory":"Other vendors","references":[{"url":"https://github.com/open5gs/open5gs","label":"github.com","kind":"reference"},{"url":"https://github.com/open5gs/open5gs/blob/v2.8.0/lib/pfcp/types.c#L484-L516","label":"github.com","kind":"reference"},{"url":"https://github.com/open5gs/open5gs/commit/88e64fc1f87e0d321364b3bb710ef6a8f274e568","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108102","published":"2026-10-09T15:17:10.850","modified":"2026-10-09T15:17:10.997","description":"Open5GS through 2.8.0 contains a heap out-of-bounds read vulnerability in ogs_pfcp_parse_volume_measurement() in lib/pfcp/types.c that allows remote unauthenticated attackers to read past IE buffers. Attackers can send a PFCP Session Report Request to the SMF on UDP port 8805 with a short, all-flags Volume Measurement IE, reading up to 48 bytes and potentially crashing the SMF.","score":6.9,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-125"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Open5gs","vendorCategory":"Other vendors","references":[{"url":"https://github.com/open5gs/open5gs","label":"github.com","kind":"reference"},{"url":"https://github.com/open5gs/open5gs/blob/v2.8.0/lib/pfcp/types.c#L581-L635","label":"github.com","kind":"reference"},{"url":"https://github.com/open5gs/open5gs/commit/88e64fc1f87e0d321364b3bb710ef6a8f274e568","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108101","published":"2026-10-09T15:17:10.667","modified":"2026-10-09T15:17:10.800","description":"HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cross-site scripting, or PHP files where .htaccess is unenforced to execute code.","score":7.7,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-434"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Danielbrendel","vendorCategory":"Other vendors","references":[{"url":"https://github.com/danielbrendel/hortusfox-web","label":"github.com","kind":"reference"},{"url":"https://github.com/danielbrendel/hortusfox-web/blob/v6.3/app/models/PlantAttachmentModel.php#L28-L31","label":"github.com","kind":"reference"},{"url":"https://github.com/danielbrendel/hortusfox-web/blob/v6.3/app/resources/js/app.js#L466","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108100","published":"2026-10-09T15:17:10.443","modified":"2026-10-09T15:17:10.583","description":"HortusFox (hortusfox-web) before 6.2 contains an SQL injection vulnerability that allows API token holders to inject SQL by supplying crafted include_info values to the /api/locations/list endpoint. Attackers can place subqueries in include_info, which PlantsModel::getSpecificInfo() concatenates into the column list, to read any database table including user password hashes.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Danielbrendel","vendorCategory":"Other vendors","references":[{"url":"https://github.com/danielbrendel/hortusfox-web","label":"github.com","kind":"reference"},{"url":"https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/controller/api.php#L642-L650","label":"github.com","kind":"reference"},{"url":"https://github.com/danielbrendel/hortusfox-web/blob/v6.1/app/models/PlantsModel.php#L1026-L1033","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107806","published":"2026-10-09T15:17:10.150","modified":"2026-10-09T16:38:57.820","description":"Nginx UI is a web user interface for the Nginx web server. From 2.3.8 until 2.5.0, an authenticated administrator with an active secure session can submit attacker-controlled portable backup key material and a matching manifest to POST /api/restore. The restore flow trusts the supplied key, decrypts attacker-controlled contents, and replaces the live app.ini, including protected nginx command settings such as TestConfigCmd. Triggering POST /api/nginx/test then executes the restored command in the Nginx UI runtime context, affecting confidentiality, integrity, and availability. This issue is fixed in version 2.5.0.","score":9.4,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-94"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"0xJacky","vendorCategory":"Other vendors","references":[{"url":"https://github.com/0xJacky/nginx-ui/commit/a467ed652591fc0cd1b466a1ec751b493faef9f7","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.5.0","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-p393-cf76-4jmr","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107805","published":"2026-10-09T15:17:09.960","modified":"2026-10-09T16:38:57.820","description":"Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume temporary filesystem capacity, disk input and output, and request-processing resources before rejection. The issue affects availability and does not bypass authentication or provide confidentiality or integrity impact. This issue is fixed in version 2.6.0.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-400"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"0xJacky","vendorCategory":"Other vendors","references":[{"url":"https://github.com/0xJacky/nginx-ui/commit/8c9b9a1aff218ee6c980d047b750e49da3c46796","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.6.0","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-j3hg-9rp3-5hw9","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107804","published":"2026-10-09T15:17:09.750","modified":"2026-10-09T16:38:57.820","description":"Nginx UI is a web user interface for the Nginx web server. From 2.2.0 until 2.6.0, the bundled reverse proxy does not preserve the external client identity used by Gin because the backend has no trusted proxy configuration. Management requests can be attributed to loopback and pass the IP allowlist loopback exception, although valid credentials are still required. Failed logins from different external clients are also attributed to the same loopback address, allowing an unauthenticated attacker to trigger a shared temporary login ban for password or OTP authentication without invalidating existing sessions. This issue is fixed in version 2.6.0.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-346"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"0xJacky","vendorCategory":"Other vendors","references":[{"url":"https://github.com/0xJacky/nginx-ui/commit/e30e331303fc21cf077a2bea724bd79e66892eaf","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/releases/tag/v2.6.0","label":"github.com","kind":"reference"},{"url":"https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-9h23-53f4-q947","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-105278","published":"2026-10-09T15:17:08.197","modified":"2026-10-09T16:41:53.540","description":"The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administrative control of the application.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-798"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-02.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02","label":"cisa.gov","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104117","published":"2026-10-09T15:17:07.910","modified":"2026-10-09T17:16:44.960","description":"A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.","score":1.9,"severity":"LOW","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Illumos","vendorCategory":"Other vendors","references":[{"url":"https://github.com/illumos/illumos-gate/commit/e8d3efa1c56e5f2b5368600a2baeb7b1d54a07f8","label":"github.com","kind":"reference"},{"url":"https://illumos.org/issues/18492","label":"illumos.org","kind":"reference"},{"url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers","label":"illumos.topicbox.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104116","published":"2026-10-09T15:17:07.750","modified":"2026-10-09T17:16:44.807","description":"A missing authorization check in the illumos zones statistics daemon (zonestatd) allows a local user in any zone to disrupt zonestat in other zones and to determine which zones are running. The zonestatd door server procedure, zsd_server() in usr/src/cmd/zonestat/zonestatd/zonestatd.c, handles the ZSD_CMD_NEW_ZONE command, which is intended to be sent by zoneadmd, without checking the caller's credentials. Because the zonestatd door is accessible to all users in every zone, an unprivileged user can send this command with an arbitrary zone ID, causing zonestatd to re-create its door file in that zone, so that new zonestat requests in that zone can fail while the file is replaced. The time taken to handle the command also reveals whether a given zone ID belongs to a running zone. The flaw has existed since 2010 (illumos-gate commit efd4c9b6), and affects any illumos distribution prior to illumos-gate commit 865b58d2.","score":1.9,"severity":"LOW","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Illumos","vendorCategory":"Other vendors","references":[{"url":"https://github.com/illumos/illumos-gate/commit/865b58d24a0f1a31c838bffc3a7193d3345fe5ba","label":"github.com","kind":"reference"},{"url":"https://illumos.org/issues/18493","label":"illumos.org","kind":"reference"},{"url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers","label":"illumos.topicbox.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104115","published":"2026-10-09T15:17:07.590","modified":"2026-10-09T16:35:35.900","description":"A stack-based buffer overflow in the illumos reparse point daemon (reparsed) allows a local user to crash the daemon. get_fs_locations() in usr/src/cmd/fs.d/nfs/rp_basic/libnfs_basic.c, part of the nfs-basic reparse plugin, copies the host and path components of a reparse string into a fixed 1024-byte stack buffer without checking their length. The reparsed door at /var/run/reparsed_door is readable by all users and the door server does not check the caller's credentials, so an unprivileged local user can send an nfs-basic request with an overlong host or path component to overflow the buffer. On systems built with stack protection, which is the default, this causes reparsed to abort; repeated requests place the svc:/system/filesystem/reparse service into maintenance. The service is disabled by default. The flaw has existed since 2009 (illumos-gate commit 2f172c55), and affects any illumos distribution prior to illumos-gate commit 6a2df4aa.","score":5.4,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-121"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Illumos","vendorCategory":"Other vendors","references":[{"url":"https://github.com/illumos/illumos-gate/commit/6a2df4aa5381599179ab6afb3165db81960dee35","label":"github.com","kind":"reference"},{"url":"https://illumos.org/issues/18496","label":"illumos.org","kind":"reference"},{"url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers","label":"illumos.topicbox.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104114","published":"2026-10-09T15:17:07.430","modified":"2026-10-09T17:16:44.647","description":"A NULL pointer dereference in the illumos Network Auto-Magic daemon (nwamd) allows a local user to crash the daemon. nwamd_door_switch() in usr/src/cmd/cmd-inet/lib/nwamd/door_if.c writes to the caller's request structure before checking that a request was supplied, and before checking the caller's credentials. Because the nwamd door at /etc/svc/volatile/nwam/nwam_door is accessible to all local users, an unprivileged user can issue a door_call() with no argument data to crash nwamd; repeated calls place the svc:/network/physical:nwam service into maintenance, stopping automatic network configuration. nwamd runs only when svc:/network/physical:nwam is enabled, which is not the default. The flaw has existed since 2010 (illumos-gate commit 6ba597c5), and affects any illumos distribution prior to illumos-gate commit 0f1064d9.","score":5.4,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-476"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Illumos","vendorCategory":"Other vendors","references":[{"url":"https://github.com/illumos/illumos-gate/commit/0f1064d97f1a43778ddf87d4e438b99872aed1a0","label":"github.com","kind":"reference"},{"url":"https://illumos.org/issues/18495","label":"illumos.org","kind":"reference"},{"url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers","label":"illumos.topicbox.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104113","published":"2026-10-09T15:17:07.270","modified":"2026-10-09T17:16:44.493","description":"A double free in the IP management daemon (ipmgmtd) of OmniOS and SmartOS allows a local user to crash the daemon. When authorizing a door request that modifies interface configuration, ipmgmt_handler() in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c frees the caller's credential with ucred_free() immediately after reading the user ID, and frees it a second time on the error path if the authorization check fails. An unprivileged local user who does not hold the solaris.network.interface.config authorization can send such a request, for example IPMGMT_CMD_RESETIF, to the ipmgmtd door, causing ipmgmtd to abort; repeated requests place the svc:/network/ip-interface-management service into maintenance, preventing IP interface configuration. The early free was introduced in 2014 to support lx-branded zones (OmniOS commit 4c170900) and is not present in upstream illumos-gate. It affects OmniOS r151020 and later, and SmartOS, prior to the fix.","score":5.4,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-415"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"TritonDataCenter","vendorCategory":"Other vendors","references":[{"url":"https://github.com/TritonDataCenter/illumos-joyent/commit/TBD","label":"github.com","kind":"reference"},{"url":"https://github.com/omniosorg/illumos-omnios/commit/670d853f335203ce8a66126cdbb25bfdba973036","label":"github.com","kind":"reference"},{"url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers","label":"illumos.topicbox.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104112","published":"2026-10-09T15:17:07.100","modified":"2026-10-09T17:16:44.340","description":"A missing release of resources in the illumos name service cache daemon (nscd) allows a local user to exhaust kernel memory. The nscd door server procedure, switcher() in usr/src/cmd/nscd/nscd_frontend.c, does not close file descriptors that are passed with a door call but not used by the request, and the main nscd door at /var/run/name_service_door accepts passed descriptors from any user in its zone. Because nscd also runs with an unlimited file descriptor limit, an unprivileged local user, including one in a non-global zone, can repeatedly pass a descriptor to its zone's nscd in a door_call() loop, causing the file descriptor table of nscd to grow without bound in kernel memory. This causes a denial of service of nscd and can render processes in all zones on the host unresponsive. The flaw has existed since 2006 (illumos-gate commit cb5caa98), and affects any illumos distribution prior to illumos-gate commit af810a72.","score":6.8,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-772"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Illumos","vendorCategory":"Other vendors","references":[{"url":"https://github.com/illumos/illumos-gate/commit/af810a72c09944e884ec695e8dbf1702a4f424ae","label":"github.com","kind":"reference"},{"url":"https://illumos.org/issues/18494","label":"illumos.org","kind":"reference"},{"url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers","label":"illumos.topicbox.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104081","published":"2026-10-09T15:17:06.940","modified":"2026-10-09T18:17:01.517","description":"KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function within app/function/helper.function.php, where a single non-recursive str_replace() sanitization pass can be bypassed using crafted filenames like \"....//\", combined with PclZip's extract() call in KodArchive.class.php lacking the PCLZIP_OPT_EXTRACT_DIR_RESTRICTION option. Authenticated attackers can upload a malicious ZIP archive with traversal sequences to overwrite arbitrary files such as core JavaScript assets, enabling stored XSS that leads to admin account takeover and subsequent remote code execution via unrestricted PHP file upload.","score":7.2,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-22"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Kalcaddle","vendorCategory":"Other vendors","references":[{"url":"https://github.com/kalcaddle/KodExplorer/releases/tag/4.55","label":"github.com","kind":"reference"},{"url":"https://www.vulncheck.com/advisories/kodexplorer-path-traversal-via-unzip-pre-name-zip-extraction","label":"vulncheck.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-102916","published":"2026-10-09T15:17:06.560","modified":"2026-10-09T22:16:55.220","description":"A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefixed MOVS or STOS instruction that accesses guest MMIO, vie_emulate_movs() and vie_emulate_stos() in usr/src/uts/intel/io/vmm/vmm_instruction_emul.c do not clear the VIES_REPEAT status flag on the final iteration. For MMIO regions emulated in the kernel (the local APIC, I/O APIC and HPET), the stale flag causes a VERIFY assertion in vie_advance_pc() to fail, and the host panics. A privileged user within a guest VM can issue a REP MOVS or REP STOS instruction against the local APIC page to cause a denial of service of the host and every other guest running on it. The flaw has existed since 2020 (illumos-gate commit e0c0d44e), and affects any illumos distribution prior to illumos-gate commit 696ecf8d.","score":6.8,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-617"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Illumos","vendorCategory":"Other vendors","references":[{"url":"https://github.com/illumos/illumos-gate/commit/696ecf8debceed9dc33937d8c8e111e4aeebfdae","label":"github.com","kind":"reference"},{"url":"https://illumos.org/issues/18491","label":"illumos.org","kind":"reference"},{"url":"https://illumos.topicbox.com/groups/developer/T697a32b688807e56/cve-2026-102916-18491-bhyve-rep-prefix-instr-emulation-fumbles-flags","label":"illumos.topicbox.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94067","published":"2026-10-09T14:17:26.027","modified":"2026-10-09T20:17:11.363","description":"Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes The Voux thevoux-wp allows PHP Local File Inclusion.This issue affects The Voux: from n/a through 6.9.5.","score":8.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-98"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/thevoux-wp/vulnerability/wordpress-the-voux-theme-6-9-5-local-file-inclusion-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94066","published":"2026-10-09T14:17:25.747","modified":"2026-10-09T18:17:15.440","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SpabRice Pond pond allows Reflected XSS.This issue affects Pond: from n/a through 2.6.1.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/pond/vulnerability/wordpress-pond-theme-2-6-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94065","published":"2026-10-09T14:17:25.497","modified":"2026-10-09T16:40:49.913","description":"Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Injection.This issue affects ColorFolio: from n/a through 1.3.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-502"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/colorit/vulnerability/wordpress-colorfolio-theme-1-3-php-object-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94064","published":"2026-10-09T14:17:25.247","modified":"2026-10-09T16:40:49.913","description":"Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-502"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/neocut/vulnerability/wordpress-neo-barber-shop-wordpress-theme-theme-3-5-php-object-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94063","published":"2026-10-09T14:17:24.990","modified":"2026-10-09T16:40:49.913","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Education Center education allows Reflected XSS.This issue affects Education Center: from n/a through 3.6.12.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/education/vulnerability/wordpress-education-center-theme-3-6-12-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-92085","published":"2026-10-09T14:17:24.847","modified":"2026-10-09T17:16:50.597","description":"Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TMT Machinery Industry and Trade Co. Ltd. Talassoft Industrial Management Software allows Stored XSS.\n\nThis issue affects Talassoft Industrial Management Software: before V16.0.1.","score":5.4,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1288","label":"siberguvenlik.gov.tr","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-85479","published":"2026-10-09T14:17:23.983","modified":"2026-10-09T16:41:53.540","description":"The STTP-based data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and exchange data with it.","score":6.9,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-306"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-02.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02","label":"cisa.gov","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-79363","published":"2026-10-09T14:17:22.777","modified":"2026-10-09T21:17:06.170","description":"Cloudron 9.1.7 and 9.2 contain a stored cross-site scripting (XSS) vulnerability in the Branding Footer feature. An authenticated administrator can store crafted HTML containing JavaScript event handlers in the Footer setting. The stored value is rendered without sufficient sanitization on the public login / OpenID interaction page and in the System Event Log, causing attacker-controlled JavaScript to execute in the Cloudron web origin when an affected page is viewed.","score":5.9,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Faydin","vendorCategory":"Other vendors","references":[{"url":"https://www.faydin.blog/cves/cves.html","label":"faydin.blog","kind":"reference"},{"url":"https://www.faydin.blog/en/cves/CVE-2026-79363/","label":"faydin.blog","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-62026","published":"2026-10-09T14:17:22.170","modified":"2026-10-09T20:17:10.900","description":"Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allows Cross Site Request Forgery.This issue affects Dashboard Notes: from n/a through 1.0.3.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-352"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/dashboard-notes/vulnerability/wordpress-dashboard-notes-plugin-1-0-3-cross-site-request-forgery-csrf-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108063","published":"2026-10-09T14:17:20.130","modified":"2026-10-09T16:37:45.710","description":"A flaw was found in libhangul. When parsing Hanja dictionary files, the library fails to verify that an entry contains a valid value alongside its key. By providing a specially crafted dictionary file to an application that queries it, an attacker can trigger an unexpected application crash, resulting in a Denial of Service (DoS).","score":5.5,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-476"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Red Hat","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-108063","label":"access.redhat.com","kind":"reference"},{"url":"https://github.com/libhangul/libhangul/blob/5094421d9586294b2aad09924b9a54e2e6060f06/hangul/hanja.c","label":"github.com","kind":"reference"},{"url":"https://github.com/libhangul/libhangul/issues/106","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107803","published":"2026-10-09T14:17:19.490","modified":"2026-10-09T18:17:02.487","description":"ProcessMaker is an open source workflow management software suite. Prior to 2026.14.3, the `GET /api/1.0/tasks` endpoint in ProcessMaker is vulnerable to SQL injection through the order_by parameter because `ProcessMaker\\Traits\\TaskControllerIndexMethods::applyColumnOrdering()` concatenates a user-controlled process_requests column name into a DB::raw() SQL subquery without validation or parameter binding. Any authenticated user can use blind, time-based queries to infer and extract data accessible to the ProcessMaker database account. This issue is fixed in version 2026.14.3.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"ProcessMaker","vendorCategory":"Other vendors","references":[{"url":"https://github.com/ProcessMaker/processmaker/commit/2622b7ae810e02c47157028331c45470567e7b79","label":"github.com","kind":"reference"},{"url":"https://github.com/ProcessMaker/processmaker/pull/9041","label":"github.com","kind":"reference"},{"url":"https://github.com/ProcessMaker/processmaker/releases/tag/v2026.14.3","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107785","published":"2026-10-09T14:17:19.227","modified":"2026-10-09T17:16:45.597","description":"Crux Agent from 1.9.0 before 2.0.3 uses the full SKA bilocation key as the WireGuard preshared key. When a peering session negotiates use of SHA-512, the key produced is 64 bytes instead of the 32 bytes WireGuard requires. The agent does not validate this size; instead it attempts to use the `wg set` command to update the live tunnel, and write the invalid key to the WireGuard configuration file. The update fails, so the live tunnel keeps using its previous preshared key until the tunnel is shut down. The tunnel will fail to start when restarted.\n\n\n\nFor a peer which has never successfully negotiated a 32-byte bilocation key in a Crux C2 organization which has the \"Enforce SKA Use\" setting turned off, no preshared key will be set for the tunnel. Therefore, an attacker who is able to intercept and store the peer's traffic, and has access (or will have access) to a cryptographically relevant quantum computer, will be able to decrypt the tunnel.","score":6.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-252","CWE-325","CWE-394"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Sirius","vendorCategory":"Other vendors","references":[{"url":"https://sirius.computer/security-disclosure-policy/","label":"sirius.computer","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-106581","published":"2026-10-09T14:17:18.433","modified":"2026-10-09T17:16:45.270","description":"Before 4.92.0, Docker Desktop for Windows did not verify the signature of a package supplied to Docker Desktop Installer.exe install -package. An attacker able to provide a crafted package and convince a user to approve the Docker-signed UAC prompt could execute attacker-controlled installer actions as LocalSystem.","score":7.3,"severity":"HIGH","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-347"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Docker","vendorCategory":"Other vendors","references":[{"url":"https://docs.docker.com/desktop/release-notes/#4920","label":"docs.docker.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-105281","published":"2026-10-09T14:17:11.450","modified":"2026-10-09T16:41:53.540","description":"The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.","score":8.7,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-306"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-02.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02","label":"cisa.gov","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104629","published":"2026-10-09T14:17:11.027","modified":"2026-10-09T17:16:45.117","description":"A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account.","score":7.7,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-470"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-02.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02","label":"cisa.gov","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-101022","published":"2026-10-09T14:17:10.157","modified":"2026-10-09T17:16:43.127","description":"A Modbus connection feature on openPDC accepts a caller-specified destination address and port with no restriction on which internal hosts may be targeted. An authenticated user can attempt connections to arbitrary internal network destinations, revealing which destinations are reachable. With repeated attempts, an attacker may be able to map the internal network.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-918"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-02.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02","label":"cisa.gov","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-100730","published":"2026-10-09T14:17:09.607","modified":"2026-10-09T16:41:53.540","description":"A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which could allow remote code execution under the privileges of the affected service account.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-502"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Cisagov","vendorCategory":"Other vendors","references":[{"url":"https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-281-02.json","label":"github.com","kind":"reference"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-02","label":"cisa.gov","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96396","published":"2026-10-09T13:17:13.033","modified":"2026-10-09T17:16:51.420","description":"The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not safely calculate the size of an image buffer when generating QuickLook thumbnails and previews of Affinity document files, leading to an integer overflow and a heap-based buffer overflow. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could corrupt heap memory and cause the thumbnail or preview extension to crash.","score":4.9,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-122"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apple","vendorCategory":"End User Compute","references":[{"url":"https://trust.canva.com?tcuUid=1998378a-9134-47e9-b761-7a49d5fd6bfb","label":"trust.canva.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96395","published":"2026-10-09T13:17:12.910","modified":"2026-10-09T17:16:51.310","description":"The Affinity by Canva app for macOS before 3.3.1 (October 2026 release) did not perform adequate bounds checking when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory, including memory addresses, in the rendered thumbnail or preview image.","score":3.6,"severity":"LOW","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-125"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apple","vendorCategory":"End User Compute","references":[{"url":"https://trust.canva.com?tcuUid=1998378a-9134-47e9-b761-7a49d5fd6bfb","label":"trust.canva.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96394","published":"2026-10-09T13:17:12.793","modified":"2026-10-09T17:16:51.197","description":"The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not validate image dimensions against the size of the pixel data when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory in the rendered thumbnail or preview image, or cause the thumbnail or preview extension to crash.","score":2.9,"severity":"LOW","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-126"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apple","vendorCategory":"End User Compute","references":[{"url":"https://trust.canva.com?tcuUid=1998378a-9134-47e9-b761-7a49d5fd6bfb","label":"trust.canva.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96393","published":"2026-10-09T13:17:12.673","modified":"2026-10-09T17:16:51.083","description":"The Affinity by Canva app before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing Affinity document files, leading to an out-of-bounds pointer dereference. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in an application crash.","score":3.6,"severity":"LOW","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-822"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Canva","vendorCategory":"Other vendors","references":[{"url":"https://trust.canva.com?tcuUid=1998378a-9134-47e9-b761-7a49d5fd6bfb","label":"trust.canva.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94062","published":"2026-10-09T13:17:12.423","modified":"2026-10-09T18:17:15.320","description":"Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes Werkstatt werkstatt allows PHP Local File Inclusion.This issue affects Werkstatt: from n/a through 4.8.3.","score":8.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-98"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/werkstatt/vulnerability/wordpress-werkstatt-theme-4-8-3-local-file-inclusion-vulnerability-2?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94061","published":"2026-10-09T13:17:12.113","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designthemes Whistle - Sports Club whistle-sports-club allows Reflected XSS.This issue affects Whistle - Sports Club: from n/a through 4.2.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/whistle-sports-club/vulnerability/wordpress-whistle-sports-club-theme-4-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94060","published":"2026-10-09T13:17:11.880","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Voldor voldor allows Reflected XSS.This issue affects Voldor: from n/a through 1.0.0.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/voldor/vulnerability/wordpress-voldor-theme-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94059","published":"2026-10-09T13:17:11.640","modified":"2026-10-09T16:17:32.197","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Ogency ogency allows Reflected XSS.This issue affects Ogency: from n/a through 1.0.0.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/ogency/vulnerability/wordpress-ogency-theme-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94058","published":"2026-10-09T13:17:11.403","modified":"2026-10-09T20:17:11.253","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Treck treck allows Reflected XSS.This issue affects Treck: from n/a through 1.0.0.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/treck/vulnerability/wordpress-treck-theme-1-0-0-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-8374","published":"2026-10-09T13:17:11.240","modified":"2026-10-09T17:07:31.693","description":"Misuse and misconfiguration in Bluetooth communication in SwitchBot Door Lock Series allows an attacker to bypass the electronic lock and access controls via a manipulated communication protocol.","score":8.5,"severity":"HIGH","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-1204","CWE-1240"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Neodyme","vendorCategory":"Other vendors","references":[{"url":"https://neodyme.io/en/advisories/cve-2026-8374/","label":"neodyme.io","kind":"reference"},{"url":"https://neodyme.io/en/blog/switchbot/","label":"neodyme.io","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-86405","published":"2026-10-09T13:17:11.100","modified":"2026-10-09T13:21:13.267","description":"Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module allows Signature Spoofing by Improper Validation.\n\nThis issue affects PrestaShop Virtual POS Module: from 26.8.1 before 26.9.1.","score":9.8,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-347"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1287","label":"siberguvenlik.gov.tr","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-85531","published":"2026-10-09T13:17:10.957","modified":"2026-10-09T13:21:13.267","description":"Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows Signature Spoofing by Improper Validation.\n\nThis issue affects OpenCart Virtual POS Module: from 26.8.2 before 26.9.1.","score":9.8,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-347"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1286","label":"siberguvenlik.gov.tr","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-62029","published":"2026-10-09T13:17:10.627","modified":"2026-10-09T18:17:13.550","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels Team WPFunnels wpfunnels allows Stored XSS.This issue affects WPFunnels: from n/a through 3.13.3.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/wpfunnels/vulnerability/wordpress-wpfunnels-plugin-3-13-3-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-62028","published":"2026-10-09T13:17:10.390","modified":"2026-10-09T13:20:48.273","description":"Missing Authorization vulnerability in bPlugins Before After Image Comparison – Image comparison for WP before-after-image-compare allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Before After Image Comparison – Image comparison for WP: from n/a through 1.1.21.","score":5.4,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/before-after-image-compare/vulnerability/wordpress-before-after-image-comparison-image-comparison-for-wp-plugin-1-1-21-broken-access-control-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-106602","published":"2026-10-09T13:17:09.930","modified":"2026-10-09T13:20:48.273","description":"Authentication Bypass Using an Alternate Path or Channel vulnerability in Automattic Jetpack jetpack allows Password Recovery Exploitation.This issue affects Jetpack: from n/a through 16.2.","score":4.8,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-288"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/jetpack/vulnerability/wordpress-jetpack-plugin-16-2-broken-authentication-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-106601","published":"2026-10-09T13:17:09.690","modified":"2026-10-09T16:17:21.680","description":"Authentication Bypass Using an Alternate Path or Channel vulnerability in Automattic Jetpack jetpack allows Password Recovery Exploitation.This issue affects Jetpack: from n/a through 16.2.","score":5.4,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-288"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/jetpack/vulnerability/wordpress-jetpack-plugin-16-2-broken-authentication-vulnerability-2?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-105883","published":"2026-10-09T13:17:09.447","modified":"2026-10-09T20:17:09.510","description":"Missing Authorization vulnerability in ThemeHunk Th Shop Mania th-shop-mania allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Th Shop Mania: from n/a through 1.9.1.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/th-shop-mania/vulnerability/wordpress-th-shop-mania-theme-1-9-1-broken-access-control-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-105877","published":"2026-10-09T13:17:09.200","modified":"2026-10-09T18:17:01.733","description":"Insertion of Sensitive Information Into Sent Data vulnerability in QuarkA QA Analytics qa-heatmap-analytics allows Retrieve Embedded Sensitive Data.This issue affects QA Analytics: from n/a through 5.3.0.0.","score":6.9,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-201"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/qa-heatmap-analytics/vulnerability/wordpress-qa-analytics-plugin-5-3-0-0-sensitive-data-exposure-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-105872","published":"2026-10-09T13:17:08.957","modified":"2026-10-09T13:20:48.273","description":"Deserialization of Untrusted Data vulnerability in mklacroix Product Configurator for WooCommerce product-configurator-for-woocommerce allows Object Injection.This issue affects Product Configurator for WooCommerce: from n/a through 1.7.5.","score":7.2,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-502"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/product-configurator-for-woocommerce/vulnerability/wordpress-product-configurator-for-woocommerce-plugin-1-7-5-php-object-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-105870","published":"2026-10-09T13:17:08.710","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Delight Star Inc. WP Associate Post R2 wp-associate-post-r2 allows Reflected XSS.This issue affects WP Associate Post R2: from n/a through 5.0.1.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/wp-associate-post-r2/vulnerability/wordpress-wp-associate-post-r2-plugin-5-0-1-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-105318","published":"2026-10-09T13:17:08.470","modified":"2026-10-09T16:17:21.303","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Datasolution AcyMailing SMTP Newsletter acymailing allows Reflected XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through 11.1.0.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/acymailing/vulnerability/wordpress-acymailing-smtp-newsletter-plugin-11-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104392","published":"2026-10-09T13:17:08.227","modified":"2026-10-09T21:17:02.470","description":"Deserialization of Untrusted Data vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Object Injection.This issue affects Quiz And Survey Master: from n/a through 11.2.7.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-502"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/quiz-master-next/vulnerability/wordpress-quiz-and-survey-master-plugin-11-2-7-php-object-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104079","published":"2026-10-09T13:17:07.987","modified":"2026-10-09T17:06:17.770","description":"Envira Gallery Lite before 1.16.2 contains a missing authorization vulnerability in its gallery conversion REST endpoint that allows lower-privileged authenticated users to create and publish Envira galleries without the required capabilities, because the endpoint only checks edit permissions on the source post and uses a hard-coded publish status. Attackers can also supply arbitrary caller-controlled image IDs without ownership verification to publish unauthorized content using attachments they are not authorized to use.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Lazytitan","vendorCategory":"Other vendors","references":[{"url":"https://lazytitan.ro/envira","label":"lazytitan.ro","kind":"reference"},{"url":"https://wordpress.org/plugins/envira-gallery-lite/#developers","label":"wordpress.org","kind":"reference"},{"url":"https://www.vulncheck.com/advisories/envira-gallery-lite-missing-authorization-via-gallery-conversion-rest-endpoint","label":"vulncheck.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-103413","published":"2026-10-09T13:17:07.633","modified":"2026-10-09T16:33:39.007","description":"Improper input validation vulnerability in Apache Camel Karavan.\n\n\n\nWhen a deployment was started, Karavan unmarshalled a project's `kubernetes.yaml` and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting security-sensitive pod options, and without pinning the target namespace. An authenticated user of any role could therefore have Karavan apply arbitrary Kubernetes resources within the reach of its service account, including pods requesting hostNetwork, hostPID, hostIPC, hostPath volumes, host ports, privileged containers, privilege escalation or added capabilities.\n\n\n\nThis issue affects Apache Camel Karavan: from 4.0.0 before 4.22.1.\n\n\n\nUsers are recommended to upgrade to version 4.22.1, which fixes the issue.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-20"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://camel.apache.org/security/CVE-2026-103413.html","label":"camel.apache.org","kind":"reference"},{"url":"https://github.com/apache/camel-karavan/commit/a773db372eab9f180110ad6129d58004a1bce571","label":"github.com","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/17","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-103412","published":"2026-10-09T13:17:07.453","modified":"2026-10-09T16:33:39.007","description":"Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan.\n\n\n\nA project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any location writable by the Karavan process. An authenticated user of any role could use this to overwrite application configuration or files on the application classpath and so execute code in the Karavan container.\n\n\n\nThis issue affects Apache Camel Karavan: from 3.18.0 before 4.22.1.\n\n\n\nUsers are recommended to upgrade to version 4.22.1, which fixes the issue.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-22"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://camel.apache.org/security/CVE-2026-103412.html","label":"camel.apache.org","kind":"reference"},{"url":"https://github.com/apache/camel-karavan/commit/5e4252494817af0cd2697216bd02f361037fedcf","label":"github.com","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/16","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-103220","published":"2026-10-09T13:17:07.330","modified":"2026-10-09T17:16:43.670","description":"The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing raster image data in Affinity document files, leading to an out-of-bounds read and the dereference of an untrusted pointer. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in memory corruption or an application crash.","score":4.5,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-129"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Canva","vendorCategory":"Other vendors","references":[{"url":"https://trust.canva.com?tcuUid=1998378a-9134-47e9-b761-7a49d5fd6bfb","label":"trust.canva.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-101130","published":"2026-10-09T13:17:07.037","modified":"2026-10-09T17:16:43.397","description":"The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing arrays of strings in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.","score":3.6,"severity":"LOW","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-126"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Canva","vendorCategory":"Other vendors","references":[{"url":"https://trust.canva.com?tcuUid=1998378a-9134-47e9-b761-7a49d5fd6bfb","label":"trust.canva.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-101094","published":"2026-10-09T13:17:05.890","modified":"2026-10-09T17:16:43.273","description":"The Affinity by Canva application before 3.3.1 (October 2026 release) did not correctly handle incomplete UTF-8 character sequences when parsing text in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.","score":3.6,"severity":"LOW","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-126"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Canva","vendorCategory":"Other vendors","references":[{"url":"https://trust.canva.com?tcuUid=1998378a-9134-47e9-b761-7a49d5fd6bfb","label":"trust.canva.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-89235","published":"2026-10-09T12:17:12.983","modified":"2026-10-09T15:17:19.660","description":"The Testimonials by BestWebSoft WordPress plugin through 1.0.8 does not sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to append additional SQL to the query.","score":6.8,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/00801815-efc8-41f7-9984-0e81698c7f68/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-87846","published":"2026-10-09T12:17:12.860","modified":"2026-10-09T15:17:18.963","description":"The Shipping for Nova Poshta WordPress plugin through 1.19.8 does not perform any authorisation, nonce or ownership checks on one of its AJAX actions available to unauthenticated users, allowing anyone to delete the shipment records of arbitrary orders and to make the store issue the carrier's waybill-deletion request for those orders using the store's own stored API credentials.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/e1ba1fbc-f61f-446f-a312-d725364313a6/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-86851","published":"2026-10-09T12:17:12.737","modified":"2026-10-09T15:17:18.657","description":"The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticated users to change the status of arbitrary orders, store arbitrary data and notes on them, and recover their order keys.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/c9730831-54a3-4307-94c9-e994337a943c/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-85348","published":"2026-10-09T12:17:12.500","modified":"2026-10-09T15:17:18.367","description":"The GDPR Data Request Form WordPress plugin through 1.7.1 does not have CSRF protection when updating one of its settings, allowing attackers to change that setting via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","score":4.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-352"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/710ae5af-01bb-43e8-a853-df00a1ceacab/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-62042","published":"2026-10-09T12:17:11.213","modified":"2026-10-09T20:17:11.003","description":"Missing Authorization vulnerability in unFocus Projects Scripts n Styles scripts-n-styles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scripts n Styles: from n/a through 3.5.8.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/scripts-n-styles/vulnerability/wordpress-scripts-n-styles-plugin-3-5-8-broken-access-control-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-62041","published":"2026-10-09T12:17:11.080","modified":"2026-10-09T18:17:13.777","description":"Missing Authorization vulnerability in Ashok Dudhat WP Event Manager wp-event-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Event Manager: from n/a through 3.4.1.","score":5.4,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/wp-event-manager/vulnerability/wordpress-wp-event-manager-plugin-3-4-1-broken-access-control-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-62040","published":"2026-10-09T12:17:10.940","modified":"2026-10-09T18:17:13.660","description":"Missing Authorization vulnerability in DEV Institute Restrict User Access – Membership Plugin with Force restrict-user-access allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict User Access – Membership Plugin with Force: from n/a through 2.8.1.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/restrict-user-access/vulnerability/wordpress-restrict-user-access-membership-plugin-with-force-plugin-2-8-1-broken-access-control-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-62039","published":"2026-10-09T12:17:10.810","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player html5-audio-player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.8.8.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/html5-audio-player/vulnerability/wordpress-html5-audio-player-plugin-2-8-8-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-62036","published":"2026-10-09T12:17:10.660","modified":"2026-10-09T13:20:48.273","description":"Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in AREOI All Bootstrap Blocks all-bootstrap-blocks allows Retrieve Embedded Sensitive Data.This issue affects All Bootstrap Blocks: from n/a through 1.3.31.","score":4.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-497"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/all-bootstrap-blocks/vulnerability/wordpress-all-bootstrap-blocks-plugin-1-3-31-sensitive-data-exposure-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-39779","published":"2026-10-09T12:17:10.513","modified":"2026-10-09T16:17:28.443","description":"Missing Authorization vulnerability in Asgaros Asgaros Forum asgaros-forum allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Asgaros Forum: from n/a through 3.4.0.","score":4.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/asgaros-forum/vulnerability/wordpress-asgaros-forum-plugin-3-4-0-broken-access-control-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107419","published":"2026-10-09T12:17:08.870","modified":"2026-10-09T13:20:48.273","description":"Missing Authorization vulnerability in Cool Plugins AI Translation for Polylang automatic-translations-for-polylang allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI Translation for Polylang: from n/a through 1.6.2.","score":5.4,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/automatic-translations-for-polylang/vulnerability/wordpress-ai-translation-for-polylang-plugin-1-6-2-broken-access-control-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-103329","published":"2026-10-09T12:17:07.437","modified":"2026-10-09T15:17:06.813","description":"The Super Payments WordPress plugin before 1.43.1 does not properly verify the authenticity of incoming payment webhook notifications, as the signing key used to validate their signature is empty by default, allowing unauthenticated attackers to forge a valid signature and mark arbitrary WooCommerce orders as paid without payment.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-347"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/aefba87d-fa4c-4b7c-9436-6e79e966e8a5/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-97791","published":"2026-10-09T11:17:03.380","modified":"2026-10-09T16:33:39.007","description":"In Apache CXF, STSTokenValidator checks whether a SAML assertion is signed by a trusted certificate before deciding to send it to the STS. That result was stored in one object shared by all requests, so one request could read another's result. A remote, unauthenticated attacker could send a forged assertion signed with an untrusted certificate while legitimate requests were being processed, and it could be accepted as trusted without ever reaching the STS. Only services that use STSTokenValidator to validate SAML tokens without alwaysValidateToSts set are affected. \nUsers are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://lists.apache.org/thread.html/ssdr417qgms9fjl0m8802xd8170wnk1l","label":"lists.apache.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/10","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-97468","published":"2026-10-09T11:17:03.270","modified":"2026-10-09T16:33:39.007","description":"Apache CXF's STSTokenValidator and Security Token Service (STS) cached validated security tokens under a non-cryptographic 32-bit hash of the token (Java Arrays.hashCode/hashCode()), and treated a cache hit as proof that the presented token had already been validated. An attacker could craft a token (for example a UsernameToken or a self-signed SAML Assertion) whose hash collides with a cached entry. The token would then be accepted without password validation, signature trust verification or a call to the STS. This could let the attacker authenticate as another user and, through STS token validation or renewal, obtain STS-signed tokens for that identity.\nUsers are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://lists.apache.org/thread.html/qthbnsyhqsxhl9p2h9v5dg4mnwv1b9r6","label":"lists.apache.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/9","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-86463","published":"2026-10-09T11:17:03.163","modified":"2026-10-09T16:33:39.007","description":"Apache CXF's FIQL query parser has a vulnerability in how it searches for operators in query expressions. The search pattern can get stuck trying many combinations when it encounters a long string without an operator, causing the parser to consume excessive CPU time. An attacker can send a crafted query to make the server use up CPU resources, potentially slowing down or stopping other requests. The fix was to limit FIQL expressions to 4 KiB by default, preventing attackers from sending extremely long inputs while still allowing normal queries.\n\nUsers are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://lists.apache.org/thread.html/mv5qfmd27gkbvt3k6by9db5bolrsbgy1","label":"lists.apache.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/8","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-79650","published":"2026-10-09T11:17:03.043","modified":"2026-10-09T16:33:39.007","description":"Apache CXF’s OIDC relying-party component could redirect users to an attacker-controlled URL after successful authentication. The issue occurs because attacker-controlled state parameters are preserved and later used as redirect targets without validating that the final decoded URI belongs to the RP’s origin. Both directly encoded and double-encoded external URLs can trigger the issue, depending on which validation path is used. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-601"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://lists.apache.org/thread.html/xj0x1r617j1z8jtyypngvwhckb3o205h","label":"lists.apache.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/7","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78384","published":"2026-10-09T11:17:02.937","modified":"2026-10-09T16:33:39.007","description":"CompressionUtils.inflate() decompressed attacker-controlled DEFLATE data with no output-size cap. A small (~KB) crafted payload could expand to gigabytes on the heap. Reachable via JWE decryption when zip=DEF (e.g. JoseSessionTokenProvider with RSA-OAEP key wrap) and via SAML redirect/POST binding token inflation — in both cases decompression happens before/independent of trust validation.\n\nFix: Added a configurable maximum inflated-size cap (default 10 MiB, org.apache.cxf.compression-max-inflated-size system property) to CompressionUtils.inflate(); aborts with DataFormatException once exceeded.\nUsers are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://lists.apache.org/thread.html/xoh63rlxn0m9koft5j4jxrfd0hf81v3q","label":"lists.apache.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/6","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-73179","published":"2026-10-09T11:17:02.817","modified":"2026-10-09T16:33:39.007","description":"Improper enforcement of single-use authorization code semantics in the JPA OAuth2 authorization code grant provider in Apache CXFallows a remote attacker to obtain multiple valid access tokens from a single authorization code via concurrent token exchange requests that race the non-atomic find-then-delete operation against a shared relational database under READ_COMMITTED isolation. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fixes this issue.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-367"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://lists.apache.org/thread.html/6msbm601o6ogfgdzdbtbrmgspmz50nxk","label":"lists.apache.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/5","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-71575","published":"2026-10-09T11:17:02.690","modified":"2026-10-09T16:33:39.007","description":"The max_age authentication-freshness check in OidcClientCodeRequestFilter was inoperative due to a milliseconds/seconds unit mismatch and an inverted comparison polarity. Any relying party using setMaxAgeOffset to enforce re-authentication would silently accept sessions of any age, bypassing step-up authentication policies. Users are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-613"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://lists.apache.org/thread/p1r9t4xl8ny7rg8wmj8nrygx35ds6vcs","label":"lists.apache.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/4","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-108039","published":"2026-10-09T11:17:02.387","modified":"2026-10-09T16:33:39.007","description":"By default, StaxUtils placed no limit on the total number of elements or the total number of characters in an XML document. A very large request could therefore use a lot of memory and CPU during parsing, especially where CXF builds a DOM from the input (for example SAAJ or WS-Security), and could cause a denial of service when no request size limit was configured. Both limits now have defaults: the maximum element count is 100 × maxChildElements (5,000,000 by default), and the maximum document size is 256M characters. Applications that process larger documents can raise the limits with the org.apache.cxf.stax.maxElementCount and org.apache.cxf.stax.maxXMLCharacters properties.\nUsers are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://lists.apache.org/thread.html/ms2gbpof609o0v1bjlzb1rn7fwh61l1j","label":"lists.apache.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/14","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107938","published":"2026-10-09T11:17:02.213","modified":"2026-10-09T16:33:39.007","description":"In Apache CXF, the Netty-based HTTP client transport (cxf-rt-transports-http-netty-client) did not verify that the hostname in the server’s TLS certificate matched the host being called. This applied over both HTTP/1.1 and HTTP/2, even when disableCNCheck was left at its default value of false. The certificate chain was validated against the configured trust store, but the endpoint’s identity was not. A network attacker able to intercept traffic could present any certificate trusted by the client, such as a publicly issued certificate for a domain they control, and impersonate the target service. They could then read or modify the exchanged messages, including credentials. \nUsers are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://lists.apache.org/thread.html/ljsjsq1foyjy1v5o22oncw80twx7k2tc","label":"lists.apache.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/13","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107937","published":"2026-10-09T11:17:02.107","modified":"2026-10-09T16:33:39.007","description":"In Apache CXF, the parser for multipart/MTOM attachment part headers did not fully enforce the configured attachment-max-header-size (default 300 characters) and attachment-headers-max-count (default 500) limits. The size limit was applied only to each physical line, not to a header value built from continuation lines or to the combined values of a repeated header. The count limit was checked against the number of distinct header names, not the total number of header lines. A remote, unauthenticated attacker could send a multipart request with very large folded or repeated part headers. The server would then allocate memory without bound, causing a denial of service. \nUsers are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://lists.apache.org/thread.html/x9twtpv3d04qj83t6w9xkh9y2q28zztj","label":"lists.apache.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/12","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-100227","published":"2026-10-09T11:17:01.993","modified":"2026-10-09T16:33:39.007","description":"Improper Verification of Cryptographic Signature vulnerability in Apache CXF's JAX-RS XML Security module. The JAX-RS XML Signature interceptors (XmlSigInHandler, XmlSigInInterceptor and the streaming XmlSecInInterceptor) did not ensure that the XML passed to the application was covered by the signature. An attacker with any document signed by a trusted key could wrap it in unsigned content, which the application would then treat as signed.\nUsers are recommended to upgrade to versions 4.2.4 or 4.1.9 or 3.6.13, which fix this issue.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Apache","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://lists.apache.org/thread.html/pst2oopnwt2rwhvkvmt5gdgwn36kq05m","label":"lists.apache.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/11","label":"openwall.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96809","published":"2026-10-09T10:16:45.980","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MultiNet Interactive AB EduAdmin Booking eduadmin-booking allows Blind SQL Injection.This issue affects EduAdmin Booking: from n/a before 6.0.0.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/eduadmin-booking/vulnerability/wordpress-eduadmin-booking-plugin-6-0-0-sql-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96761","published":"2026-10-09T10:16:45.840","modified":"2026-10-09T16:17:33.497","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Welcart Welcart e-Commerce usc-e-shop allows Reflected XSS.This issue affects Welcart e-Commerce: from n/a through 2.12.3.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/usc-e-shop/vulnerability/wordpress-welcart-e-commerce-plugin-2-12-3-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96671","published":"2026-10-09T10:16:45.697","modified":"2026-10-09T21:17:08.080","description":"Cross-Site Request Forgery (CSRF) vulnerability in fifu.app Featured Image from URL featured-image-from-url allows Cross Site Request Forgery.This issue affects Featured Image from URL: from n/a through 6.0.7.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-352"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/featured-image-from-url/vulnerability/wordpress-featured-image-from-url-plugin-6-0-7-cross-site-request-forgery-csrf-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96607","published":"2026-10-09T10:16:45.557","modified":"2026-10-09T18:17:16.483","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Reflected XSS.This issue affects NEX-Forms: from n/a through 9.3.1.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/nex-forms-express-wp-form-builder/vulnerability/wordpress-nex-forms-plugin-9-3-1-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96553","published":"2026-10-09T10:16:45.420","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Damian Góra FiboSearch ajax-search-for-woocommerce allows Reflected XSS.This issue affects FiboSearch: from n/a through 1.34.1.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/ajax-search-for-woocommerce/vulnerability/wordpress-fibosearch-plugin-1-34-1-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96539","published":"2026-10-09T10:16:45.280","modified":"2026-10-09T13:20:48.273","description":"Incorrect Privilege Assignment vulnerability in Ultimate Member Ultimate Member ultimate-member allows Privilege Escalation.This issue affects Ultimate Member: from n/a through 2.13.1.","score":5.6,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-266"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/ultimate-member/vulnerability/wordpress-ultimate-member-plugin-2-13-1-privilege-escalation-vulnerability-2?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96518","published":"2026-10-09T10:16:45.143","modified":"2026-10-09T16:17:33.363","description":"Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.17.3.","score":5.9,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/wp-user-avatar/vulnerability/wordpress-profilepress-plugin-4-17-3-broken-access-control-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96461","published":"2026-10-09T10:16:45.000","modified":"2026-10-09T21:17:07.970","description":"Missing Authorization vulnerability in TMS Amelia ameliabooking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Amelia: from n/a through 2.4.10.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/ameliabooking/vulnerability/wordpress-amelia-plugin-2-4-10-broken-access-control-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96337","published":"2026-10-09T10:16:44.863","modified":"2026-10-09T18:17:16.370","description":"Missing Authorization vulnerability in properfraction ProfilePress wp-user-avatar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfilePress: from n/a through 4.17.3.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/wp-user-avatar/vulnerability/wordpress-profilepress-plugin-4-17-3-broken-access-control-vulnerability-2?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96336","published":"2026-10-09T10:16:44.730","modified":"2026-10-09T13:20:48.273","description":"Authentication Bypass by Spoofing vulnerability in WPMU DEV Forminator forminator allows Identity Spoofing.This issue affects Forminator: from n/a through 1.57.2.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-290"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/forminator/vulnerability/wordpress-forminator-plugin-1-57-2-payment-bypass-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96334","published":"2026-10-09T10:16:44.597","modified":"2026-10-09T13:20:48.273","description":"Missing Authorization vulnerability in ThemeGrill User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 5.2.7.","score":5.6,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/user-registration/vulnerability/wordpress-user-registration-plugin-5-2-7-broken-access-control-vulnerability-2?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96333","published":"2026-10-09T10:16:44.460","modified":"2026-10-09T16:17:33.230","description":"Authentication Bypass by Spoofing vulnerability in Liquid Web / StellarWP GiveWP give allows Identity Spoofing.This issue affects GiveWP: from n/a through 4.16.8.1.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-290"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/give/vulnerability/wordpress-givewp-plugin-4-16-8-1-payment-bypass-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96332","published":"2026-10-09T10:16:44.320","modified":"2026-10-09T21:17:07.847","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yalla ya! Simple Payment simple-payment allows Reflected XSS.This issue affects Simple Payment: from n/a through 2.5.4.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/simple-payment/vulnerability/wordpress-simple-payment-plugin-2-5-4-cross-site-scripting-xss-vulnerability-2?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96331","published":"2026-10-09T10:16:44.167","modified":"2026-10-09T18:17:16.250","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdreams Ajax Search Pro ajax-search-pro allows Blind SQL Injection.This issue affects Ajax Search Pro: from n/a through 4.29.1.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/ajax-search-pro/vulnerability/wordpress-ajax-search-pro-plugin-4-29-1-sql-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96330","published":"2026-10-09T10:16:43.917","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows Blind SQL Injection.This issue affects tagDiv Opt-In Builder: from n/a through 1.7.6.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/td-subscription/vulnerability/wordpress-tagdiv-opt-in-builder-plugin-1-7-6-sql-injection-vulnerability-2?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96329","published":"2026-10-09T10:16:43.740","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows Blind SQL Injection.This issue affects tagDiv Opt-In Builder: from n/a through 1.7.6.","score":8.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/td-subscription/vulnerability/wordpress-tagdiv-opt-in-builder-plugin-1-7-6-sql-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96328","published":"2026-10-09T10:16:43.600","modified":"2026-10-09T16:17:33.083","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in jegtheme JNews - Pay Writer jnews-pay-writer allows Blind SQL Injection.This issue affects JNews - Pay Writer: from n/a through 12.0.1.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/jnews-pay-writer/vulnerability/wordpress-jnews-pay-writer-plugin-12-0-1-sql-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-96327","published":"2026-10-09T10:16:43.460","modified":"2026-10-09T21:17:07.733","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Blind SQL Injection.This issue affects WPLMS: from n/a before 1.9.9.8.2.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/wplms_plugin/vulnerability/wordpress-wplms-plugin-1-9-9-8-2-sql-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-95610","published":"2026-10-09T10:16:43.330","modified":"2026-10-09T18:17:16.137","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UpSolution UpSolution Core us-core allows Blind SQL Injection.This issue affects UpSolution Core: from n/a through 9.3.","score":8.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/us-core/vulnerability/wordpress-upsolution-core-plugin-9-3-sql-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-95609","published":"2026-10-09T10:16:43.193","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Stored XSS.This issue affects Media LIbrary Assistant: from n/a through 3.41.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/media-library-assistant/vulnerability/wordpress-media-library-assistant-plugin-3-41-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-95608","published":"2026-10-09T10:16:43.053","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginUs.Net HUSKY woocommerce-products-filter allows Reflected XSS.This issue affects HUSKY: from n/a through 1.4.3.2.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/woocommerce-products-filter/vulnerability/wordpress-husky-plugin-1-4-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-95607","published":"2026-10-09T10:16:42.917","modified":"2026-10-09T16:17:32.950","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS  wplms allows Blind SQL Injection.This issue affects WPLMS : from n/a through 4.973.","score":8.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/wplms/vulnerability/wordpress-wplms-theme-4-973-sql-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-95599","published":"2026-10-09T10:16:42.780","modified":"2026-10-09T21:17:07.620","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Taskbuilder Taskbuilder taskbuilder allows Blind SQL Injection.This issue affects Taskbuilder: from n/a through 6.0.5.","score":8.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/taskbuilder/vulnerability/wordpress-taskbuilder-plugin-6-0-5-sql-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-95598","published":"2026-10-09T10:16:42.643","modified":"2026-10-09T18:17:16.020","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Search in Place search-in-place allows Reflected XSS.This issue affects Search in Place: from n/a through 1.5.5.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/search-in-place/vulnerability/wordpress-search-in-place-plugin-1-5-5-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-95597","published":"2026-10-09T10:16:42.510","modified":"2026-10-09T13:20:48.273","description":"Missing Authorization vulnerability in codemstory 워드프레스 결제 심플페이 pgall-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects 워드프레스 결제 심플페이: from n/a through 5.5.17.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/pgall-for-woocommerce/vulnerability/wordpress-plugin-5-5-17-settings-change-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-95596","published":"2026-10-09T10:16:42.370","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mamunur Rashid ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder allows Reflected XSS.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through 3.4.1.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/shopbuilder/vulnerability/wordpress-shopbuilder-elementor-woocommerce-builder-addons-plugin-3-4-1-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-95591","published":"2026-10-09T10:16:42.237","modified":"2026-10-09T16:17:32.810","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikbooking allows Reflected XSS.This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.14.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/vikbooking/vulnerability/wordpress-vikbooking-hotel-booking-engine-pms-plugin-1-8-14-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-95589","published":"2026-10-09T10:16:42.097","modified":"2026-10-09T21:17:07.510","description":"Missing Authorization vulnerability in Magepeople inc. Deposits and Partial Payments for WooCommerce advanced-partial-payment-or-deposit-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Deposits and Partial Payments for WooCommerce: from n/a through 4.0.1.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/advanced-partial-payment-or-deposit-for-woocommerce/vulnerability/wordpress-deposits-and-partial-payments-for-woocommerce-plugin-4-0-1-broken-access-control-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94668","published":"2026-10-09T10:16:41.957","modified":"2026-10-09T18:17:15.910","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Reflected XSS.This issue affects Salon booking system: from n/a through 10.31.5.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/salon-booking-system/vulnerability/wordpress-salon-booking-system-plugin-10-31-5-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94667","published":"2026-10-09T10:16:41.823","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetReviews jet-reviews allows Stored XSS.This issue affects JetReviews: from n/a through 3.1.2.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/jet-reviews/vulnerability/wordpress-jetreviews-plugin-3-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94666","published":"2026-10-09T10:16:41.690","modified":"2026-10-09T13:20:48.273","description":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-pdf-using-contact-form-7 allows Path Traversal.This issue affects Generate PDF using Contact Form 7: from n/a through 4.2.1.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-22"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/generate-pdf-using-contact-form-7/vulnerability/wordpress-generate-pdf-using-contact-form-7-plugin-4-2-1-arbitrary-file-download-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94665","published":"2026-10-09T10:16:41.557","modified":"2026-10-09T16:17:32.687","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mamunur Rashid Classified Listing classified-listing allows Stored XSS.This issue affects Classified Listing: from n/a through 6.1.2.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/classified-listing/vulnerability/wordpress-classified-listing-plugin-6-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94664","published":"2026-10-09T10:16:41.420","modified":"2026-10-09T21:17:07.393","description":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org PDF for Contact Form 7 pdf-for-contact-form-7 allows Path Traversal.This issue affects PDF for Contact Form 7: from n/a through 7.1.0.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-22"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/pdf-for-contact-form-7/vulnerability/wordpress-pdf-for-contact-form-7-plugin-7-1-0-arbitrary-file-download-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94663","published":"2026-10-09T10:16:41.283","modified":"2026-10-09T18:17:15.790","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Blind SQL Injection.This issue affects ProfileGrid: from n/a through 6.0.0.2.","score":8.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/profilegrid-user-profiles-groups-and-communities/vulnerability/wordpress-profilegrid-plugin-6-0-0-2-sql-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94661","published":"2026-10-09T10:16:41.150","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlog jet-blog allows Reflected XSS.This issue affects JetBlog: from n/a through 2.4.10.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/jet-blog/vulnerability/wordpress-jetblog-plugin-2-4-10-cross-site-scripting-xss-vulnerability-2?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94641","published":"2026-10-09T10:16:41.020","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stiofan UsersWP userswp allows Reflected XSS.This issue affects UsersWP: from n/a through 1.2.73.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/userswp/vulnerability/wordpress-userswp-plugin-1-2-73-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94632","published":"2026-10-09T10:16:40.880","modified":"2026-10-09T16:17:32.553","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stiofan BlockStrap Page Builder - Bootstrap Blocks blockstrap-page-builder-blocks allows Reflected XSS.This issue affects BlockStrap Page Builder - Bootstrap Blocks: from n/a through 0.1.58.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/blockstrap-page-builder-blocks/vulnerability/wordpress-blockstrap-page-builder-bootstrap-blocks-plugin-0-1-58-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94568","published":"2026-10-09T10:16:40.743","modified":"2026-10-09T21:17:07.280","description":"Deserialization of Untrusted Data vulnerability in WP Hosting AS Pay with Vipps for WooCommerce woo-vipps allows Object Injection.This issue affects Pay with Vipps for WooCommerce: from n/a through 6.2.0.","score":7.2,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-502"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/woo-vipps/vulnerability/wordpress-pay-with-vipps-for-woocommerce-plugin-6-2-0-php-object-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94503","published":"2026-10-09T10:16:40.607","modified":"2026-10-09T18:17:15.677","description":"Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify zombify allows Upload a Web Shell to a Web Server.This issue affects Zombify: from n/a through 1.7.7.","score":10,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-434"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/zombify/vulnerability/wordpress-zombify-plugin-1-7-7-arbitrary-file-upload-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94415","published":"2026-10-09T10:16:40.473","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muffingroup Betheme betheme allows Reflected XSS.This issue affects Betheme: from n/a through 28.5.8.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/betheme/vulnerability/wordpress-betheme-theme-28-5-8-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94170","published":"2026-10-09T10:16:40.333","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Heateor Support Sassy Social Share sassy-social-share allows Reflected XSS.This issue affects Sassy Social Share: from n/a through 3.3.79.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/sassy-social-share/vulnerability/wordpress-sassy-social-share-plugin-3-3-79-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94167","published":"2026-10-09T10:16:40.193","modified":"2026-10-09T16:17:32.427","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Extend Themes Kubio AI Page Builder kubio allows Reflected XSS.This issue affects Kubio AI Page Builder: from n/a through 2.9.3.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/kubio/vulnerability/wordpress-kubio-ai-page-builder-plugin-2-9-3-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94166","published":"2026-10-09T10:16:40.063","modified":"2026-10-09T21:17:07.163","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UpSolution UpSolution Core us-core allows Reflected XSS.This issue affects UpSolution Core: from n/a through 8.44.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/us-core/vulnerability/wordpress-upsolution-core-plugin-8-44-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94161","published":"2026-10-09T10:16:39.923","modified":"2026-10-09T18:17:15.563","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a before 7.0.11.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/grandrestaurant/vulnerability/wordpress-grand-restaurant-theme-7-0-11-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94159","published":"2026-10-09T10:16:39.787","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Total Donations totaldonations allows Stored XSS.This issue affects Total Donations: from n/a through 2.0.5.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/totaldonations/vulnerability/wordpress-total-donations-plugin-2-0-5-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-94158","published":"2026-10-09T10:16:39.653","modified":"2026-10-09T13:20:48.273","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bkninja Gloria Admin Panel gloria-admin-panel allows Reflected XSS.This issue affects Gloria Admin Panel: from n/a through 1.3.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/gloria-admin-panel/vulnerability/wordpress-gloria-admin-panel-plugin-1-3-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-93947","published":"2026-10-09T10:16:39.520","modified":"2026-10-09T16:17:32.090","description":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shinetheme Traveler traveler allows Blind SQL Injection.This issue affects Traveler: from n/a through 3.2.9.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/theme/traveler/vulnerability/wordpress-traveler-theme-3-2-9-sql-injection-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78341","published":"2026-10-09T10:16:39.387","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-863"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78340","published":"2026-10-09T10:16:39.253","modified":"2026-10-09T18:17:14.630","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Filesystem access for attacker.","score":6.3,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-22"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78339","published":"2026-10-09T10:16:39.103","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, and Unauthorized access.","score":6.3,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-732"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78027","published":"2026-10-09T10:16:38.970","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Server-side request forgery.","score":5.8,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-918"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78026","published":"2026-10-09T10:16:38.833","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.","score":4.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-639"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78025","published":"2026-10-09T10:16:38.707","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, and Unauthorized access.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-306"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78024","published":"2026-10-09T10:16:38.570","modified":"2026-10-09T18:17:14.520","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, Server-side request forgery, and Unauthorized access.","score":7.7,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-918"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78023","published":"2026-10-09T10:16:38.430","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-639"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-71884","published":"2026-10-09T10:16:38.260","modified":"2026-10-09T16:33:39.007","description":"In Bouncy Castle for Java LTS before 2.73.13, the native one-shot CTR packet cipher did not check that the requested input length fitted the counter space the IV left. In CTR mode the IV and the block counter share one 16-byte block, so an IV of 13 to 15 bytes leaves a counter of only 1 to 3 bytes, addressing 256, 65536 or 16777216 blocks respectively. Given a longer input the counter wrapped and the keystream repeated from the start of the same packet, and the call then returned the full input length as though every byte had been correctly transformed. Two segments of the message were therefore encrypted under the same keystream, so their plaintexts can be recovered from the ciphertext alone, without the key, while the caller saw neither an exception nor a short length to indicate it. The streaming implementation validates at init and again while processing, and the portable AESCTRPacketCipher rejects such a request with \"Counter in CTR/SIC mode out of range.\", but the native one-shot path has a single entry point and performed no counter-range validation there. It now preflights the IV-derived counter range and rejects an over-long request before any output is written, so the operation is failure-atomic and never reports success for bytes it did not correctly transform. A counter of four bytes or more cannot be exhausted by a Java int length and is unaffected, as is a full 16-byte IV, where the counter range is the caller's responsibility. Bouncy Castle for Java (bcprov) is not affected, as it ships no native implementations.","score":8.2,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-323"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Bcgit","vendorCategory":"Other vendors","references":[{"url":"https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9071884","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-62049","published":"2026-10-09T10:16:38.067","modified":"2026-10-09T21:17:05.353","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows Stored XSS.This issue affects JetBlocks For Elementor: from n/a through 1.5.2.1.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/jet-blocks/vulnerability/wordpress-jetblocks-for-elementor-plugin-1-5-2-1-cross-site-scripting-xss-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107935","published":"2026-10-09T10:16:37.497","modified":"2026-10-09T20:17:10.607","description":"A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.","score":9.3,"severity":"CRITICAL","attackVector":"ADJACENT_NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-22"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Red Hat","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107935","label":"access.redhat.com","kind":"reference"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2548382","label":"bugzilla.redhat.com","kind":"reference"},{"url":"https://github.com/containers/gvisor-tap-vsock/pull/718","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-84224","published":"2026-10-09T09:17:10.000","modified":"2026-10-09T15:17:17.390","description":"The Kirki WordPress plugin before 6.3.2 does not validate the host of a URL it is given before fetching it, allowing users with editor-level access and above to make the site issue requests to internal services that are not otherwise reachable, and to tell which of those are live from the response.","score":4.1,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-918"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/6a2455dd-8da9-4c7e-a249-3c694cf2983e/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-84220","published":"2026-10-09T09:17:09.857","modified":"2026-10-09T15:17:17.267","description":"The Kirki WordPress plugin before 6.3.2 does not prevent shortcodes held in comments from being executed when it renders them, and displays comments regardless of their moderation status, allowing unauthenticated visitors to run shortcodes registered on the site and to read private custom fields of the page being viewed.","score":4.8,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-74"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/e5cfd004-dd57-4d42-858c-fbb9b9e320f6/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78022","published":"2026-10-09T09:17:09.550","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Not Failing Securely ('Failing Open') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.","score":6.8,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-636"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78021","published":"2026-10-09T09:17:09.420","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Generation of Error Message Containing Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information exposure.","score":3.7,"severity":"LOW","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-209"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78020","published":"2026-10-09T09:17:09.300","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Remote execution.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-295"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78019","published":"2026-10-09T09:17:09.177","modified":"2026-10-09T18:17:14.403","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Filesystem access for attacker, and Remote execution.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-829"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78018","published":"2026-10-09T09:17:09.053","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.","score":6.3,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-1188"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78017","published":"2026-10-09T09:17:08.927","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Protection mechanism bypass.","score":3.8,"severity":"LOW","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-754"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78016","published":"2026-10-09T09:17:08.803","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Validation of Specified Type of Input vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure and Information tampering.","score":3.1,"severity":"LOW","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-1287"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78015","published":"2026-10-09T09:17:08.680","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Less Trusted Source vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.","score":3.7,"severity":"LOW","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-348"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-78013","published":"2026-10-09T09:17:08.557","modified":"2026-10-09T18:17:14.290","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Protection mechanism bypass.","score":5.2,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-1188"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-76779","published":"2026-10-09T09:17:08.430","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and Unauthorized access.","score":7.4,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-307"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-76769","published":"2026-10-09T09:17:08.290","modified":"2026-10-09T16:34:28.700","description":"Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.","score":4.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Dell","vendorCategory":"End User Compute","references":[{"url":"https://www.dell.com/support/kbdoc/en-ca/000503592/dsa-2026-385-security-update-for-dell-secure-connect-gateway-policy-manager-multiple-vulnerabilities?msockid=3021cac2195069ed3194ddad186a68f9","label":"dell.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107655","published":"2026-10-09T09:17:08.120","modified":"2026-10-09T18:17:02.200","description":"A flaw was found in CUPS. When processing embedded job ticket comments within documents, the service improperly handles specific IPP attributes, causing an unhandled null pointer dereference. An unauthenticated attacker permitted to submit jobs to a shared printer queue can send a crafted Internet Printing Protocol (IPP) request to crash the print daemon, resulting in a temporary Denial of Service (DoS) for all printing services.","score":4,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-476"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Red Hat","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107655","label":"access.redhat.com","kind":"reference"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2548399","label":"bugzilla.redhat.com","kind":"reference"},{"url":"https://github.com/OpenPrinting/cups/commit/12237ad","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-104635","published":"2026-10-09T09:17:07.360","modified":"2026-10-09T17:07:31.693","description":"Uncontrolled Recursion vulnerability in Protobuf.JSON.Decode in elixir-protobuf protobuf allows an unauthenticated remote attacker to crash the decoding process via a deeply nested JSON document. Any application that decodes attacker-supplied JSON with Protobuf.JSON.decode/3, Protobuf.JSON.decode!/3, or Protobuf.JSON.from_decoded/3 into a schema that contains a self-referential or cyclic message type is affected.\n\nIn lib/protobuf/json/decode.ex, the embedded-message clause of decode_singular/3 recurses into internal_from_json_data/3 once per nesting level without incrementing or checking the decoder's depth counter. The depth guard increase_depth_and_maybe_throw/1 covers only the Google.Protobuf.ListValue and Google.Protobuf.Struct clauses, so the recursion_limit option has no effect on user-defined message types. Each nesting level allocates a stack frame and heap objects, and a sufficiently deep document exhausts the memory of the decoding process. Confidentiality and integrity are not affected.\n\nThis issue affects protobuf: from 0.8.0 before 0.17.1.","score":8.2,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-674"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Google","vendorCategory":"End User Compute","references":[{"url":"https://cna.erlef.org/cves/CVE-2026-104635.html","label":"cna.erlef.org","kind":"reference"},{"url":"https://github.com/elixir-protobuf/protobuf/commit/b0a1d4eaffaf50012fa71a8e931a47cf252d0370","label":"github.com","kind":"reference"},{"url":"https://github.com/elixir-protobuf/protobuf/commit/e9432ad1c4099511905353cebcececa3a1f7c3ff","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-98384","published":"2026-10-09T08:16:56.940","modified":"2026-10-09T08:16:56.940","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix out-of-bounds read of sk_protocol in bpf_sock_destroy()\n\nsk_protocol lives in struct sock, not in struct sock_common. A timewait\nor request sock handed to bpf_sock_destroy() by the tcp iterator is\nneither, so reading sk->sk_protocol runs past the object:\n\n==================================================================\nBUG: KASAN: slab-out-of-bounds in bpf_sock_destroy+0xc7/0xe0\nRead of size 2 at addr ffff8881047d11b4 by task test_progs/428\n\nTainted: [W]=WARN\nCall Trace:\n <TASK>\n dump_stack_lvl+0x91/0xf0\n print_report+0xd1/0x630\n kasan_report+0xf3/0x130\n __asan_report_load2_noabort+0x14/0x30\n bpf_sock_destroy+0xc7/0xe0\n bpf_prog_c3dd61f9d9cd9f37_iter_tcp6_timewait+0x9f/0xb7\n bpf_iter_run_prog+0x538/0xde0\n bpf_iter_tcp_seq_show+0x26b/0x4b0\n bpf_seq_read+0x424/0x1210\n vfs_read+0x197/0xe40\n ksys_read+0x119/0x240\n __x64_sys_read+0x72/0xc0\n x64_sys_call+0x647/0x27e0\n do_syscall_64+0xe5/0x610\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nOnly check sk_protocol on full socks. tcp_abort() already knows how to\ndeal with TIME_WAIT and NEW_SYN_RECV socks. Also fix the comment, it\nnever matched the code.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Kernel","vendorCategory":"Other vendors","references":[{"url":"https://git.kernel.org/stable/c/01b245ba016d44861690594e10f67e026ce8552f","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/2534a5e5d360c2b10203cfa80f4ab9d021e48f2f","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/5b4eb82475ae17d55974235c09e97044829426a8","label":"git.kernel.org","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-98383","published":"2026-10-09T08:16:56.800","modified":"2026-10-09T08:16:56.800","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Disallow bpf_skb_pull_data() for LWT_SEG6LOCAL\n\nAn LWT_SEG6LOCAL program can invalidate its cached SRH with\nbpf_lwt_seg6_adjust_srh() and then call bpf_skb_pull_data(). The latter\nmay reallocate skb->head, leaving the per-CPU SRH pointer dangling.\nPost-program SRH validation then writes through that pointer.\n\nDisallow bpf_skb_pull_data() for LWT_SEG6LOCAL programs so the verifier\nrejects this unsafe helper combination. Other LWT program types continue\nto expose the helper through lwt_out_func_proto().","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Kernel","vendorCategory":"Other vendors","references":[{"url":"https://git.kernel.org/stable/c/0f38472a2aa8704a6b514c0dfa9c32f3672b8f32","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/37b18688cd18fd86d2f35c212df1611862a26cd5","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/9f9e57b5a3a033f95f49ef9d541340cdbcb80abb","label":"git.kernel.org","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-98382","published":"2026-10-09T08:16:56.680","modified":"2026-10-09T08:16:56.680","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject dev-bound-only programs on other devices\n\n__bpf_offload_dev_match() falls back to comparing offdev pointers after an\nexact netdev mismatch. Bound-only programs normally have NULL offdevs, so\nunrelated netdevs compare equal. A bound-only program on an\noffload-registered netdev can instead inherit a real offdev and match a\nsibling port. With CAP_BPF and CAP_NET_ADMIN, a caller can use\nbpf(BPF_LINK_CREATE) with a different target ifindex to run metadata kfuncs\nspecialized for the bound driver on the target driver's xdp_buff. Running a\nveth-bound program on tun reads beyond tun's bare stack xdp_buff as a\nveth_xdp_buff.\n\n  Oops: general protection fault, probably for non-canonical address\n  KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\n  RIP: 0010:veth_xdp_rx_timestamp (drivers/net/veth.c:1673)\n  Call Trace:\n   ...\n   tun_build_skb (drivers/net/tun.c:1739)\n   tun_get_user (drivers/net/tun.c:1856)\n   tun_chr_write_iter (drivers/net/tun.c:2091)\n   vfs_write (fs/read_write.c:595 fs/read_write.c:687)\n   ksys_write (fs/read_write.c:739)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:84)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n  Kernel panic - not syncing: Fatal exception in interrupt\n\nRestrict non-offloaded programs to exact netdev matches and retain the\nshared-offdev fallback only for genuinely offloaded multi-port programs.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Canonical","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://git.kernel.org/stable/c/0dceda331180617aeeb22381e8480b37f18ba08b","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/6db1ce73e9853f533eb7f413f14ba00f8ec6f80d","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/940b626854de200e6187777d42114727daca617c","label":"git.kernel.org","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-98381","published":"2026-10-09T08:16:56.547","modified":"2026-10-09T08:16:56.547","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nveth: manage XDP program pointers during channel resize\n\nveth_set_channels() tears down XDP resources for removed RX queues\nwithout clearing rq->xdp_prog.  If the program is then detached or\nreplaced, those queues keep the old pointer after bpf_prog_put().\nA later channel increase can re-enable NAPI and run the freed program.\n\n  BUG: unable to handle page fault for address: ffffc90000256048\n  Oops: Oops: 0000 [#1] SMP KASAN NOPTI\n  RIP: veth_xdp_rcv_skb (include/linux/filter.h:779\n                         include/net/xdp.h:696 drivers/net/veth.c:820)\n  Call Trace:\n   veth_xdp_rcv (drivers/net/veth.c:941)\n   veth_poll (drivers/net/veth.c:986)\n   __napi_poll (net/core/dev.c:7787)\n   net_rx_action (net/core/dev.c:7850 net/core/dev.c:8007)\n   handle_softirqs (kernel/softirq.c:645)\n  Kernel panic - not syncing: Fatal exception in interrupt","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Kernel","vendorCategory":"Other vendors","references":[{"url":"https://git.kernel.org/stable/c/1a5c5b9c64ba5f39dba55da6e12561ca56eeb758","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/25bb7c36225220d30f404d7e29d2e052bc5f4b99","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/3c10a5dd0d38f506f671dbb59e9d0ee4c72076f9","label":"git.kernel.org","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-98380","published":"2026-10-09T08:16:56.400","modified":"2026-10-09T08:16:56.400","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: reject IDR error pointers when deleting actions\n\ntcf_action_delete() drops the reference held by its lookup before calling\ntcf_idr_delete_index() with the saved action index.  An unlocked\nclassifier can remove that action and reserve the same IDR slot with\nERR_PTR(-EBUSY) in between.\n\ntcf_idr_delete_index() only checks the lookup result for NULL.  It\ntherefore treats the reservation as a tc_action and dereferences\ntcfa_bindcnt.  A hardware execution breakpoint was used to schedule the\ninterleaving without changing the kernel source.  KASAN reported this\ndecoded trace:\n\n  BUG: KASAN: null-ptr-deref in tca_action_gd+0x5b9/0x1010\n  Read of size 4 at addr 0000000000000010 by task poc/150\n  Oops: general protection fault, probably for non-canonical address 0xdffffc0000000002\n  RIP: tca_action_gd+0x5c0/0x1010:\n    arch_atomic_read at arch/x86/include/asm/atomic.h:23\n    raw_atomic_read at include/linux/atomic/atomic-arch-fallback.h:457\n    atomic_read at include/linux/atomic/atomic-instrumented.h:33\n    tcf_idr_delete_index at net/sched/act_api.c:766\n    tcf_action_delete at net/sched/act_api.c:1859\n    tcf_del_notify at net/sched/act_api.c:2014\n    tca_action_gd at net/sched/act_api.c:2064\n  R13: 0000000000000010 R15: fffffffffffffff0\n  Kernel panic - not syncing: Fatal exception\n\nR15 contains ERR_PTR(-EBUSY), and adding the tcfa_bindcnt offset produces\nthe address in R13.  With the guard applied, the same reproducer returned\n-ENOENT without a KASAN report or panic.  Treat error pointers as absent\nand return -ENOENT.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Canonical","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://git.kernel.org/stable/c/259caa711b7688365676442e2fdb286b8aceaa80","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/39b751a210bf61a374afa82749afc7a77a08bf1d","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/6bf076258aac4e0af69ef317656c31ce6444d647","label":"git.kernel.org","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-98379","published":"2026-10-09T08:16:56.250","modified":"2026-10-09T08:16:56.250","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ip6t_rpfilter: reject routes without inet6_dev\n\nip6_route_lookup() can return an error-free route whose rt6i_idev is\nNULL. Lowering an external nexthop device's MTU below IPV6_MIN_MTU tears\ndown its inet6_dev while fib6_ifdown() leaves routes using nexthop objects\nin the FIB. An unprivileged user can construct this state with rtnetlink\nin a private user and network namespace, then trigger a NULL dereference\nthrough an IPv6 rpfilter lookup:\n\n  Oops: general protection fault, probably for non-canonical address\n  0xdffffc0000000000\n  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n  RIP: rpfilter_mt (net/ipv6/netfilter/ip6t_rpfilter.c:75)\n  Call Trace:\n  ip6t_do_table (net/ipv6/netfilter/ip6_tables.c:316)\n  nf_hook_slow (net/netfilter/core.c:619)\n  ipv6_rcv (net/ipv6/ip6_input.c:351)\n  __netif_receive_skb_one_core (net/core/dev.c:6216)\n  process_backlog (net/core/dev.c:6680)\n  __napi_poll (net/core/dev.c:7739)\n  net_rx_action (net/core/dev.c:7959)\n  handle_softirqs (kernel/softirq.c:622)\n  do_softirq.part.0 (kernel/softirq.c:523)\n  __local_bh_enable_ip (kernel/softirq.c:450)\n  __dev_queue_xmit (net/core/dev.c:4913)\n  packet_sendmsg (net/packet/af_packet.c:3139)\n  __sys_sendto (net/socket.c:2252)\n  __x64_sys_sendto (net/socket.c:2259)\n  do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n  entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n  Kernel panic - not syncing: Fatal exception in interrupt\n\nReject routes without an inet6_dev immediately after lookup. Such routes\nare not eligible for reverse-path filtering, and the check protects all\nlater rt6i_idev dereferences.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Canonical","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://git.kernel.org/stable/c/1681ab6dd1271f2f36047490793b78b1848bbcc9","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/1b9b5323725e458906c7620a3bc10398b51ad954","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/290c96e5d9471d1ded9ab1e8ffbb04f6ee7b0f40","label":"git.kernel.org","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-98378","published":"2026-10-09T08:16:56.123","modified":"2026-10-09T08:16:56.123","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Skip unsettled links in link iterator\n\nbpf_link_prime() inserts a link into link_idr before anon_inode_getfile()\nsucceeds and before bpf_link_settle() publishes the ID in link->id.\nbpf_link_by_id() treats such an ID-zero link as unsettled, but the link\niterator takes a reference without this check.\n\nIf anon_inode_getfile() then fails, the creator removes the ID and frees\nits still-private link directly.  The iterator is left with a dangling\nreference and its next bpf_link_put() accesses freed memory.\n\nTreat ID-zero entries as transient in bpf_link_get_curr_or_next(), just as\nbpf_link_by_id() does.\n\n  BUG: KASAN: slab-use-after-free in bpf_link_put\n  Write of size 8 by task exp/384\n  Call Trace:\n  bpf_link_put                    kernel/bpf/syscall.c:3372\n  bpf_link_seq_next               kernel/bpf/link_iter.c:33\n  bpf_seq_read                    kernel/bpf/bpf_iter.c:158\n  vfs_read                        fs/read_write.c:572\n  ksys_read                       fs/read_write.c:716\n  do_syscall_64                   arch/x86/entry/syscall_64.c:84\n  entry_SYSCALL_64_after_hwframe  arch/x86/entry/entry_64.S:121\n  Kernel panic - not syncing: KASAN: panic_on_warn set ...","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Kernel","vendorCategory":"Other vendors","references":[{"url":"https://git.kernel.org/stable/c/50e80e2bb5e2be8515205b9c496b9640ddefa434","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/68930f8d40ab4c10ca3b019f076136758fd100a8","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/6e271f093d15d323f42de26f66556af53fa8e19f","label":"git.kernel.org","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-98377","published":"2026-10-09T08:16:56.010","modified":"2026-10-09T08:16:56.010","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nvlan: require the MAC header to be present in __vlan_insert_inner_tag()\n\n__vlan_insert_inner_tag() only guarantees head room via skb_cow_head(),\nnever that mac_len bytes of MAC header are present.  Its ETH_HLEN\nwrappers - __vlan_insert_tag() under skb_vlan_push(), and\nvlan_insert_tag() under validate_xmit_vlan() on the generic transmit\npath - therefore rewrite the first 16 bytes at skb->data: a 12-byte\nmemmove plus two 2-byte stores at +12 and +14.  No caller supplies the\nbound, while the pop helpers use skb_ensure_writable()/pskb_may_pull().\n\nAn IFF_TUN device has hard_header_len == 0, so packet_snd() accepts a\none-byte AF_PACKET/SOCK_RAW frame.  The first vlan push only sets a\nhwaccel tag; the next - clsact \"action vlan push\" or\nbpf_skb_vlan_push() - enters the helper with skb->len still 1.  The\nhead comes from skbuff_small_head without __GFP_ZERO, so each push\ndrags bytes from beyond skb->tail into the frame.  After three the\none-byte send leaves as 13 bytes carrying 11 bytes of uninitialised\nslab:\n\n  0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81\n           `------------------------------'\n  only 0x5a was sent; the rest is slab, here the top 56 bits of a\n  linear-map address\n\nRequire the MAC header the helper rewrites to be present, so such a\nframe is dropped rather than transmitted.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Kernel","vendorCategory":"Other vendors","references":[{"url":"https://git.kernel.org/stable/c/40a5cc4b7251c74f3341332a226d02200e96bccf","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/59af43ccece4d2d8b62e9e3ccc96b6e2e793bcdc","label":"git.kernel.org","kind":"reference"},{"url":"https://git.kernel.org/stable/c/ab888242fce4f16f6c4d4c6ec53939ad36aa3b3a","label":"git.kernel.org","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-98376","published":"2026-10-09T08:16:55.910","modified":"2026-10-09T08:16:55.910","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Use array_map_meta_equal for percpu array inner map replacement\n\npercpu_array_map_ops.map_meta_equal points to the generic\nbpf_map_meta_equal(), which does not compare max_entries.  When a\npercpu array serves as an inner map, replacing it with one that has\nfewer max_entries bypasses the check.  Since percpu_array_map_gen_lookup()\ninlines the original template's index_mask as a JIT immediate, a lookup\non the replacement map can access pptrs[] out of bounds.\n\nPoint percpu_array_map_ops.map_meta_equal to array_map_meta_equal(),\nwhich already enforces the max_entries equality check.\n\nAdd a selftest to verify that replacing a percpu array inner map with\na differently-sized one is rejected.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Kernel","vendorCategory":"Other vendors","references":[{"url":"https://git.kernel.org/stable/c/593980175389a05793f6060aa20e626330960395","label":"git.kernel.org","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-98375","published":"2026-10-09T08:16:55.807","modified":"2026-10-09T12:17:13.480","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nxen/netfront: drop RX packets with a short Ethernet header\n\nhandle_incoming_queue() pulls pull_to bytes into the head before\ncalling eth_type_trans().  pull_to is the length of the first RX slot,\ncapped at RX_COPY_THRESHOLD, and that length comes from the backend.\nNothing checks it against ETH_HLEN.\n\nIf the first slot is shorter than ETH_HLEN and more slots follow, the\nhead ends up shorter than an Ethernet header while skb->len is longer,\nand eth_type_trans() BUG()s in __skb_pull().  If the whole packet is\nshorter than ETH_HLEN, eth_type_trans() reads the header past the end\nof the data instead.\n\nPull at least ETH_HLEN, and drop the packet if that fails, which also\ndrops packets too short to hold an Ethernet header.  This also checks\nthe return value of the pull, which was ignored.","score":null,"severity":"UNRATED","attackVector":"","products":[],"vendors":[],"windowsVersions":[],"weaknesses":[],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Kernel","vendorCategory":"Other vendors","references":[{"url":"https://git.kernel.org/stable/c/089e58805c452e52179482b1025a8e309a57f801","label":"git.kernel.org","kind":"reference"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/09/3","label":"openwall.com","kind":"reference"},{"url":"http://xenbits.xen.org/xsa/advisory-522.html","label":"xenbits.xen.org","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-97075","published":"2026-10-09T08:16:55.683","modified":"2026-10-09T18:17:16.600","description":"Missing Authorization vulnerability in WP Media WP Rocket wp-rocket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Rocket: from n/a before 3.23.5.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/wp-rocket/vulnerability/wordpress-wp-rocket-plugin-3-23-5-broken-access-control-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-4264","published":"2026-10-09T08:16:55.300","modified":"2026-10-09T18:17:08.400","description":"Reflected Cross-Site Scripting (XSS) on the BeeTienda e-commerce platform, specifically in the latest demo version. The incident occurs due to a lack of proper sanitization of user input data in the 'search' parameter of the product list endpoint. When malicious payloads are transmitted via the 'search' parameter, they are displayed insecurely in the HTML response, allowing for the arbitrary execution of JavaScript code in the victim's browser.","score":5.1,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Incibe","vendorCategory":"Other vendors","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/reflected-cross-site-scripting-beetienda-ecommerce-platform","label":"incibe.es","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-19575","published":"2026-10-09T08:16:55.057","modified":"2026-10-09T18:17:08.263","description":"The user-mode verification handler for the device_deinit() system call, z_vrfy_device_deinit() in kernel/device.c, validated its dev argument with K_SYSCALL_OBJ_INIT(dev, K_OBJ_ANY). k_object_validate() short-circuits its type comparison when the requested type is K_OBJ_ANY, so the check reduced to \"this pointer is the base address of some kernel object the calling thread has been granted\" — the object's actual type was never compared, and K_SYSCALL_OBJ_INIT also skips the initialization-state check. The sibling handlers z_vrfy_device_init() and z_vrfy_device_is_ready() already used K_OBJ_DRIVER_ANY and were unaffected.\n\nA thread running in user mode can therefore pass any kernel object it holds permission on — most usefully a thread stack object obtained from the k_thread_stack_alloc() syscall or a statically defined K_THREAD_STACK it was granted in order to spawn a child user thread — whose backing memory is writable from user mode. z_impl_device_deinit() then interprets those attacker-written bytes as a struct device: it dereferences the state pointer read out of the object, calls the function pointer read out of ops.deinit, and on success writes through state again. The result is an indirect call to an arbitrary address executed in supervisor mode, plus an arbitrary kernel read and a single-byte kernel write.\n\nExploitation gives a local unprivileged thread full kernel code execution, defeating the CONFIG_USERSPACE isolation boundary entirely; a less precise attempt yields a supervisor-mode fault and a system crash. The defect is only reachable in builds that enable both CONFIG_USERSPACE and CONFIG_DEVICE_DEINIT_SUPPORT — with de-initialization support disabled, z_impl_device_deinit() returns -ENOTSUP without ever dereferencing the pointer. In v4.2.x and v4.3.x, CONFIG_DEVICE_DEINIT_SUPPORT defaulted to y, so every CONFIG_USERSPACE build of those releases is exposed unless the option was explicitly turned off. From v4.4.0 the option is opt-in (no default, and not selected by any in-tree subsystem), so a v4.4.x build is exposed only if it enables the option explicitly. The v4.2 line is no longer maintained and receives no backport.\n\nThe fix changes the object check to K_OBJ_DRIVER_ANY, which constrains the argument to the build-generated driver object type range (K_OBJ_DRIVER_FIRST..K_OBJ_DRIVER_LAST) — the real struct device instances placed by the linker — so the state and ops.deinit fields are once again kernel-controlled.","score":7.8,"severity":"HIGH","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-843"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Zephyrproject Rtos","vendorCategory":"Other vendors","references":[{"url":"https://github.com/zephyrproject-rtos/zephyr/commit/1036694889ab33996db41b4141ddf66aa786d267","label":"github.com","kind":"reference"},{"url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-j9m4-fr5f-49wm","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-19574","published":"2026-10-09T08:16:54.940","modified":"2026-10-09T18:17:08.147","description":"The ARM64 MMU back-end allocated address space identifiers (ASIDs) for memory domains with a bare round-robin counter in arch_mem_domain_init() (arch/arm64/core/mmu.c). VM_ASID_BITS is 8, so only 255 ASIDs exist; once the counter wrapped, arch_mem_domain_init() could hand an ASID to a new domain while a still-live domain held the same one. Domain-private mappings are installed non-global (MT_NG), so the ASID is the only tag separating one domain's cached translations from another's in the TLB.\n\nThe context-switch path in z_arm64_swap_ptables() only flushes the TLB when the outgoing and incoming domains carry the same ASID, which does not cover a duplicate reached through a third domain: for domains A and C sharing an ASID and an unrelated domain B, the schedule A -> B -> C never takes the flush branch, so the ASID-tagged entries A populated remain resident while C runs. Under SMP two live domains sharing an ASID can additionally be resident on two CPUs at once, which the architecture does not allow for distinct translation-table sets.\n\nTriggering the wrap requires a CONFIG_USERSPACE application on ARM64 that creates more than 255 memory domains over its lifetime; k_mem_domain_init() and k_mem_domain_deinit() are supervisor-only APIs and are not exposed as syscalls, so an unprivileged thread cannot drive the counter directly. Once two live domains alias, however, a user-mode thread in one domain can read and write memory belonging to the other domain's partitions and thread stacks with that domain's permissions, defeating the memory-domain isolation boundary.\n\nThe fix scans the live domain_list before assigning an ASID, advances the round-robin counter past ASIDs already in use, and returns -ENOMEM when all are taken, so domain creation fails closed instead of silently aliasing.","score":7,"severity":"HIGH","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-284"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Zephyrproject Rtos","vendorCategory":"Other vendors","references":[{"url":"https://github.com/zephyrproject-rtos/zephyr/commit/805054b8ed89dd5441fbca36b3cd3be7e4fb4100","label":"github.com","kind":"reference"},{"url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-923h-8c2j-pcm5","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-19571","published":"2026-10-09T08:16:54.817","modified":"2026-10-09T18:17:08.020","description":"The ITE IT8xxx2 SHI host-command backend (subsys/mgmt/ec_host_cmd/backends/ec_host_cmd_backend_shi_ite.c) copied the 8-byte host-command request header from the SPI Rx FIFO directly into the shared receive buffer data->in_msg and only afterwards checked the protocol version and the derived packet length. The interrupt handler also accepted a chip-select assertion and an Rx-valid-length (RVLI) interrupt in any driver state other than SHI_STATE_DISABLED, so a new header could be parsed while the host-command thread was still processing the previous request out of the very same buffer.\n\nThe host processor is the SPI controller and drives both chip select and the clock. After sending a well-formed request it can immediately de-assert chip select — which returns the driver to the ready state and re-enables the FIFO — and start a second transaction carrying a header with data_len = 0xFFFF. Those eight bytes are written into in_msg before the oversized length is rejected, so they land in a buffer whose contents verify_rx() in subsys/mgmt/ec_host_cmd/ec_host_cmd_handler.c has already validated. If this lands in the window before the host-command thread executes args.input_buf_size = rx_header->data_len, the framework hands the registered command handler a 65535-byte input length over a 256-byte buffer.\n\nThe result is an out-of-bounds read of up to roughly 64 KiB beyond the request buffer: command handlers that copy or echo input_buf_size bytes disclose adjacent embedded-controller memory back to the host or overflow the response buffer, and a read past the end of SRAM faults the controller. The same race also allows cmd_id and cmd_ver to be swapped after checksum verification and after handler lookup. Exploitation requires the ability to drive the inter-processor SHI bus (a compromised host OS or physical access to the SPI lines) and winning a timing race, which the SPI controller can retry indefinitely.\n\nThe fix parses the header into a local struct ec_host_cmd_request_header and copies it into in_msg only after the length has been bounded by sizeof(data->in_msg), and ignores chip-select and RVLI interrupts outside SHI_STATE_READY_TO_RECV/SHI_STATE_RECEIVING. A residual, bounded race remains: an end-of-transaction interrupt still resets the state to ready while the host-command thread owns the buffer, so a valid second request can still overwrite the in-flight request's contents, unlike the NPCX backend which parks in SHI_STATE_CNL_RESP_NOT_RDY while the buffer is in use.","score":6.7,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-362"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Zephyrproject Rtos","vendorCategory":"Other vendors","references":[{"url":"https://github.com/zephyrproject-rtos/zephyr/commit/0636e65c825e810ad97f154606365870152d402f","label":"github.com","kind":"reference"},{"url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-4x98-6536-cwjv","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-19570","published":"2026-10-09T08:16:54.693","modified":"2026-10-09T18:17:07.887","description":"The LE Audio Broadcast Sink in subsys/bluetooth/audio/bap_broadcast_sink.c copies subgroup metadata from a received Basic Audio Announcement (BASE) into the static Broadcast Audio Scan Service parameter structure mod_src_param without any bounds check. In base_subgroup_meta_cb() the destination element was selected as mod_src_param.subgroups[mod_src_param.num_subgroups] with no test against ARRAY_SIZE(mod_src_param.subgroups) (sized by CONFIG_BT_BAP_BASS_MAX_SUBGROUPS, default 1), and the metadata was copied with memcpy() using the raw on-air length returned by bt_bap_base_get_subgroup_codec_meta() into a metadata array sized by CONFIG_BT_AUDIO_CODEC_CFG_MAX_METADATA_SIZE (default 4). The BASE validator bt_bap_base_get_base_from_ad() only checks structural consistency and permits up to ~24 subgroups and metadata LTVs of ~240 octets.\n\nThe defect is reached from the periodic advertising receive callback: pa_recv() → bt_data_parse() → pa_decode_base() → update_recv_state_base() → bt_bap_base_foreach_subgroup() → base_subgroup_meta_cb(). Every broadcast sink registers a scan-delegator receive state at creation (bt_bap_broadcast_sink_create() calls broadcast_sink_add_src()), and CONFIG_BT_BAP_BROADCAST_SINK depends on CONFIG_BT_BAP_SCAN_DELEGATOR, so the path is active in every broadcast-sink build once the device is periodic-advertising-synced. An attacker in radio range who operates a broadcast source the device syncs to — or who impersonates the advertiser address and SID of one already in use, periodic advertising data being unauthenticated — can change the BASE at will; each new BASE is re-parsed.\n\nA crafted BASE therefore writes attacker-chosen bytes past the end of a fixed static object in .bss: up to roughly 236 bytes for an oversized metadata LTV, plus whole struct bt_bap_bass_subgroup records for each subgroup beyond CONFIG_BT_BAP_BASS_MAX_SUBGROUPS. This is memory corruption of adjacent Bluetooth-audio state reachable with no pairing, bonding or GATT connection, with a potential for remote code execution in the Bluetooth RX thread; in addition, the unvalidated metadata_len is forwarded to bt_bap_scan_delegator_mod_src(), which neither clamps it nor rejects it, leading to a further copy into the receive state and to out-of-bounds memory being disclosed in the BASS receive-state notification sent to a connected Broadcast Assistant.\n\nThe fix rejects a BASE carrying more subgroups than the receive state can hold (discarding the update entirely) and omits metadata that does not fit rather than copying it, and additionally honours the previously-ignored error return of the subgroup decode pass.","score":8.8,"severity":"HIGH","attackVector":"ADJACENT_NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-120","CWE-787"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Zephyrproject Rtos","vendorCategory":"Other vendors","references":[{"url":"https://github.com/zephyrproject-rtos/zephyr/commit/5738f61f4128bb38508bab57342b1f7bf218d127","label":"github.com","kind":"reference"},{"url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-4qwc-2qfq-w2fj","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-19569","published":"2026-10-09T08:16:54.563","modified":"2026-10-09T18:17:07.760","description":"dynamic_object_create() in kernel/userspace/userspace.c computed the backing allocation for a dynamically allocated kernel object as obj_size_get(otype) + size, and for thread stack elements as STACK_ELEMENT_DATA_SIZE(size) (a round-up plus fixed overhead), without checking either expression for unsigned wrap-around. A size close to SIZE_MAX makes the computed total wrap to a very small value, so the heap chunk handed out is a few bytes while the object descriptor is still tagged with the full requested type and registered in the kernel object table.\n\nThe size argument reaches that arithmetic directly from user mode. k_object_alloc_size() is declared __syscall in include/zephyr/sys/kobject.h, its verifier z_vrfy_k_object_alloc_size() in kernel/userspace/userspace_handler.c is a bare pass-through, and z_object_alloc() only range-checks otype — nothing bounds size. The stack-element branch is additionally reachable through the k_thread_stack_alloc() syscall via kernel/dynamic.c. Because subsequent kernel-object validation checks only the object's type and initialization state, the undersized handle passes K_SYSCALL_OBJ_INIT()/K_SYSCALL_OBJ_NEVER_INIT(), and the matching init syscall (for example k_mutex_init(), k_sem_init(), or k_thread_create()) then writes a complete object over the truncated allocation.\n\nAn unprivileged user-mode thread can therefore trigger a supervisor-mode out-of-bounds write into the kernel resource-pool heap, of a size and content it substantially controls, corrupting sys_heap chunk metadata and adjacent kernel objects. Under CONFIG_GEN_PRIV_STACKS the thread-stack branch additionally stores an attacker-influenced wild pointer as a user thread's privileged stack base. The practical result is escape from the CONFIG_USERSPACE sandbox — kernel-level code execution or at minimum kernel memory corruption and system compromise.\n\nExploitation requires CONFIG_USERSPACE together with CONFIG_DYNAMIC_OBJECTS (also selected by CONFIG_DYNAMIC_THREAD under userspace), and a calling thread with an assigned resource pool. The fix rejects both overflowing computations and frees the partially built descriptor.","score":8.8,"severity":"HIGH","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-190"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Zephyrproject Rtos","vendorCategory":"Other vendors","references":[{"url":"https://github.com/zephyrproject-rtos/zephyr/commit/85c1c4c21945d9b8fcef03216f1ccb2b27794e3d","label":"github.com","kind":"reference"},{"url":"https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-fg8c-9fhq-q7hv","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-106155","published":"2026-10-09T08:16:54.377","modified":"2026-10-09T18:17:02.077","description":"In Progress® Telerik® Report Server prior to version 12.2.26.1007, a stored cross-site scripting vulnerability in the shared reporting engine allows an authenticated report author to embed javascript: or vbscript: URLs in report navigation actions or HTML text box links. When another user views the malicious report and the embedded navigation is triggered, attacker-controlled script can execute in the web report viewer's origin. In a multi-user Report Server deployment, this can enable privilege escalation by performing actions in a higher-privilege user's authenticated session, including an administrator's session.","score":8.9,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Telerik","vendorCategory":"Other vendors","references":[{"url":"https://www.telerik.com/report-server/documentation/knowledge-base/kb-security-improper-neutralization-of-input-cve-2026-106155","label":"telerik.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-106145","published":"2026-10-09T08:16:54.250","modified":"2026-10-09T18:17:01.940","description":"In Progress® Telerik® Report Server prior to version 12.2.26.1007, incorrect privilege assignment in the service-agent SignalR hub allows an authenticated user, including a low-privilege or guest account with a valid bearer token, to register as a trusted service agent. On the next server settings-synchronization event, the rogue agent receives storage settings and encryption private keys. This privilege escalation enables disclosure of protected secrets, including stored data-source credentials and connection strings, and allows agent impersonation and interference with task dispatch.","score":7.1,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-266"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Telerik","vendorCategory":"Other vendors","references":[{"url":"https://www.telerik.com/report-server/documentation/knowledge-base/kb-security-incorrect-privilege-assignment-cve-2026-106145","label":"telerik.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2025-14123","published":"2026-10-09T08:16:54.090","modified":"2026-10-09T13:20:48.273","description":"The Redux Framework plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.5.11. This is due to the plugin saving arbitrary meta keys under a registered option name without sufficient capability checks or key allowlist / restrictions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set an arbitrary role (e.g., Administrator) when performing a profile update if a plugin or theme using this framework has added at least one user profile field that leverages Redux_Users::set_profile/set_section/set_field.","score":6.8,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-269"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Wordpress","vendorCategory":"Other vendors","references":[{"url":"https://plugins.trac.wordpress.org/changeset/3582185/redux-framework","label":"plugins.trac.wordpress.org","kind":"reference"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/bbe52266-9ee1-47a8-a6df-7057b29e8098?source=cve","label":"wordfence.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-97076","published":"2026-10-09T07:17:19.350","modified":"2026-10-09T13:20:48.273","description":"Executable Regular Expression Error vulnerability in WP Media WP Rocket wp-rocket allows Code Injection.This issue affects WP Rocket: from n/a before 3.23.5.","score":7.5,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-624"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://patchstack.com/database/wordpress/plugin/wp-rocket/vulnerability/wordpress-wp-rocket-plugin-3-23-5-denial-of-service-attack-vulnerability?_s_id=cve","label":"patchstack.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-93548","published":"2026-10-09T07:17:19.247","modified":"2026-10-09T15:17:20.140","description":"The FooSales  WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales  WordPress plugin before 1.43.3 act as an arbitrary other user, including an administrator, resulting in that user's account details being exposed and their account being taken over.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-269"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/7d9238eb-f56e-49db-a804-7505f59fca5c/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-92990","published":"2026-10-09T07:17:19.153","modified":"2026-10-09T15:17:19.967","description":"The SendPress Newsletters WordPress plugin through 1.26.1.20 protects a logging endpoint with a hardcoded token that is the same on every site rather than a per-site secret, allowing unauthenticated users to read newsletter sending logs, including recipient email addresses.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-200"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/595c6a6b-d346-4ed4-9a4e-674d90a35e74/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-92989","published":"2026-10-09T07:17:19.050","modified":"2026-10-09T15:17:19.783","description":"The SendPress Newsletters WordPress plugin through 1.26.1.20 does not check the user's capability on several newsletter-management actions, allowing any authenticated subscriber-level user to synchronise all site users into a mailing list and to drive the newsletter send queue.","score":4.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-284"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/771aeab9-2bd2-4d77-b3b8-9fdfb651507f/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-88931","published":"2026-10-09T07:17:18.950","modified":"2026-10-09T15:17:19.480","description":"The Social Web Suite  WordPress plugin through 4.1.12 does not restrict which of its settings may be written through an unauthenticated endpoint, allowing attackers to overwrite arbitrary Social Web Suite  WordPress plugin through 4.1.12 options, including the shared secret that guards its own privileged endpoints.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/e1341110-abad-47f5-aed5-1c06cb0c8071/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-87841","published":"2026-10-09T07:17:18.847","modified":"2026-10-09T15:17:18.783","description":"The UnitechPay  WordPress plugin through 1.0.6.3 does not verify the authenticity of the payment notifications it receives, allowing unauthenticated attackers to mark orders placed through it as paid without any payment being made, as well as to force other orders into a failed state.","score":5.3,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/f04babb4-2dee-4c41-8b4c-0c2428009180/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-86850","published":"2026-10-09T07:17:18.750","modified":"2026-10-09T15:17:18.490","description":"The SKU Error Fixer for WooCommerce WordPress plugin through 1.0 does not perform any capability or nonce checks on two of its AJAX actions, which are also available to unauthenticated users, allowing them to permanently delete product variations it classifies as obsolete, and to disclose those variations' details, with no recoverable copy left behind.","score":6.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/889aaa2a-ad05-423a-a601-70ac1d8b7920/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-81929","published":"2026-10-09T07:17:18.600","modified":"2026-10-09T16:17:30.913","description":"The Ocean Pro Demos and Ocean eComm Treasure Box plugins for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter in all versions up to, and including, 1.5.4, and 1.8.0, respectively, due to insufficient authorization, input sanitization, and output escaping in the Popup Builder's save_popup_content AJAX action. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into a published Gutenberg popup that will execute whenever a user accesses a page on which the popup is configured to display. A valid premium license, the Popup Builder module, and at least one published Gutenberg popup configured for display are required.","score":7.2,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Oceanwp","vendorCategory":"Other vendors","references":[{"url":"https://docs.oceanwp.org/article/670-ocean-pro-demos-changelog","label":"docs.oceanwp.org","kind":"reference"},{"url":"https://docs.oceanwp.org/article/860-ocean-ecomm-treasure-box-changelog","label":"docs.oceanwp.org","kind":"reference"},{"url":"https://docs.oceanwp.org/article/887-popup-builder","label":"docs.oceanwp.org","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-106097","published":"2026-10-09T07:17:17.997","modified":"2026-10-09T15:17:08.503","description":"The Code Snippets WordPress plugin before 3.10.0 does not sanitise and escape a user-supplied parameter before using it in a SQL query in some of its snippet-migration import endpoints, which are accessible to any user holding site-administration capabilities; on a WordPress Multisite network those belong to subsite Administrators, allowing a subsite Administrator who is not a network Super Admin to perform UNION-based SQL injection against shared network tables and disclose network-wide data such as other users' password hashes.","score":6.8,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-89"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/f5206366-2e9c-42d5-90b9-ddfaf39aa02f/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-106095","published":"2026-10-09T07:17:17.897","modified":"2026-10-09T15:17:08.340","description":"The Code Snippets WordPress plugin before 3.10.0 does not perform a capability check on one of its snippet-management actions and derives the network scope of the targeted snippet from the request instead of from the stored record, allowing an administrator of a single subsite on a multisite network to activate, deactivate and reprioritise network-scoped snippets that run across every site in the network.","score":3.3,"severity":"LOW","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-862"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/4aeddbb6-d7a9-48cb-96ea-5898586bce04/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-101028","published":"2026-10-09T07:17:17.627","modified":"2026-10-09T18:17:01.197","description":"Incorrect Authorization vulnerability in ash-project ash allows an actor to infer data in related records they cannot read via Ash.count/2, Ash.exists/2 and Ash.aggregate/3.\n\nAsh.Actions.Aggregate.run/4 (lib/ash/actions/aggregate.ex) applied only the root resource's read policy before running the aggregate query. The read path also applies each related resource's read policy to filter and sort references that cross a relationship, directly (for example comments.body) or through an aggregate over one, but the aggregate path skipped that step. A caller whose filter or sort reaches these functions, for example through Ash.Query.filter_input/2, an ash_lua script, or an AshAi tool offering count or exists results, can test conditions against related rows hidden from them and recover their existence and attribute values one query at a time. Ash.read/2 and its page counts are not affected.\n\nThis issue affects ash: from 2.6.0 before 3.34.6.","score":6,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-863"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Erlef","vendorCategory":"Other vendors","references":[{"url":"https://cna.erlef.org/cves/CVE-2026-101028.html","label":"cna.erlef.org","kind":"reference"},{"url":"https://github.com/ash-project/ash/commit/30eaf1c6e8524527b703e3c4bfeff7967ee0b37c","label":"github.com","kind":"reference"},{"url":"https://github.com/ash-project/ash/commit/80936187b27ee94f15cd875affd3141b5cb23185","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2025-15700","published":"2026-10-09T07:17:16.640","modified":"2026-10-09T15:17:05.333","description":"The AWP Classifieds WordPress plugin before 4.4.9 does not validate the type of files extracted from an uploaded ZIP archive during its listing-import feature, allowing users with the AWP Classifieds WordPress plugin before 4.4.9's management capability to upload arbitrary PHP files to a publicly accessible, network-shared directory and achieve remote code execution.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-434"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Unclassified / Awaiting NVD","vendorCategory":"Awaiting classification","references":[{"url":"https://wpscan.com/vulnerability/6d3e7721-41d4-4e5f-9a44-c601f0cdfe50/","label":"wpscan.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-87110","published":"2026-10-09T06:17:13.280","modified":"2026-10-09T16:37:45.710","description":"An unauthenticated user with network access to the Ops Manager web port can repeatedly request monitoring endpoints that perform costly work without rate limiting. This can temporarily slow other traffic served by the same process while requests continue.","score":6.9,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-770"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Mongodb","vendorCategory":"Other vendors","references":[{"url":"https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#ops-manager-server-8027","label":"mongodb.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-87109","published":"2026-10-09T06:17:13.140","modified":"2026-10-09T18:17:15.087","description":"An authenticated Ops Manager organization member can retrieve another member's pending authenticator enrollment seed through user-listing endpoints while that member's enrollment is unconfirmed. This results in disclosure of secret authentication material to another member of the same organization or project.","score":6,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-201"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Mongodb","vendorCategory":"Other vendors","references":[{"url":"https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#ops-manager-server-8027","label":"mongodb.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-87108","published":"2026-10-09T06:17:12.980","modified":"2026-10-09T17:16:50.470","description":"An authenticated Ops Manager user with a read-only project role can retrieve a daily host monitoring record associated with a different project when they possess the required record identifier. Insufficient ownership validation can expose deployment metadata, including host and configuration details.","score":2.3,"severity":"LOW","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-639"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Mongodb","vendorCategory":"Other vendors","references":[{"url":"https://www.mongodb.com/docs/ops-manager/current/release-notes/application/#ops-manager-server-8027","label":"mongodb.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107914","published":"2026-10-09T06:17:12.777","modified":"2026-10-09T17:06:17.770","description":"Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the \"Synchronize, import, and export configuration\" permission. NOTE: CVE-2026-107914 refers to the vulnerability in which config.admin.inc does not ensure that a file_unmanaged_delete operation occurs. Therefore, many archives could persist: config.tar.gz, config_0.tar.gz, config_1.tar.gz, etc. There is a separate config.module issue that could allow remote access by an anonymous user, but only for the one filename config.tar.gz.","score":7.8,"severity":"HIGH","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-459"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Backdropcms","vendorCategory":"Other vendors","references":[{"url":"https://backdropcms.org/security/backdrop-sa-core-2026-006","label":"backdropcms.org","kind":"reference"},{"url":"https://github.com/backdrop/backdrop/commit/1ae67061d9d487bb6cb3b8611191354052f34749","label":"github.com","kind":"reference"},{"url":"https://github.com/backdrop/backdrop/commit/347c8e558254633205f431ce5c12321a7ae9248e","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107911","published":"2026-10-09T06:17:12.620","modified":"2026-10-09T17:16:46.130","description":"A type confusion vulnerability in the _read_flags function (src/commands/cmd_dispatcher.c) in FalkorDB before 4.20.0 allows a remote authenticated attacker who can run GRAPH.QUERY to cause a denial of service and possibly disclose or corrupt memory. The function accepts a --bolt argument from any client and casts the following command argument, a Redis string object, to a Bolt client structure without checking its origin; the result-set code then dereferences pointers read from that object. The argument is parsed even when the Bolt endpoint is disabled, so default configurations are affected.","score":7.7,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-843"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"FalkorDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/FalkorDB/FalkorDB/commit/0b11a00b34b25c4d4fdfe55f0a35c8a00593bd7d","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/pull/2170","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/releases/tag/v4.20.0","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107910","published":"2026-10-09T06:17:12.457","modified":"2026-10-09T06:17:12.577","description":"An improper authentication vulnerability in the is_authenticated function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to execute graph queries without credentials through the Bolt endpoint. The function decides whether a password is required by issuing an empty AUTH command to Redis and treats only a WRONGPASS error as meaning that a password is required; any other error, such as LOADING while a dataset is being loaded, MASTERDOWN during replication failover, or OOM under memory pressure, causes the client to be treated as authenticated. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.","score":9.2,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-287"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"FalkorDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/FalkorDB/FalkorDB/commit/0b11a00b34b25c4d4fdfe55f0a35c8a00593bd7d","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/pull/2170","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/releases/tag/v4.20.0","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107909","published":"2026-10-09T06:17:12.303","modified":"2026-10-09T06:17:12.413","description":"A heap-based out-of-bounds write in the ws_read_frame function (src/bolt/ws.c) and the buffer_apply_mask function (src/bolt/buffer.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly corrupt heap memory by sending a WebSocket frame with a 64-bit extended payload length to the Bolt port. The payload length is not bounded, and the only bounds check in buffer_apply_mask is an ASSERT(), which is compiled out in release builds, so the function XORs memory beyond the end of the receive buffer with the attacker-supplied mask key. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-787"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"FalkorDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/FalkorDB/FalkorDB/commit/0b11a00b34b25c4d4fdfe55f0a35c8a00593bd7d","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/pull/2170","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/releases/tag/v4.20.0","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107908","published":"2026-10-09T06:17:10.777","modified":"2026-10-09T06:17:12.243","description":"A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly execute arbitrary code by sending a Bolt RESET message with an attacker-chosen chunk size to the Bolt port. The handler checks the size only with ASSERT(), which is compiled out in release builds, then computes a destination pointer from the wire-supplied 16-bit size and moves buffered data up to about 64 KiB backwards past the start of the read buffer. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-787"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"FalkorDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/FalkorDB/FalkorDB/commit/0b11a00b34b25c4d4fdfe55f0a35c8a00593bd7d","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/pull/2170","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/releases/tag/v4.20.0","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-7827","published":"2026-10-09T05:16:45.327","modified":"2026-10-09T17:16:50.163","description":"A stack-based buffer overflow in the _RdbLoadEntity function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service and possibly execute arbitrary code by supplying a crafted RDB stream with an attacker-controlled entity property count. The count sizes two variable-length arrays on the thread stack with no upper bound, and the decoder then fills them with attacker-supplied values.","score":9.2,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-121"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"FalkorDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/FalkorDB/FalkorDB/commit/7d15431aadf37588fadc2578b90c3afb5e8daa94","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/pull/1973","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/releases/tag/v4.18.4","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-7826","published":"2026-10-09T05:16:45.150","modified":"2026-10-09T05:16:45.270","description":"A heap-based out-of-bounds read in the BufferSerializerIOv2_ReadBuffer function (src/serializers/serializer_io.c) in FalkorDB before 4.18.4 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or disclose heap memory by supplying a crafted RDB stream whose sub-buffer length field exceeds the remaining buffer size. The only bounds check is an ASSERT(), which is compiled out in release builds, so memcpy() reads past the end of the heap allocation.","score":8.8,"severity":"HIGH","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-125"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"FalkorDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/FalkorDB/FalkorDB/commit/55d986f45ecd5d80f7a9e5e138e8b0f96535b48c","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/pull/1972","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/releases/tag/v4.18.4","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-5759","published":"2026-10-09T05:16:44.920","modified":"2026-10-09T05:16:45.043","description":"A double free and use-after-free vulnerability in the RdbLoadDeletedNodes function of the RDB graph decoders (src/serializers/decoders/*/decode_graph_entities.c) in FalkorDB before 4.18.1 allows a remote attacker who can issue Redis replication commands (for example, against an instance with no password configured) to cause a denial of service or execute arbitrary code in the redis-server process by supplying a crafted RDB stream whose deleted-nodes buffer length is not a multiple of sizeof(NodeID). The length check relies on ASSERT(), which is compiled out in release builds, so the function continues after freeing the buffer, reading it and freeing it a second time.","score":9.3,"severity":"CRITICAL","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-415","CWE-416"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"FalkorDB","vendorCategory":"Other vendors","references":[{"url":"https://github.com/FalkorDB/FalkorDB/commit/523d98ac7ffe99f11a9c95c258025c235f0dff4c","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/pull/1843","label":"github.com","kind":"reference"},{"url":"https://github.com/FalkorDB/FalkorDB/releases/tag/v4.18.1","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107890","published":"2026-10-09T05:16:44.730","modified":"2026-10-09T16:37:45.710","description":"OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation requests. IPP parsing creates unnamed separator attributes with IPP_TAG_ZERO, but add_job() converts these separators to IPP_TAG_JOB. During job startup, get_options()/ipp_length() subsequently calls strlen() on a NULL attribute name, terminating cupsd and disrupting all queues. A single crafted Print-Job request can trigger the crash when the client can reach the scheduler and submit jobs to an accepting, enabled queue supporting the submitted document format. Anonymous submission is possible when permitted by listener and access-control configuration.","score":3.3,"severity":"LOW","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-476"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"OpenPrinting","vendorCategory":"Other vendors","references":[{"url":"https://github.com/OpenPrinting/cups/security/advisories/GHSA-wjc4-qhjr-5m5x","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107889","published":"2026-10-09T05:16:44.583","modified":"2026-10-09T16:37:45.710","description":"A flaw was found in the login theme rendering component of Keycloak. The issue occurs because the security filter responsible for cleaning user input can be bypassed, allowing a realm administrator to store malicious scripts in display fields. This could result in unauthorized JavaScript execution in the browsers of users visiting the login page, potentially leading to data exposure or session interference.","score":5.5,"severity":"MEDIUM","attackVector":"NETWORK","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-79"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"Red Hat","vendorCategory":"Enterprise & Cloud","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107889","label":"access.redhat.com","kind":"reference"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2548355","label":"bugzilla.redhat.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107888","published":"2026-10-09T05:16:44.407","modified":"2026-10-09T16:37:45.710","description":"OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted. Temporary-printer cleanup can remove the destination without canceling its held jobs, and the scheduler dereferences the NULL result of cupsdFindDest() while checking holding_new_jobs. This terminates cupsd and interrupts all queues managed by that process. In some plausible scenarios, an unprivileged submission can trigger this.","score":5.1,"severity":"MEDIUM","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-476"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"OpenPrinting","vendorCategory":"Other vendors","references":[{"url":"https://github.com/OpenPrinting/cups/security/advisories/GHSA-qqm8-4q5h-jg55","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107886","published":"2026-10-09T04:18:05.163","modified":"2026-10-09T18:17:06.273","description":"OpenPrinting CUPS before 2.4.20 contains a double-free in printer-class management. When CUPS-Add-Modify-Class replaces an existing class member list, add_class() frees pclass->printers without clearing the pointer. If subsequent validation fails, the class retains the dangling pointer; CUPS-Delete-Class subsequently frees the same allocation in cupsdDeletePrinter(). A client authorized to modify and delete classes can cause scheduler-wide denial of service. The default policy requires @SYSTEM privileges.","score":2.3,"severity":"LOW","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-415"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"OpenPrinting","vendorCategory":"Other vendors","references":[{"url":"https://github.com/OpenPrinting/cups/security/advisories/GHSA-pwg4-pv39-8c22","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-107885","published":"2026-10-09T04:18:04.940","modified":"2026-10-09T21:17:03.713","description":"OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation, without matching that connection to the job being examined. A client allowed to reach the IPP service can hold an incomplete HTTP request containing parsed Send-Document headers before operation authorization, preventing unrelated incomplete jobs from expiring. Where Create-Job submission is allowed, incomplete jobs can accumulate until MaxJobs is exhausted and further legitimate print submissions are rejected. The suppression ends when the held connection closes.","score":3.3,"severity":"LOW","attackVector":"LOCAL","products":[],"vendors":[],"windowsVersions":[],"weaknesses":["CWE-770"],"fixedVersions":[],"remediationStatus":"Vendor guidance","patchAvailable":false,"primaryVendor":"OpenPrinting","vendorCategory":"Other vendors","references":[{"url":"https://github.com/OpenPrinting/cups/security/advisories/GHSA-hhw5-qqmc-p6rg","label":"github.com","kind":"reference"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-10-10T00:45:28.417Z","changedFields":["new record"],"lastChangedAt":"2026-10-10T00:45:28.417Z"},{"id":"CVE-2026-66150","published":"2026-08-11T21:17:49.497","modified":"2026-08-11T22:18:51.760","description":"Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.","score":7.8,"severity":"HIGH","products":[],"vendors":[],"windowsVersions":[],"primaryVendor":"SonicWall","vendorCategory":"Networking & Security","references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0012","label":"psirt.global.sonicwall.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-11T21:17:49.497","changedFields":["remediation"],"lastChangedAt":"2026-09-13T13:15:35.059Z"},{"id":"CVE-2026-66149","published":"2026-08-11T21:17:49.393","modified":"2026-08-11T22:18:51.290","description":"Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.","score":7.8,"severity":"HIGH","products":[],"vendors":[],"windowsVersions":[],"primaryVendor":"SonicWall","vendorCategory":"Networking & Security","references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0012","label":"psirt.global.sonicwall.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-11T21:17:49.393","changedFields":["remediation"],"lastChangedAt":"2026-09-13T13:15:35.059Z"},{"id":"CVE-2026-20349","published":"2026-08-11T17:17:48.833","modified":"2026-08-11T20:17:38.940","description":"A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.&nbsp;\r\n\r\nThis vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.","score":8.6,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF","label":"sec.cloudapps.cisco.com"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20349","label":"cisa.gov"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-11T17:17:48.833","changedFields":["affected products","remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-51583","published":"2026-08-11T14:17:14.323","modified":"2026-08-11T14:17:14.323","description":"An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation mechanism in internal/webhook/validate.go, by setting a webhook target to an internal address.","score":null,"severity":"UNRATED","products":[],"references":[{"url":"https://gist.github.com/seiyaibuki0523/d8af15eb555808319a2633269a9ebb80","label":"gist.github.com"},{"url":"https://github.com/usememos/memos","label":"github.com"}],"kev":null,"firstSeenAt":"2026-08-11T14:17:14.323","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-48056","published":"2026-08-11T14:17:14.170","modified":"2026-08-11T14:17:14.170","description":"Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0  improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.","score":10,"severity":"CRITICAL","products":[],"references":[{"url":"https://github.com/truelockmc/streambert/releases/tag/2.5.0","label":"github.com"},{"url":"https://github.com/truelockmc/streambert/security/advisories/GHSA-x267-77m6-qjc9","label":"github.com"}],"kev":null,"firstSeenAt":"2026-08-11T14:17:14.170","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-48046","published":"2026-08-11T14:17:14.020","modified":"2026-08-11T14:17:14.020","description":"Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch.","score":9.3,"severity":"CRITICAL","products":[],"references":[{"url":"https://github.com/truelockmc/streambert/releases/tag/2.5.0","label":"github.com"},{"url":"https://github.com/truelockmc/streambert/security/advisories/GHSA-vj74-r9xm-37mj","label":"github.com"}],"kev":null,"firstSeenAt":"2026-08-11T14:17:14.020","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-46670","published":"2026-08-11T14:17:13.863","modified":"2026-08-11T14:17:13.863","description":"YesWiki is a wiki system written in PHP. Prior to version 4.6.4,  an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue.","score":9.8,"severity":"CRITICAL","products":[],"references":[{"url":"https://github.com/YesWiki/yeswiki/security/advisories/GHSA-jwvv-qr7q-cv8j","label":"github.com"}],"kev":null,"firstSeenAt":"2026-08-11T14:17:13.863","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-19539","published":"2026-08-11T14:17:13.580","modified":"2026-08-11T14:17:13.580","description":"Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to hijack another company's tickets by reassigning their company_id, and to delete another company's tickets without any authorization check, via the ticket's numeric identifier, because the read and save operations retrieve the record without constraining the query to the authenticated user's company, and the delete controller type-hints a generic Illuminate\\Http\\Request instead of the TicketDeleteRequest that would enforce the required permission.","score":8.6,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/Roskus/prospero-flow-crm/commit/b2b6ffdace0972ab62d1f7e8cdab0ed213bfc4a9","label":"github.com"},{"url":"https://github.com/Roskus/prospero-flow-crm/releases/tag/v5.5.3","label":"github.com"},{"url":"https://secur0.com/en/cna/cve-list/cve-2026-19539-idor-in-prospero-flow-crm-allows-cross-tenant-ticket-read-hijacking-and-deletion","label":"secur0.com"}],"kev":null,"firstSeenAt":"2026-08-11T14:17:13.580","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-19434","published":"2026-08-11T14:17:13.433","modified":"2026-08-11T14:17:13.433","description":"Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup stored in a finding's severity field, which the frontend interpolates unescaped into class and style attributes when rendering the report.","score":5.1,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/ccyl13/Pentestify/commit/8e81053d490f0ba188543b7de3e5edf87112291a","label":"github.com"},{"url":"https://github.com/ccyl13/Pentestify/releases/tag/v2.3.2","label":"github.com"},{"url":"https://secur0.com/en/cna/cve-list/cve-2026-19434-stored-xss-in-pentestify-finding-severity-field","label":"secur0.com"}],"kev":null,"firstSeenAt":"2026-08-11T14:17:13.433","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72785","published":"2026-08-11T13:19:09.220","modified":"2026-08-11T18:18:25.553","description":"Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's category structure — reordering and re-parenting categories — via the structures/move-element action. The structureEditable flag is computed from the view permission rather than the save permission, and the StructuresController authorizes the mutating action on that read-time session grant without a save re-check. Because a category's URI is derived from its position in the structure, moving a category changes its URL and those of its descendants and can corrupt navigation menus built from the category taxonomy. The issue is fixed in 5.10.6.","score":9.3,"severity":"CRITICAL","products":[],"references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-xxpx-f366-4xpq","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/craft-cms-before-authorization-bypass-via-structures-move-element","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:09.220","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72784","published":"2026-08-11T13:19:09.077","modified":"2026-08-11T16:17:37.100","description":"Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-supplied URL server-side. The anti-SSRF validation is incomplete: validateIp() does not cover CGNAT (100.64.0.0/10) or NAT64 (64:ff9b::/96) ranges, and the only IP check runs after the request has already been issued. An attacker holding a GraphQL token scoped only to asset-creation permissions can disclose internal HTTP content from CGNAT/NAT64 targets, force outbound GET requests to internal hosts (including RFC1918, loopback, and metadata endpoints), and enumerate internal services.","score":6.9,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-2mx8-9ww7-p27x","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/craft-cms-rc1-before-ssrf-via-graphql-asset-mutation","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:09.077","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72783","published":"2026-08-11T13:19:08.940","modified":"2026-08-11T13:19:08.940","description":"Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContained function of the Local file system class. The order of operations validates the path before normalization, so normalization could invalidate prior validation assumptions (a desanitization-style issue) and potentially resolve to files outside the intended volume directory. The vendor notes the issue is not directly exploitable and no exploitable scenario has been discovered; the fix is recommended for hardening.","score":6.9,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-7hxc-f267-h5q7","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/craft-cms-rc1-before-path-traversal-via-ensurepathiscontained","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:08.940","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72782","published":"2026-08-11T13:19:08.797","modified":"2026-08-11T18:18:25.430","description":"Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates before rendering, even when the Twig sandbox is enabled. An authenticated attacker with control panel access can render a malicious sandboxed Twig template and, using a blind error-based technique across many requests, incrementally leak arbitrary environment variables and secrets. These can be abused to forge sessions (via CRAFT_SECURITY_KEY), escalate privileges, and steal database, SMTP, API, or blob storage credentials. Fixed in 5.10.6 and 4.18.2.","score":7.1,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-596p-6jv8-775v","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/craft-cms-rc1-before-environment-variable-leak","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:08.797","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72781","published":"2026-08-11T13:19:08.657","modified":"2026-08-11T15:17:36.130","description":"Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribute) and the sandbox allowlisting extends to the entire class hierarchy (craft\\base\\Component up to yii\\base\\Component), an authenticated attacker with permission to access the control panel can render a malicious Twig template that abuses the yii\\base\\Component arbitrary function-call gadget to execute arbitrary code, even when the Twig sandbox is enabled via enableTwigSandbox().","score":8.7,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-f5wm-88jv-g5hx","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/craft-cms-rc1-before-remote-code-execution-via-twig-sandbox-escape","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:08.657","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72780","published":"2026-08-11T13:19:08.510","modified":"2026-08-11T18:18:25.313","description":"Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional authenticated sessions for victim accounts.","score":7.1,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-wg23-69c2-gjc8","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/craft-cms-before-webauthn-assertion-replay-via-login-with-passkey","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:08.510","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72779","published":"2026-08-11T13:19:08.360","modified":"2026-08-11T16:17:36.973","description":"Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that does not include SplFileObject, allowing an authenticated administrator (with allowAdminChanges=true) to configure a malicious entry type title or URI format that instantiates SplFileObject in a non-sandboxed template context. When a user subsequently creates an entry in the affected section, arbitrary files on the server (such as .env containing the security key and database credentials) are read and rendered as entry titles.","score":8.7,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-957r-qf9p-67xw","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/craft-cms-rc1-before-arbitrary-file-read-via-splfileobject","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:08.360","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72778","published":"2026-08-11T13:19:08.207","modified":"2026-08-11T13:19:08.207","description":"Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled condition array via Component::cleanseConfig(), but Conditions::createCondition() later decodes and merges the JSON string in condition.config without re-running cleanseConfig() on the decoded configuration. Because condition.config is a JSON string during the first cleanse, Yii special config keys such as 'as ...' and 'on ...' can be hidden inside it and, after JSON decoding, are interpreted by Yii as behavior/event configuration during FieldLayout object creation. An attacker with an authenticated control panel session (and a valid CSRF token) can exploit this to execute operating system commands as the PHP/web user.","score":8.7,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-265m-7826-wjqm","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/craft-cms-rc1-before-authenticated-rce-via-condition-config","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:08.207","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72775","published":"2026-08-11T13:19:08.040","modified":"2026-08-11T18:18:25.190","description":"n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifier parameters (channel, function, and trigger names) into SQL statements without proper escaping. An authenticated user can inject arbitrary SQL executed against the connected PostgreSQL database with the configured credential's privileges, allowing full read and write access.","score":5.8,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-jqwr-vx3p-r266","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-sql-injection-via-postgrestrigger-node","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:08.040","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72774","published":"2026-08-11T13:19:07.893","modified":"2026-08-11T15:17:36.010","description":"n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared workflow can reference another user's credential while specifying the credential type via an expression. Because the pre-execution permission check compares the unresolved expression instead of the resolved credential type, the ownership check is skipped and the credential is loaded at execution time, allowing the member to use or exfiltrate a credential they were not granted. Exploitation requires knowing the target credential's identifier.","score":7.1,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-6qc9-mqvw-jg7x","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-authentication-bypass-via-http-request-node","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:07.893","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72773","published":"2026-08-11T13:19:07.757","modified":"2026-08-11T18:18:25.040","description":"n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory confinement check and expand to locations outside the configured directory, causing the tool to return the names and contents of arbitrary local files readable by the daemon's OS user. Any deployment where an actor can influence the tool's search input is affected.","score":4.9,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-pf2q-pxhf-hgmw","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-path-traversal-via-computer-use-search-files","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:07.757","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72772","published":"2026-08-11T13:19:07.623","modified":"2026-08-11T16:17:36.860","description":"n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched to a local account by its email claim, the service did not verify that the email claim was verified, nor that the trusted key's permitted role ceiling covered that account. As a result, anyone able to obtain a token accepted by a configured trusted key (for example, a trusted issuer emitting unverified email addresses) could authenticate as any existing user and gain full account control. This issue only affects instances where the embed login feature is enabled and at least one trusted key source is configured.","score":8.9,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-8342-988q-86cr","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-authentication-bypass-via-token-exchange","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:07.623","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72771","published":"2026-08-11T13:19:07.490","modified":"2026-08-11T13:19:07.490","description":"n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are configured. Low-privileged workflow editors with use-only access to shared credentials can redirect requests to attacker-controlled hosts and exfiltrate credential secrets for reuse against underlying services.","score":7.1,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-64xh-79j6-r5v8","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-credential-restriction-bypass-via-ai-llm-nodes","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:07.490","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72770","published":"2026-08-11T13:19:07.353","modified":"2026-08-11T18:18:24.887","description":"n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated users to bypass repository-path containment checks. Attackers with workflow create/execute rights can point allowlisted remote configurations at local paths outside the sandbox to pull arbitrary git repositories and read their files and history.","score":7.1,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-gf29-4f56-r2jf","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-path-traversal-via-git-node-operations","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:07.353","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72769","published":"2026-08-11T13:19:07.220","modified":"2026-08-11T15:17:35.880","description":"n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process (a sandbox escape), leading to a denial of service. Both self-hosted and cloud instances running the VM expression engine are affected.","score":6.1,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-hx4h-vr3m-45vh","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-prototype-pollution-via-vm-expression-engine","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:07.220","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72768","published":"2026-08-11T13:19:07.077","modified":"2026-08-11T18:18:24.757","description":"n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections. Attackers can craft workflows that send requests to internal or blocked hosts without routing through SSRF protection, exposing internal services and reading responses back through the workflow.","score":6.4,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-vhf8-cg2h-cg3p","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-ssrf-protection-bypass-via-mcp-client","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:07.077","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72767","published":"2026-08-11T13:19:06.940","modified":"2026-08-11T16:17:36.737","description":"n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users with rights to create and execute workflows can stage a crafted local repository that causes git to run hooks under default git security settings, executing arbitrary commands as the n8n process user. Both self-hosted and cloud instances are affected.","score":8.7,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-rcv6-pvrj-4xcg","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-remote-code-execution-via-git-node","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:06.940","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72766","published":"2026-08-11T13:19:06.807","modified":"2026-08-11T13:19:06.807","description":"n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that its message fields are strings. A crafted non-string value supplied from a workflow expression into the text or HTML body field can be interpreted by the underlying mail library (Nodemailer) as a file path or URL, allowing arbitrary local file disclosure and server-side request forgery (SSRF). Exploitation requires a pre-existing active workflow with an unauthenticated webhook, valid SMTP credentials configured on the node, and untrusted input mapped directly into the body field; this is not a default configuration.","score":8.2,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-2x35-3fw4-9jr4","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-arbitrary-file-read-via-send-email-node","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:06.807","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72765","published":"2026-08-11T13:19:06.670","modified":"2026-08-11T18:18:24.623","description":"n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using arrow-function bodies to bypass the expression sandbox, triggering system command execution on the host running n8n. The issue is fixed in versions 2.31.5 and 2.32.1.","score":8.7,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-gv7g-jm28-cr3m","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-remote-code-execution-via-expression-sandbox-escape","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:06.670","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72764","published":"2026-08-11T13:19:06.530","modified":"2026-08-11T15:17:35.757","description":"n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able to run a Code node could poison a cached module and thereby alter other users' Code-node executions on the same runner, affecting their confidentiality, integrity, or availability. This is a cross-user isolation break within a single n8n instance and does not constitute a sandbox escape or remote code execution. Only multi-user instances running the JS task runner with built-in or external modules enabled are affected.","score":5.8,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-9cmh-xcqm-5hqr","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-module-cache-poisoning-via-code-node","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:06.530","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72763","published":"2026-08-11T13:19:06.367","modified":"2026-08-11T18:18:24.477","description":"n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for credentials referenced inside an Execute Sub-workflow node's inline workflow JSON. A member with Editor access to a shared workflow (when workflow sharing is enabled) who knows a target credential's ID can reference that credential in the inline JSON; it passes save-time and runtime validation and resolves in the parent workflow's project context, allowing the attacker to use or exfiltrate credentials they are not permitted to access.","score":7.2,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-cj9h-qx8g-pq2g","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-credential-exfiltration-via-sub-workflow","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:06.367","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72762","published":"2026-08-11T13:19:06.230","modified":"2026-08-11T16:17:36.620","description":"n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to the underlying image library without validation. An authenticated user able to run workflows can supply a crafted format value to write arbitrary files outside the node's working directory on the n8n instance.","score":7.7,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-xmc9-4f2h-jf9c","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-arbitrary-file-write-via-edit-image-node","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:06.230","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72750","published":"2026-08-11T13:19:06.097","modified":"2026-08-11T13:19:06.097","description":"n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates expression values directly into the SQL string. When a workflow author embeds untrusted, externally-controlled expression data directly in a raw SQL query, that data is not parameterized, allowing SQL injection. The fix adds an optional 'Query Parameters' field to bind values via positional placeholders.","score":5.3,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-652q-gvq3-74qv","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-sql-injection-via-executequery-operation","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:06.097","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72749","published":"2026-08-11T13:19:05.960","modified":"2026-08-11T18:18:24.303","description":"n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output fields via a dot-notation path setter without restricting the field name, allowing an authenticated user to name a field after an inherited built-in method path and corrupt a shared global in the main Node.js process. Because that global is used on the request-authentication path, the instance then fails every authenticated request, causing an instance-wide denial of service for all users until the process is restarted.","score":7.1,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-xwx6-jjhv-84p8","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/n8n-before-prototype-pollution-via-edit-fields","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:05.960","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72748","published":"2026-08-11T13:19:05.813","modified":"2026-08-11T15:17:35.623","description":"AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achieve remote code execution.","score":6.9,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/WWBN/AVideo/commit/1b55a9b3c4911d2f31594ce2e60566c70c6b95e8","label":"github.com"},{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-v7p7-jccx-h37c","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/avideo-unauthenticated-arbitrary-file-write-via-avideoencoderchunk-json-php","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:05.813","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72747","published":"2026-08-11T13:19:05.663","modified":"2026-08-11T18:18:24.060","description":"AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session.","score":5.1,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/WWBN/AVideo/commit/1adcb75458a3b31058655698a833e8cbde4d0593","label":"github.com"},{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-cfvq-r985-84wj","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/avideo-stored-cross-site-scripting-via-unauthenticated-registration","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:05.663","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72746","published":"2026-08-11T13:19:05.520","modified":"2026-08-11T16:17:36.480","description":"FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, the handshake dispatches inbound PDUs based solely on the attacker-supplied wire pduType without verifying that the received PDU is the one required at the current step. Because the rdpRdstls object is calloc-zeroed, its resultCode defaults to 0 (RDSTLS_RESULT_SUCCESS). An unauthenticated remote client can send a Capabilities PDU instead of the required Authentication Request PDU; rdstls_process_capabilities() returns success without ever setting resultCode, so the server responds with an AUTHRSP carrying resultCode SUCCESS and treats the session as authenticated without evaluating any password, redirection GUID, or auto-reconnect cookie. This affects the released FreeRDP 3.x series (e.g., 3.27.1) and master HEAD; at the time of the advisory no patched version was available.","score":8.7,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/FreeRDP/FreeRDP/commit/b05a9510787c83c87ffc5fa8d7cc9f06ed971695","label":"github.com"},{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rqgv-grx4-xm6x","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/freerdp-before-rdstls-server-authentication-bypass-via-pdu-type-confusion","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:05.520","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72745","published":"2026-08-11T13:19:05.370","modified":"2026-08-11T13:19:05.370","description":"FreeRDP before 3.30.0 contains an out-of-bounds vulnerability in kerberos_DecryptMessage() (winpr/libwinpr/sspi/Kerberos/kerberos.c). The 16-bit EC (extra count) field of a peer-supplied GSS Wrap token (RFC 4121) is used directly in pointer arithmetic to locate the encrypted regions without being bounds-checked, while only RRC and the total buffer length are validated. A malicious peer (server or client) can supply a large EC value (up to 0xFFFF) during CredSSP/NLA authentication, moving the decrypt operation's base pointers past the end of the ~60-byte token buffer. Because the AES-CTS-HMAC enctypes decrypt in place before the HMAC integrity check, this results in an out-of-bounds read and in-place out-of-bounds write, potentially leading to information disclosure, memory corruption, or denial of service.","score":8.7,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/freerdp-before-out-of-bounds-read-via-kerberos-gss-wrap-token-ec","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:05.370","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72744","published":"2026-08-11T13:19:05.210","modified":"2026-08-11T18:18:23.890","description":"Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome DevTools workspace endpoint (GET /.well-known/appspecific/com.chrome.devtools.json). The endpoint's local-request gate (isLocalDevRequest) is header-based and trusts the attacker-supplied Host header rather than the connected peer address. When the dev server is bound to a network-reachable interface (e.g. nuxt dev --host) and experimental.chromeDevtoolsProjectSettings is enabled (the default), an unauthenticated attacker on the LAN can send a request with a spoofed Host header and no browser-specific headers (Sec-Fetch-Site, Origin, Referer) to retrieve the project's absolute filesystem root path (rootDir) and a persistent per-project workspace UUID. Production builds are unaffected. Fixed in 4.5.1 and 3.21.10.","score":6.9,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/nuxt/nuxt/security/advisories/GHSA-7c4v-fwgw-9rf7","label":"github.com"},{"url":"https://www.vulncheck.com/advisories/nuxt-before-information-disclosure-via-chrome-devtools","label":"vulncheck.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:05.210","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-69109","published":"2026-08-11T13:19:02.030","modified":"2026-08-11T18:18:17.730","description":"A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.","score":8.7,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-077553.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:02.030","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-69108","published":"2026-08-11T13:19:01.883","modified":"2026-08-11T15:17:34.647","description":"A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privilege escalation due to an insecure sudoers policy. This could allow an attacker to execute arbitrary commands and plant malicious files as root, leading to full system compromise.","score":8.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-077553.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:01.883","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-64629","published":"2026-08-11T13:19:01.560","modified":"2026-08-11T13:19:01.560","description":"A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.","score":7.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-138516.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:01.560","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59701","published":"2026-08-11T13:19:00.763","modified":"2026-08-11T14:17:14.850","description":"A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.","score":7.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-584312.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:00.763","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59700","published":"2026-08-11T13:19:00.627","modified":"2026-08-11T13:19:00.627","description":"A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.","score":7.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-584312.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:00.627","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59693","published":"2026-08-11T13:19:00.477","modified":"2026-08-11T18:17:41.267","description":"A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01.21.233.16-7862), Desigo PXC4 (All versions < V02.21.194.36-2715), Desigo PXC5.E003 (All versions < V02.21.194.36-2715), Desigo PXC5.E24 (All versions < V02.21.194.36-2715), Desigo PXC7 (All versions < V02.21.194.36-2715). The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality.","score":5.3,"severity":"MEDIUM","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-781903.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:00.477","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59086","published":"2026-08-11T13:19:00.333","modified":"2026-08-11T15:17:32.637","description":"A vulnerability has been identified in Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.","score":7.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-069220.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:00.333","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-58115","published":"2026-08-11T13:19:00.190","modified":"2026-08-11T13:19:00.190","description":"A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing system commands on the server.\r\nThis could allow an unauthenticated remote attacker to create malicious flows through the HTTP interface in order to execute arbitrary code on the underlying server with maximum privileges.","score":10,"severity":"CRITICAL","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-834709.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:19:00.190","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-57263","published":"2026-08-11T13:18:59.607","modified":"2026-08-11T14:17:14.590","description":"A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affected products stores the password as an unsalted SHA-256 hash. This could allow an attacker who has obtained the project file to perform efficient offline dictionary or brute-force attacks against the unsalted hash.","score":7,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-751328.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:18:59.607","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-57262","published":"2026-08-11T13:18:59.463","modified":"2026-08-11T13:18:59.463","description":"A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded AES master key to encrypt project files. This could allow a local attacker to extract the master key from the application files or memory and use it to decrypt project files or remove project passwords entirely without knowing the actual user-defined password.","score":7,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-751328.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:18:59.463","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-50064","published":"2026-08-11T13:18:58.990","modified":"2026-08-11T18:17:35.633","description":"A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PSM files. This could allow an attacker to execute code in the context of the current process.","score":7.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-621657.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:18:58.990","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-50063","published":"2026-08-11T13:18:58.860","modified":"2026-08-11T15:17:30.990","description":"A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.","score":7.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-621657.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:18:58.860","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-50062","published":"2026-08-11T13:18:58.720","modified":"2026-08-11T13:18:58.720","description":"A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.","score":7.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-621657.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:18:58.720","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-50061","published":"2026-08-11T13:18:58.583","modified":"2026-08-11T15:17:30.847","description":"A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.","score":7.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-621657.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:18:58.583","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-50060","published":"2026-08-11T13:18:58.447","modified":"2026-08-11T13:18:58.447","description":"A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.","score":7.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-621657.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:18:58.447","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-50059","published":"2026-08-11T13:18:58.313","modified":"2026-08-11T18:17:35.120","description":"A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.","score":7.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-621657.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:18:58.313","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-50058","published":"2026-08-11T13:18:58.153","modified":"2026-08-11T15:17:30.730","description":"A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update 7). The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.","score":7.3,"severity":"HIGH","products":[],"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-621657.html","label":"cert-portal.siemens.com"}],"kev":null,"firstSeenAt":"2026-08-11T13:18:58.153","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-18972","published":"2026-08-11T13:17:56.997","modified":"2026-08-11T14:17:12.920","description":"An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \\\"Grpc-Metadata-USER\\\". This can lead to an account takeover attack from a user with low privileges to administrator.","score":9.6,"severity":"CRITICAL","products":[],"references":[{"url":"http://docs.velociraptor.app/announcements/advisories/cve-2026-18972/","label":"docs.velociraptor.app"}],"kev":null,"firstSeenAt":"2026-08-11T13:17:56.997","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72610","published":"2026-08-11T12:17:44.257","modified":"2026-08-11T13:19:05.077","description":"A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the borrowers => edit_borrowers permission to cause a time-based denial of service by storing a SQL payload in a patron lang field. The value is concatenated raw into a subquery in Koha::AdditionalContents->search_for_display when an issue slip is printed for the affected patron. The 25-character column length limits exploitation to timing attacks; data extraction is not practical. The stored payload executes on each subsequent issue-slip print, scaling linearly with the SLEEP value and the number of slip-news rows.","score":4.3,"severity":"MEDIUM","products":[],"references":[{"url":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42866","label":"bugs.koha-community.org"},{"url":"https://koha-community.org/","label":"koha-community.org"}],"kev":null,"firstSeenAt":"2026-08-11T12:17:44.257","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72609","published":"2026-08-11T12:17:44.120","modified":"2026-08-11T13:19:04.957","description":"An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the acquisition => order_receive permission to read arbitrary database contents via the orderby request parameter in acqui/parcels.pl. The parameter is passed to C4::Acquisition::GetInvoices, which allow-lists the column name but concatenates the direction token raw into the SQL ORDER BY clause without validation. Exploitation is blind (time-based) in production and allows extraction of patron PII, staff bcrypt password hashes, and two-factor secrets.","score":7.1,"severity":"HIGH","products":[],"references":[{"url":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42749","label":"bugs.koha-community.org"},{"url":"https://koha-community.org/","label":"koha-community.org"}],"kev":null,"firstSeenAt":"2026-08-11T12:17:44.120","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72608","published":"2026-08-11T12:17:43.987","modified":"2026-08-11T13:19:04.843","description":"A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_creator permission to execute arbitrary SQL via the image_name field of a patron card layout. The image_name value is stored verbatim in the layout XML and later concatenated raw into a SQL query in patroncards/create-pdf.pl when a patron card batch is printed. An attacker can read the entire Koha database including patron PII and staff bcrypt password hashes via error-based or time-based blind injection.","score":6.5,"severity":"MEDIUM","products":[],"references":[{"url":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42747","label":"bugs.koha-community.org"},{"url":"https://koha-community.org/","label":"koha-community.org"}],"kev":null,"firstSeenAt":"2026-08-11T12:17:43.987","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72607","published":"2026-08-11T12:17:43.867","modified":"2026-08-11T13:19:04.733","description":"A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_batchmod permission to read arbitrary database contents by storing a SQL payload in the agefield value of an automatic item modification rule. The agefield value is stored verbatim to the system preference and later interpolated without parameterization into a SQL query in C4::Items::ToggleNewStatus (line 1228) when the scheduled cron job executes. The injection is SELECT-only under standard MariaDB/MySQL DBI single-statement execution; a time-based SLEEP payload is also achievable via the cron trigger. An attacker can read the entire Koha database including patron PII and staff bcrypt password hashes.","score":7.1,"severity":"HIGH","products":[],"references":[{"url":"https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=42746","label":"bugs.koha-community.org"},{"url":"https://koha-community.org/","label":"koha-community.org"}],"kev":null,"firstSeenAt":"2026-08-11T12:17:43.867","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72606","published":"2026-08-11T12:17:43.743","modified":"2026-08-11T13:19:04.623","description":"A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the pin-from-URL feature. The feature passes the user-supplied URL directly to requests.get() without host or IP validation, and ALLOW_NEW_REGISTRATIONS defaults to true enabling anonymous triggering. An attacker can reach internal services or cloud metadata endpoints from the server.","score":7.5,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/pinry/pinry","label":"github.com"}],"kev":null,"firstSeenAt":"2026-08-11T12:17:43.743","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72605","published":"2026-08-11T12:17:43.623","modified":"2026-08-11T13:19:04.527","description":"A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use it to access protected functionality on the server.","score":7.5,"severity":"HIGH","products":[],"references":[{"url":"https://github.com/swingmx/swingmusic","label":"github.com"}],"kev":null,"firstSeenAt":"2026-08-11T12:17:43.623","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72604","published":"2026-08-11T12:17:43.507","modified":"2026-08-11T13:19:04.420","description":"A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server via the admin panel file deletion endpoint. The endpoint passes a user-supplied file path directly to unlink() without sanitization or path canonicalization. An authenticated administrator can delete sensitive system files outside the web root, potentially causing server instability or facilitating further attacks.","score":6.5,"severity":"MEDIUM","products":[],"references":[{"url":"https://github.com/intelliants/subrion","label":"github.com"}],"kev":null,"firstSeenAt":"2026-08-11T12:17:43.507","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-50472","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50472","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-56174","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 23H2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56174","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-54113","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.5,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54113","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-54984","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54984","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-49179","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49179","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59127","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59127","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59128","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59128","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59130","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.6,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59130","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59132","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.5,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59132","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59135","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59135","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59134","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.5,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59134","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59136","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59136","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59137","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59137","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59138","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59138","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61345","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61345","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61346","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61346","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61353","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61353","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61347","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61347","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61361","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61361","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61348","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61348","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61350","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":4.6,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61350","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61356","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61356","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61367","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61367","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61923","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61923","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61366","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61366","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61368","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61368","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61924","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61924","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61925","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61925","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61927","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61927","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61928","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61928","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61930","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61930","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61937","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61937","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62692","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62692","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61932","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows 11 23H2","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61932","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61933","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61933","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61934","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61934","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61936","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61936","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61939","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61939","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62695","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation); see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62695","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62688","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62688","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121003","label":"5121003"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120994","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120994","label":"5120994"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62690","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62690","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62693","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62693","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121003","label":"5121003"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120994","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120994","label":"5120994"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62696","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62696","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62702","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems; see the authoritative advisory for technical details.","score":6.8,"severity":"MEDIUM","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62702","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62699","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.8,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62699","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62703","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62703","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62705","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62705","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121003","label":"5121003"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120994","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120994","label":"5120994"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62707","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62707","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62713","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62713","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62712","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62712","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62718","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62718","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62715","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62715","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62716","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62716","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62719","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62719","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62722","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62722","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62723","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62723","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62724","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62724","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62748","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62748","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62729","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62729","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62746","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62746","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62740","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62740","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62753","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62753","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62735","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62735","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62737","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62737","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62739","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62739","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62742","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62742","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62745","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62745","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62747","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62747","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62750","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62750","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62754","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62754","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62783","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62783","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62755","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62755","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62758","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62758","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62766","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62766","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62773","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62773","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62772","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62772","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121000","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121000","label":"5121000"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62774","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62774","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62785","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62785","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62777","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62777","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62779","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62779","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62792","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.1,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62792","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62784","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62784","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62787","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.5,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62787","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62798","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62798","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62795","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62795","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62796","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62796","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62797","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62797","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62812","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62812","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62815","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation); see the authoritative advisory for technical details.","score":9.8,"severity":"CRITICAL","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62816","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62816","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62817","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62817","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62818","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62818","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62819","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.1,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62819","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62820","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.1,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62820","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62876","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62876","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62877","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62877","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62878","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":9.8,"severity":"CRITICAL","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62878","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62889","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.1,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62889","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62890","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62890","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62892","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62892","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62893","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":9.8,"severity":"CRITICAL","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62893","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62894","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62894","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62897","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, .NET 10.0 installed on Mac OS, Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems",".NET 10.0 installed on Mac OS","Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems","Microsoft .NET Framework 4.8.1 on Windows 11 version 26H1 for x64-based Systems",".NET 9.0 installed on Mac OS",".NET 10.0 installed on Windows",".NET 10.0 installed on Linux","Microsoft .NET Framework 3.5 on Windows 11 version 26H1 for x64-based Systems",".NET 8.0 installed on Mac OS",".NET 8.0 installed on Linux",".NET 9.0 installed on Linux",".NET 8.0 installed on Windows",".NET 9.0 installed on Windows","Microsoft Visual Studio 2026 version 18.8","Microsoft Visual Studio 2022 version 17.14","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems","Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 26H1","Windows 10 1809"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62897","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120711","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120711","label":"5120711"},{"url":"https://dotnet.microsoft.com/download/dotnet/10.0","label":"Security Update"},{"url":"https://support.microsoft.com/help/5122106","label":"5122106"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":["affected products"],"lastChangedAt":"2026-09-01T00:15:34.205Z"},{"id":"CVE-2026-62908","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62908","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65662","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65662","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65671","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65671","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65672","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation); see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65672","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65678","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65678","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65785","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65785","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65784","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65784","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65786","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65786","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65789","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.1,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65789","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65787","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65787","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65788","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65788","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65814","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65814","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-66799","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66799","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-68819","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.9,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68819","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-68820","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-70307","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70307","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-70304","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.7,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70304","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-70330","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.7,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70330","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61352","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.5,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61352","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65783","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 25H2","Windows 11 24H2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65783","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121003","label":"5121003"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120994","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120994","label":"5120994"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-66804","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 22H2 for x64-based Systems, Windows 10 Version 22H2 for ARM64-based Systems, Windows 10 Version 22H2 for 32-bit Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 22H2","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120249","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120249","label":"5120249"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121003","label":"5121003"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-70344","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70344","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-70345","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70345","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-70346","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70346","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-70347","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70347","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-70348","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70348","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121003","label":"5121003"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120994","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120994","label":"5120994"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-72971","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121000","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121000","label":"5121000"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-42976","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for x64-based Systems, Windows Server 2022, Windows Server 2022 (Server Core installation); see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for x64-based Systems","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2019 (Server Core installation)","Windows 10 Version 1809 for 32-bit Systems","Windows Server 2019","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows 10 Version 22H2 for x64-based Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2022","Windows Server 2019","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42976","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5094123","label":"Security Update"},{"url":"https://support.microsoft.com/help/5094123","label":"5094123"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59122","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59122","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59125","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59125","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59126","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59126","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-59131","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.6,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59131","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61349","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61349","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61363","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.5,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61363","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61359","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation); see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61359","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61355","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61355","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61364","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61364","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61365","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61365","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61357","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61357","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61358","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61358","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61360","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61360","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61920","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.6,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61920","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61926","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61926","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61918","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61918","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61921","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61921","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61929","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61929","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-61938","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-61938","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62698","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62698","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62700","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62700","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62701","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62701","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62708","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":6.4,"severity":"MEDIUM","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62708","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62709","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62709","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62710","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62710","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62711","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62711","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62720","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62720","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62714","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62714","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62717","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62717","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62721","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62721","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62725","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62725","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62726","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62726","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62728","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62728","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62733","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62733","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62743","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62743","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62730","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62730","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62732","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62732","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62734","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62734","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62736","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62736","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62757","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.3,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62757","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62741","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62741","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62749","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62749","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62751","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62751","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62752","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62752","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62769","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.7,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62769","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62771","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62771","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62761","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62761","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62768","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62768","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62770","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62770","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62775","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62775","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121000","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121000","label":"5121000"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62799","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 26H1 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62799","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121000","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121000","label":"5121000"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62776","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62776","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62778","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.1,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62778","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62780","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62780","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62782","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62782","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62781","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.1,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62781","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62800","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62800","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62786","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62786","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62788","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62788","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62790","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62790","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62793","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62793","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62803","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62803","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62807","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62807","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62811","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation); see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62811","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62814","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62814","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62823","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62823","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62824","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows Server 2016; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62824","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120418","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120418","label":"5120418"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120386","label":"Monthly Rollup"},{"url":"https://support.microsoft.com/help/5120386","label":"5120386"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62822","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62822","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62832","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62872","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation), Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016; see the authoritative advisory for technical details.","score":8.8,"severity":"HIGH","products":["Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation)","Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems","Microsoft .NET Framework 4.8 on Windows Server 2016","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems","Microsoft .NET Framework 4.8 on Windows Server 2012 R2","Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation)","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for 32-bit Systems","Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems","Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems","Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016","Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016 (Server Core installation)","Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012","Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)","Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)","Microsoft .NET Framework 4.8.1 on Windows 11 version 26H1 for x64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2016","Windows 10 1607","Windows 10 1809","Windows Server 2012 R2","Windows 10 21H2","Windows 10 22H2","Windows Server 2012","Windows 11 26H1","Windows Server 2022","Windows Server 2025","Windows 11 23H2","Windows 11 25H2","Windows 11 24H2","Windows Server 2019"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62872","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120702","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120702","label":"5120702"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120703","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120703","label":"5120703"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62880","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62880","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62881","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.7,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62881","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62883","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.7,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62883","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62885","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62885","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62887","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62887","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62888","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows 10 Version 21H2 for 32-bit Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62888","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65681","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.5,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65681","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65679","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.1,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65679","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65773","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65773","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65774","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65774","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65775","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65775","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65776","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65776","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65777","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2022, Windows Server 2022 (Server Core installation), Windows Server 2025 (Server Core installation); see the authoritative advisory for technical details.","score":5.3,"severity":"MEDIUM","products":["Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2022","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65777","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120229","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120229","label":"5120229"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65779","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65779","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121003","label":"5121003"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120994","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120994","label":"5120994"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65780","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65780","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121003","label":"5121003"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120994","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120994","label":"5120994"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65778","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 25H2","Windows 11 24H2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65778","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121003","label":"5121003"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120994","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120994","label":"5120994"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65782","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 25H2","Windows 11 24H2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65782","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121003","label":"5121003"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120994","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120994","label":"5120994"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65781","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows 11 Version 24H2 for ARM64-based Systems; see the authoritative advisory for technical details.","score":7,"severity":"HIGH","products":["Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 25H2","Windows 11 24H2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65781","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003","label":"Security Update"},{"url":"https://support.microsoft.com/help/5121003","label":"5121003"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120994","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120994","label":"5120994"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65790","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65790","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65791","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":9.8,"severity":"CRITICAL","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65791","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65795","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.7,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65795","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65794","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65794","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65797","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.7,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65797","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65799","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.7,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65799","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65798","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":6.7,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65798","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65796","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.9,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 10 Version 1607 for 32-bit Systems","Windows 10 Version 1607 for x64-based Systems","Windows Server 2016","Windows Server 2016 (Server Core installation)","Windows Server 2012","Windows Server 2012 (Server Core installation)","Windows Server 2012 R2","Windows Server 2012 R2 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65796","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-65810","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Microsoft .NET Framework 4.8.1 on Windows 11 version 26H1 for x64-based Systems, Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems, Microsoft .NET Framework 3.5 on Windows 11 version 26H1 for x64-based Systems; see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Microsoft .NET Framework 4.8.1 on Windows 11 version 26H1 for x64-based Systems","Microsoft .NET Framework 4.8.1 on Windows 11 Version 26H1 for ARM64-based Systems","Microsoft .NET Framework 3.5 on Windows 11 version 26H1 for x64-based Systems","Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems","Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems","Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems","Microsoft .NET Framework 4.8 on Windows Server 2016","Microsoft .NET Framework 4.8 on Windows Server 2016 (Server Core installation)","Microsoft .NET Framework 4.8 on Windows Server 2012","Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation)","Microsoft .NET Framework 4.8 on Windows Server 2012 R2","Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation)","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems","Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019","Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019 (Server Core installation)","Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022","Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2","Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65810","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120711","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120711","label":"5120711"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120747","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120747","label":"5120747"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-66802","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.1,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66802","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-56179","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows Server 2025 (Server Core installation), Windows 11 Version 25H2 for ARM64-based Systems, Windows 11 Version 25H2 for x64-based Systems; see the authoritative advisory for technical details.","score":8.3,"severity":"HIGH","products":["Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025","Windows 11 version 26H1 for x64-based Systems","Windows 11 Version 26H1 for ARM64-based Systems"],"vendors":["Microsoft"],"windowsVersions":["Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 26H1"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56179","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120233","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120233","label":"5120233"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120228","label":"Security Hotpatch Update"},{"url":"https://support.microsoft.com/help/5120228","label":"5120228"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-70354","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 on Windows Server 2012, Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation); see the authoritative advisory for technical details.","score":7.8,"severity":"HIGH","products":["Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems","Microsoft .NET Framework 3.5 on Windows Server 2012","Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation)","Microsoft .NET Framework 3.5 on Windows 11 Version 26H1 for ARM64-based Systems","Microsoft .NET Framework 3.5 on Windows Server 2012 R2","Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems","Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation)","Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems","Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems","Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems","Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016 (Server Core installation)","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems","Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019","Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019 (Server Core installation)","Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems","Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019","Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 22H2 for x64-based Systems","Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1607","Windows Server 2012","Windows 11 26H1","Windows Server 2012 R2","Windows Server 2016","Windows 10 1809","Windows Server 2019","Windows 10 22H2","Windows Server 2022","Windows 10 21H2","Windows Server 2025","Windows 11 25H2","Windows 11 24H2","Windows 11 23H2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70354","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120418","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120418","label":"5120418"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120716","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120716","label":"5120716"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":["affected products"],"lastChangedAt":"2026-08-14T19:30:49.526Z"},{"id":"CVE-2026-71331","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":8.1,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows Server 2025 (Server Core installation)","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows Server 2025"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71331","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-62738","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.5,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607","Windows Server 2016","Windows Server 2012","Windows Server 2012 R2"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62738","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-6727","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":5.9,"severity":"MEDIUM","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6727","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-6726","published":"2026-08-11T07:00:00.000Z","modified":"2026-08-11T07:00:00.000Z","description":"Microsoft security vulnerability affecting Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for x64-based Systems, Windows Server 2019; see the authoritative advisory for technical details.","score":7.9,"severity":"HIGH","products":["Windows 10 Version 1809 for 32-bit Systems","Windows 10 Version 1809 for x64-based Systems","Windows Server 2019","Windows Server 2019 (Server Core installation)","Windows Server 2022","Windows Server 2022 (Server Core installation)","Windows 10 Version 21H2 for 32-bit Systems","Windows 10 Version 21H2 for ARM64-based Systems","Windows 10 Version 21H2 for x64-based Systems","Windows 10 Version 22H2 for x64-based Systems","Windows 10 Version 22H2 for ARM64-based Systems","Windows 10 Version 22H2 for 32-bit Systems","Windows Server 2025 (Server Core installation)","Windows 11 Version 25H2 for ARM64-based Systems","Windows 11 Version 25H2 for x64-based Systems","Windows 11 Version 23H2 for ARM64-based Systems","Windows 11 Version 23H2 for x64-based Systems","Windows 11 Version 24H2 for ARM64-based Systems","Windows 11 Version 24H2 for x64-based Systems","Windows Server 2025"],"vendors":["Microsoft"],"windowsVersions":["Windows 10 1809","Windows Server 2019","Windows Server 2022","Windows 10 21H2","Windows 10 22H2","Windows Server 2025","Windows 11 25H2","Windows 11 23H2","Windows 11 24H2","Windows 11 26H1","Windows 10 1607"],"primaryVendor":"Microsoft","vendorCategory":"End User Compute","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6726","label":"Microsoft Security Update Guide"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120238","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120238","label":"5120238"},{"url":"https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120242","label":"Security Update"},{"url":"https://support.microsoft.com/help/5120242","label":"5120242"}],"kev":null,"source":"Microsoft MSRC","firstSeenAt":"2026-08-11T07:00:00.000Z","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-66151","published":"2026-08-07T20:16:52.750","modified":"2026-08-11T20:18:37.943","description":"SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.","score":5.5,"severity":"MEDIUM","products":[],"vendors":[],"windowsVersions":[],"primaryVendor":"SonicWall","vendorCategory":"Networking & Security","references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0010","label":"psirt.global.sonicwall.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-07T20:16:52.750","changedFields":["remediation"],"lastChangedAt":"2026-09-13T13:15:35.059Z"},{"id":"CVE-2026-20313","published":"2026-08-05T17:16:52.437","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20313 are related to Improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-1284.","score":7.7,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:52.437","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20312","published":"2026-08-05T17:16:52.093","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.","score":8.8,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:52.093","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20311","published":"2026-08-05T17:16:51.893","modified":"2026-08-06T15:44:56.043","description":"A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.","score":6.3,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-webui-dos-PtAODAWW","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:51.893","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20310","published":"2026-08-05T17:16:51.520","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59.","score":9.1,"severity":"CRITICAL","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:51.520","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20308","published":"2026-08-05T17:16:51.280","modified":"2026-08-06T15:44:56.043","description":"A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.\r\n\r\nThis vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.","score":4.3,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-dos-qdc7qx3","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:51.280","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20304","published":"2026-08-05T17:16:50.890","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.","score":9.9,"severity":"CRITICAL","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:50.890","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20303","published":"2026-08-05T17:16:50.513","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.","score":9.9,"severity":"CRITICAL","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:50.513","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20301","published":"2026-08-05T17:16:50.187","modified":"2026-08-06T15:44:56.043","description":"A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.","score":8.6,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xmcp-thbAr34t","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:50.187","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20294","published":"2026-08-05T17:16:49.877","modified":"2026-08-06T15:44:56.043","description":"A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.\r\n\r\nThis vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.","score":6.5,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-infodis-SPuJBDCe","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:49.877","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20289","published":"2026-08-05T17:16:49.733","modified":"2026-08-06T15:44:56.043","description":"A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information.\r\n\r\nThis vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials.","score":5.7,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-infodisc-qBXjfmWm","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:49.733","changedFields":["affected products","remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20288","published":"2026-08-05T17:16:49.527","modified":"2026-08-06T15:44:56.043","description":"A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nbsp;Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp;\r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp;\r\nCisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes&nbsp;root.","score":6.5,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:49.527","changedFields":["affected products","remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20273","published":"2026-08-05T17:16:49.290","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20273 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.","score":8.6,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:49.290","changedFields":["affected products","remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20272","published":"2026-08-05T17:16:49.053","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.","score":9.8,"severity":"CRITICAL","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:49.053","changedFields":["affected products","remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20271","published":"2026-08-05T17:16:48.810","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20271 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-691.\r\n&nbsp;","score":8.6,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:48.810","changedFields":["affected products","remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20270","published":"2026-08-05T17:16:48.340","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20270 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682.","score":8.6,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:48.340","changedFields":["affected products","remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20269","published":"2026-08-05T17:16:48.070","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.","score":8.6,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:48.070","changedFields":["affected products","remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20268","published":"2026-08-05T17:16:47.830","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.","score":8.6,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:47.830","changedFields":["affected products","remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20267","published":"2026-08-05T17:16:47.560","modified":"2026-08-06T15:44:56.043","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by&nbsp;CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar&nbsp;CWE-284.","score":9,"severity":"CRITICAL","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:47.560","changedFields":["affected products","remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20263","published":"2026-08-05T17:16:47.310","modified":"2026-08-06T15:44:56.043","description":"A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.","score":8.6,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:47.310","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20200","published":"2026-08-05T17:16:47.180","modified":"2026-08-06T15:44:56.043","description":"A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp;\r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.&nbsp;","score":8.8,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:47.180","changedFields":["affected products","remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20198","published":"2026-08-05T17:16:46.913","modified":"2026-08-06T15:44:56.043","description":"A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.\r\n\r\nThis vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.","score":4.8,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-7EhBFxBp","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:46.913","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20124","published":"2026-08-05T17:16:46.643","modified":"2026-08-06T15:44:56.043","description":"A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.\r\n\r\nThis vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP &mdash; Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.","score":7.7,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:46.643","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20028","published":"2026-08-05T17:16:46.427","modified":"2026-08-06T15:44:56.043","description":"A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker.\r\n\r\nThis vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.","score":5,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ts-agent-fw-bypass-MYBTMrev","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-08-05T17:16:46.427","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20316","published":"2026-07-29T17:16:51.840","modified":"2026-08-01T05:16:55.973","description":"A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.\r\n\r\nThis vulnerability is due to the presence of static user credentials for a low-privileged&nbsp;account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.&nbsp;\r\nNote:&nbsp;If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.&nbsp;&nbsp;\r\nCisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.","score":5.3,"severity":"MEDIUM","products":["cisco secure firewall management center"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh","label":"Vendor Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20316","label":"US Government Resource"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-29T17:16:51.840","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20187","published":"2026-07-15T17:16:47.770","modified":"2026-08-11T14:27:18.650","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20187 are related to improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.","score":7.5,"severity":"HIGH","products":["cisco roomos","cisco roomos cloud"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-15T17:16:47.770","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20158","published":"2026-07-15T17:16:47.640","modified":"2026-08-11T01:29:34.070","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20158 are related to improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.","score":7.5,"severity":"HIGH","products":["cisco roomos","cisco roomos cloud"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-15T17:16:47.640","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20157","published":"2026-07-15T17:16:47.507","modified":"2026-08-11T14:34:12.060","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20157 are related to missing encryption that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-311.","score":7.5,"severity":"HIGH","products":["cisco roomos","cisco roomos cloud"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-15T17:16:47.507","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20156","published":"2026-07-15T17:16:47.380","modified":"2026-08-11T14:37:37.570","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20156 are related to improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.","score":8.1,"severity":"HIGH","products":["cisco roomos","cisco roomos cloud"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-15T17:16:47.380","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20153","published":"2026-07-15T17:16:47.247","modified":"2026-08-11T14:43:00.033","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20153 are related to improper input validation that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.","score":7.5,"severity":"HIGH","products":["cisco roomos","cisco roomos cloud"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-15T17:16:47.247","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20150","published":"2026-07-15T17:16:47.110","modified":"2026-08-11T14:44:05.387","description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.\r\n\r\nThe vulnerabilities tracked by CVE-2026-20150 are related to improper access control&nbsp;that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.","score":8.8,"severity":"HIGH","products":["cisco roomos","cisco roomos cloud"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-15T17:16:47.110","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20146","published":"2026-07-15T17:16:46.970","modified":"2026-07-16T14:03:27.247","description":"A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.&nbsp;\r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.","score":5.5,"severity":"MEDIUM","products":["cisco identity services engine passive identity connector","cisco identity services engine passive identity connector 3.3.0","cisco identity services engine passive identity connector 3.4.0","cisco identity services engine passive identity connector 3.5.0","cisco identity services engine","cisco identity services engine 3.3.0","cisco identity services engine 3.4.0","cisco identity services engine 3.5.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-15T17:16:46.970","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-59838","published":"2026-07-15T14:18:33.057","modified":"2026-07-15T18:47:38.323","description":"A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>","score":5.9,"severity":"MEDIUM","products":["fortinet fortisiem","fortinet fortisiem 7.4.0"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-149","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-15T14:18:33.057","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-59841","published":"2026-07-14T16:17:03.520","modified":"2026-07-15T05:17:23.870","description":"A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>","score":7.5,"severity":"HIGH","products":["fortinet fortisiem"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-155","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-14T16:17:03.520","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-59840","published":"2026-07-14T16:17:03.297","modified":"2026-08-11T13:19:01.330","description":"A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to information disclosure via <insert attack vector here>","score":4.3,"severity":"MEDIUM","products":["fortinet fortiproxy","fortinet fortios"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-154","label":"Vendor Advisory"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-864900.html","label":"cert-portal.siemens.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-14T16:17:03.297","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-59839","published":"2026-07-14T16:17:03.047","modified":"2026-08-11T13:19:01.100","description":"A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4 through 7.4.13, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>","score":5.5,"severity":"MEDIUM","products":["fortinet fortiproxy","fortinet fortios","fortinet fortipam","fortinet fortipam 1.8.0"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-151","label":"Vendor Advisory"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-127084.html","label":"cert-portal.siemens.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-14T16:17:03.047","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-59837","published":"2026-07-14T16:17:02.853","modified":"2026-08-11T13:19:00.900","description":"A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via crafted HTTP requests.","score":6.6,"severity":"MEDIUM","products":["fortinet fortiproxy","fortinet fortios","fortinet fortipam"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-148","label":"Vendor Advisory"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-864900.html","label":"cert-portal.siemens.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-14T16:17:02.853","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-59836","published":"2026-07-14T16:17:02.727","modified":"2026-07-15T15:00:03.010","description":"A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>","score":7.5,"severity":"HIGH","products":["fortinet forticlientems"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-147","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-14T16:17:02.727","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-59835","published":"2026-07-14T16:17:02.593","modified":"2026-07-15T15:00:41.437","description":"A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.","score":8.6,"severity":"HIGH","products":["fortinet fortisandbox"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-145","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-14T16:17:02.593","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-23573","published":"2026-07-14T16:16:51.823","modified":"2026-08-11T13:17:59.330","description":"An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.4.0 through 7.4.3, FortiProxy 7.2.0 through 7.2.9 may allow an authenticated remote user to execute code or commands via crafted requests.","score":6.1,"severity":"MEDIUM","products":["fortinet fortiproxy","fortinet fortios","fortinet fortipam"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-150","label":"Vendor Advisory"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-127084.html","label":"cert-portal.siemens.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-14T16:16:51.823","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2025-62826","published":"2026-07-14T16:16:42.850","modified":"2026-08-11T13:17:46.880","description":"An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests.","score":3.1,"severity":"LOW","products":["fortinet fortiproxy","fortinet fortios"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-153","label":"Vendor Advisory"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-864900.html","label":"cert-portal.siemens.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-14T16:16:42.850","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2025-62675","published":"2026-07-14T16:16:42.617","modified":"2026-08-11T13:17:46.343","description":"An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link.","score":3.4,"severity":"LOW","products":["fortinet fortiproxy","fortinet fortios"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-152","label":"Vendor Advisory"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-864900.html","label":"cert-portal.siemens.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-14T16:16:42.617","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2025-53379","published":"2026-07-14T16:16:42.477","modified":"2026-07-15T18:30:56.310","description":"A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request.","score":7.5,"severity":"HIGH","products":["fortinet fortiauthenticator"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-146","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-14T16:16:42.477","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2025-43892","published":"2026-07-14T16:16:42.340","modified":"2026-08-11T13:17:31.930","description":"A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request.","score":4.3,"severity":"MEDIUM","products":["fortinet fortiproxy","fortinet fortios"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/#5944","label":"Vendor Advisory"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-864900.html","label":"cert-portal.siemens.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-14T16:16:42.340","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-57054","published":"2026-07-09T22:17:09.180","modified":"2026-07-13T20:03:52.347","description":"A Use of Incorrectly-Resolved Name or Reference vulnerability in the URL filtering plugin of Juniper Networks Junos OS on MX Series allows an unauthenticated, network-based attacker to bypass web filtering and access downstream resources that should be unreachable.\n\n\n\nIf an MX Series device is configured with web filtering, and an attacker sends a request with a specifically formatted URL, this request will get forwarded despite the system being configured to block it. In turn, an attacker can access downstream resources that are expected to be unreachable.\n\nThis issue affects Junos OS on MX Series:\n\n\n  *  all versions before 23.2R2-S7,\n  *  23.4 versions before 23.4R2-S8,\n  *  24.2 versions before 24.2R2-S5,\n  *  24.4 versions before 24.4R2-S4,\n  *  25.2 versions before 25.2R2-S1,\n  *  25.4 versions before 25.4R1-S2, 25.4R2.","score":6.9,"severity":"MEDIUM","products":["juniper junos","juniper junos 23.2","juniper junos 23.4","juniper junos 24.2","juniper junos 24.4","juniper junos 25.2","juniper junos 25.4"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110093","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:09.180","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57032","published":"2026-07-09T22:17:09.007","modified":"2026-07-13T20:07:12.477","description":"An Improper Handling of Undefined Parameters vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on EX Series devices allows an authenticated attacker with low privileges to cause a Denial-of-Service (DoS).\n\nIf an attempt is made to subscribe to an unsupported telemetry sensor path on EX2300, EX3400, EX4000, EX4100 and EX4400 via gRPC, this causes the FPC to crash. This leads to a complete service outage until the module has automatically restarted. \n\nThe following log message can be seen when this issue happens:\n\nagentd[<PID>]: AGENTD_RESOURCE_NOT_FOUND: No resource name found for <sensor>\n\n\nThis issue affects Junos OS on \n\nEX2300, EX3400, EX4000, EX4100 and EX4400\n\ndevices:\n\n\n  *  all versions before 23.2R2-S7,\n  *  23.4 versions before 23.4R2-S8,\n  *  24.2 versions before  24.2R2-S5,\n  *  24.4 versions before 24.4R2.","score":7.1,"severity":"HIGH","products":["juniper junos","juniper junos 23.2","juniper junos 23.4","juniper junos 24.2","juniper junos 24.4"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110092","label":"Mitigation"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:09.007","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57031","published":"2026-07-09T22:17:08.827","modified":"2026-07-10T17:49:57.737","description":"An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on MX Series allows adjacent subscribers to bypass configured firewall filters.\n\nOn MX Series devices with MPC10/11, LC4800/9600, and MX304 with subscribers configured on static interfaces, ingress firewall filters are not enforced, so that neither protocol level nor upstream bandwidth limitation are in effect. \n\n\nThis issue affects Junos OS on MX with MPC10/11, LC4800/9600/4802, and MX304:\n\n\n  *  23.2 versions from 23.2R2-S1 before 23.2R2-S7,\n  *  23.4 versions from 23.4R2 before 23.4R2-S7,\n  *  24.2 versions before 24.2R2-S3,\n  *  24.4 versions before 24.4R2-S2,\n  *  25.2 versions before 25.2R2.","score":5.3,"severity":"MEDIUM","products":[],"vendors":[],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110091","label":"supportportal.juniper.net"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:08.827","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57030","published":"2026-07-09T22:17:08.643","modified":"2026-07-13T20:16:07.750","description":"A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).\n\nAs part of the stateful traffic processing on SRX Series devices flows are being established, and removed when not needed anymore. During the removal process the timeout of a flow should be set to 3 seconds and consequentially the flow should be removed shortly after. Due to a race condition occurring when setting the timeout there is a chance (the exact conditions are outside the attackers control) that the timeout is instead set to a very high value of larger than 10,000 seconds:\n\n\n\nuser@host> show security flow session | match timeout\nSession ID: 98784248524, Policy name: PROD-FLOW/4, HA State: Active, Timeout: 85250, Session State: Valid\n\nThis will lead to an accumulation of flows which can be observed by an ever-increasing value of invalidated sessions in the output of 'show security flow session summary':\n\nuser@host> show security flow session summary | match invalid\nInvalidated sessions: 216931These sessions can't be cleared manually with the 'clear security flow session' command, which will either lead to forwarding to stop (and the system needs to be manually recovered with a reboot) or to a flowd core and automatic reboot.\n\n\nThis issue affects Junos OS on SRX Series:\n\n\n  *  24.2 versions before 24.2R2-S3,\n  *  24.4 versions before 24.4R2-S1, 24.4R2-S2,\n  *  25.2 versions before 25.2R1-S2, 25.2R2.\n\n\n\n\nThis issue does not affect releases earlier than 24.2R1;","score":8.2,"severity":"HIGH","products":["juniper junos 24.2","juniper junos 24.4","juniper junos 25.2"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110090","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:08.643","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57029","published":"2026-07-09T22:17:08.453","modified":"2026-07-13T20:23:46.113","description":"A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS).\n\n\nWhen the reachability of an sFlow collector changes, the corresponding next-hop entry is updated. If this update occurs simultaneously with the sFlow thread accessing the next-hop data (which is outside the attackers control), it causes the evo-pfemand process to crash, impacting all traffic forwarding until the automatic process restart has completed.\n\n\n\n\nThis issue affects Junos OS Evolved on QFX Series:\n\n\n  *  all 23.2 versions, \n  *  23.4 versions before 23.4R2-S7-EVO,\n  *  24.2 versions before 24.2R2-S5-EVO,\n  *  24.4 versions before 24.4R2-S3-EVO,\n  *  25.2 versions before 25.2R2-EVO.","score":6,"severity":"MEDIUM","products":["juniper junos os evolved 23.2","juniper junos os evolved 23.4","juniper junos os evolved 24.2","juniper junos os evolved 24.4","juniper junos os evolved 25.2"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110089","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:08.453","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57028","published":"2026-07-09T22:17:08.257","modified":"2026-07-13T20:24:50.030","description":"An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause license exhaustion.\n\n\nDue to an incorrect initialization, a process which should only be able to communicate internally within the device, can be reached over the network via an open port. This leads to unauthorized access to the license management.\n\nThis issue affects all Junos OS Evolved versions before 23.2R2-EVO.","score":6.9,"severity":"MEDIUM","products":["juniper junos os evolved","juniper junos os evolved 23.2"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110088","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:08.257","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57027","published":"2026-07-09T22:17:08.093","modified":"2026-07-13T20:26:30.937","description":"A Missing Release of Memory after Effective Lifetime vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on specific EX Series devices allows an unauthenticated adjacent attacker to cause a Denial-of-Service (DoS).When sFlow is configured in a Virtual Chassis (VC) scenario with EX4100 Series or EX4400 Series devices, multicast traffic which is received on one VC member and sent out on another member leads to a memory leak and ultimately an FPC crash and restart.\n\nThe leak can be monitored by watching the continuous increase of the buffer values in the output of:\n\nuser@host> show chassis fpc \nThis issue affects Junos OS on EX4100 Series and EX4400:\n\n\n  *  all versions before 23.2R2-S7,\n  *  23.4 versions before 23.4R2-S7,\n  *  24.2 versions before 24.2R2-S4,\n  *  24.4 versions before 24.4R2.","score":7.1,"severity":"HIGH","products":["juniper junos","juniper junos 23.2","juniper junos 23.4","juniper junos 24.2","juniper junos 24.4"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110087","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:08.093","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57026","published":"2026-07-09T22:17:07.923","modified":"2026-07-14T15:03:23.637","description":"An Improper Validation of Syntactic Correctness of Input vulnerability in the SIP plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).If the SIP ALG is enabled on an affected device, the processing of a malformed SIP invite packet will cause a flow processing daemon (flowd) crash and restart. This leads to a complete service outage until the system has automatically recovered.\n\n\n\nThis issue affects Junos OS on MX Series with SPC3 and SRX Series:\n\n\n  *  all versions before 23.2R2-S7,\n  *  23.4 versions before 23.4R2-S8,\n  *  24.2 versions before 24.2R2-S5,\n  *  24.4 versions before 24.4R2-S4,\n  *  25.2 versions before 25.2R2,\n  *  25.4 versions before 25.4R1-S2.","score":8.7,"severity":"HIGH","products":["juniper junos","juniper junos 23.2","juniper junos 23.4","juniper junos 24.2","juniper junos 24.4","juniper junos 25.2","juniper junos 25.4"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110086","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:07.923","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57025","published":"2026-07-09T22:17:07.747","modified":"2026-07-16T09:16:18.650","description":"A Return of Pointer Value Outside of Expected Range vulnerability in the fileio library of Juniper Networks Junos OS and Junos OS Evolved allows a local, low-privilged attacker to cause a Denial-of-Service (DoS).\n\nOn EX Series, QFX Series and MX Series a low-privileged attacker issuing a specific 'show l2-learning' or 'show ethernet-switching' command will cause an l2ald crash which will lead to a temporary service impact for all layer 2 services until the process has automatically restarted.\n\nThis issue affects EX Series, QFX Series, MX Series:\nJunos OS:\n\n\n  *  all versions before 23.2R2-S7,\n  *  23.4 versions before 23.4R2-S7,\n  *  24.2 versions before 24.2R2,\n  *  24.4 versions before 24.4R1-S2.\n\n\n\nJunos OS Evolved:\n  *  all versions before 23.2R2-S7-EVO,\n  *  23.4 versions before 23.4R2-S8-EVO,\n  *  24.2 versions before 24.2R2-EVO,\n  *  24.4 versions before 24.4R1-S3-EVO.","score":6.8,"severity":"MEDIUM","products":["juniper junos","juniper junos 23.2","juniper junos 23.4","juniper junos 24.2","juniper junos 24.4","juniper junos os evolved","juniper junos os evolved 23.2","juniper junos os evolved 23.4"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110085","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:07.747","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57024","published":"2026-07-09T22:17:07.553","modified":"2026-07-14T15:16:42.397","description":"A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).\n\n\n\nOn an MX with SPC3 and SRX devices configured for VPN service, when a large number of VPN negotiations fail a peer index rollover will eventually occur. As a result, new peers are assigned index values that are already in use and the iked process starts to crash repeatedly. This results in failure to establish new VPN connections and rekeying existing ones. To restore service the system must be rebooted.\nPlease note that the index value can't be monitored, so customers should monitor tunnel up and down events and if a lot of events occur over an extended period of time it becomes likely that this issue occurs.\n\nTo be exposed to this issue the system needs to run iked (vs. kmd which is not affected), which can be verified with:\n\nuser@host> show system processes extensive | match \"KMD|IKED\"\nThis issue affects Junos OS on MX with SPC3, SRX Series:\n\n\n  *  all versions before 23.2R2-S7,\n  *  23.4 versions before 23.4R2-S6,\n  *  24.2 versions before 24.2R2-S3,\n  *  24.4 versions before 24.4R2-S4,\n  *  25.2 versions before 25.2R1-S1.","score":6.9,"severity":"MEDIUM","products":["juniper junos","juniper junos 23.2","juniper junos 23.4","juniper junos 24.2","juniper junos 24.4","juniper junos 25.2"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110084","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:07.553","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57023","published":"2026-07-09T22:17:07.397","modified":"2026-07-14T15:19:42.860","description":"An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS).\n\nWhen TCP proxy is engaged in a flow session, to support ALGs, Advanced Anti-Malware, ICAP or UTM, a TCP packet with specifically malformed TCP header will cause flow processing daemon (flowd) to crash and restart. This causes a complete service outage until the system has automatically recovered.\n\n\n\nThis issue affects Junos OS on MX with SPC3, and SRX Series: \n\n\n\n  *  23.4 versions before 23.4R2-S7, \n  *  24.2 versions before 24.2R2-S4, \n  *  24.4 versions before 24.4R2-S3,\n  *  25.2 versions before 25.2R2.\n\n\n\n\nThis issue does not affect releases before 23.4R1.","score":8.7,"severity":"HIGH","products":["juniper junos 23.4","juniper junos 24.2","juniper junos 24.4","juniper junos 25.2"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110083","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:07.397","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57022","published":"2026-07-09T22:17:07.233","modified":"2026-07-14T16:54:04.857","description":"An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).\n\nWhen an affected device initiates a TCP connection to an attacker-controlled system that responds with a specific packet, this causes a PFE crash and restart, which affects all services until the system has automatically recovered.\nThis issue can happen among others in the following scenarios: ALG, SSL proxy, UTM, RTLOG, AppQoE probing, AAMW, ICAP, URL filtering.\n\nThis issue affects Junos OS on MX Series with SPC3, SRX5k Series with SPC3, SRX1600 Series, SRX2300 Series, SRX4000 Series, and vSRX Series:\n\n  *  all versions before 23.2R2-S4,\n  *  23.4 versions before 23.4R2-S5,\n  *  24.2 versions before 24.2R2.","score":8.2,"severity":"HIGH","products":["juniper junos","juniper junos 23.2","juniper junos 23.4","juniper junos 24.2"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110082","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:07.233","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57021","published":"2026-07-09T22:17:07.057","modified":"2026-07-13T20:33:08.187","description":"An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).\n\nIf an SRX Series device is configured for remote-access VPN with pre-logon compliance check, a network-based attacker sending specifically formatted requests can trigger an out of bounds write leading to an http-gk process crash. This crash leads to unavailability of all services depending on the [ system services web-management ] configuration (like J-Web, remote access VPN and firewall authentication) until the process automatically restarts.\n\nThis issue affects Junos OS on SRX Series:\n\n\n  *  23.2 versions before 23.2R2-S7,\n  *  23.4 versions before 23.4R2-S8,\n  *  24.2 versions before 24.2R2-S4,\n  *  24.4 versions before 24.4R2-S4,\n  *  25.2 versions before 25.2R2,\n  *  25.4 versions before 25.4R1-S1, 25.4R2.","score":6.9,"severity":"MEDIUM","products":["juniper junos 23.2","juniper junos 23.4","juniper junos 24.2","juniper junos 24.4","juniper junos 25.2","juniper junos 25.4"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110081","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:07.057","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57020","published":"2026-07-09T22:17:06.887","modified":"2026-07-13T20:57:06.157","description":"An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on QFX10000 Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).\n\nOn all QFX10000 platforms in an EVPN-VxLAN scenario, if an attacker sends IPv6 multicast traffic and these packets reach the non-IRB interface of a spine switch it floods the packet to other spines and all Ethernet Segment Identifier (ESI) leaf switches. This flooding causes the packet to be forwarded in a endless loop, which can lead to saturation of the involved links and in turn impact to legitimate traffic.\n\n\n\nThis issue affects Junos OS on QFX10000 Series:\n\n\n  *  all versions before 23.2R2-S7,\n  *  23.4 versions before 23.4R2-S8,\n  *  24.2 versions before 24.2R2-S4,\n  *  24.4 versions before 24.4R2-S4.\n\n\n\nThis issue does not affect Junos version after 24.4 as the QFX10000 Series devices are not supported on newer versions anymore.","score":7.1,"severity":"HIGH","products":["juniper junos","juniper junos 23.2","juniper junos 23.4","juniper junos 24.2","juniper junos 24.4"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110080","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:06.887","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-57019","published":"2026-07-09T22:17:06.707","modified":"2026-07-13T20:58:26.287","description":"An Improper Validation of Specified Quantity in Input vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).\n\n\nWhen a specific packet is received from device in the same broadcast domain, an affected system calculates the packet size incorrectly. This causes further packet processing to fail, which triggers an FPC major error, resulting in a FPC reset impacting traffic until the FPC has automatically recovered.\n\nAffected scenarios are: MAP-T, or non-IP traffic encapsulated in IP (e.g. MPLS over GRE).\n\nWhen this issue happens the following logs can be observed:\n\nfpc<#> CMError: /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb), scope: pfe, category: functional, severity: major, module: MQSS(0), type: LI: Unroll TAIL length overflow, oc_category: default\nfpc<#> Performing action reset-fru for error /fpc/0/pfe/0/cm/0/MQSS(0)/0/MQSS_CMERROR_LI_INT_REG_UNROLL_TAIL_LENGTH_OVF (0x2205eb) in module: MQSS(0) with scope: pfe category: functional level: major, oc_category: default\n\n\n\n\nThis issue affects Junos OS on MX Series:\n\n\n  *  all versions before 23.2R2-S6,\n  *  23.4 versions before 23.4R2-S7,\n  *  24.2 versions before 24.2R2-S4,\n  *  24.4 versions before 24.4R2-S4,\n  *  25.2 versions before 25.2R2.","score":7.1,"severity":"HIGH","products":["juniper junos","juniper junos 23.2","juniper junos 23.4","juniper junos 24.2","juniper junos 24.4","juniper junos 25.2"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110079","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:06.707","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-33803","published":"2026-07-09T22:17:03.807","modified":"2026-07-13T20:59:26.603","description":"An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device.\n\n\nDue to a wrong initialization, a process which should only be able to communicate internally within the device can be reached over the network via an open port. This leads to a device being inadvertently exposed and increased CPU cycles spent processing ingress packets.\n\nThis issue affects Junos OS Evolved:\n\n\n  *  all versions before 23.2R2-S7-EVO,\n  *  23.4 versions before 23.4R2-S8-EVO,\n  *  24.2 versions before 24.2R2-S5-EVO,\n  *  24.4 versions before 24.4R2-S4-EVO,\n  *  25.2 versions before 25.2R2-S1-EVO,\n  *  25.4 versions before 25.4R1-S2-EVO.","score":6.9,"severity":"MEDIUM","products":["juniper junos os evolved","juniper junos os evolved 23.2","juniper junos os evolved 23.4","juniper junos os evolved 24.2","juniper junos os evolved 24.4","juniper junos os evolved 25.2","juniper junos os evolved 25.4"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110078","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:03.807","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-33802","published":"2026-07-09T22:17:03.633","modified":"2026-07-14T16:59:28.487","description":"A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-of-Service (DoS).\n\n\n\nOn EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400 switches, an authenticated, local attacker with no specific permissions or class can execute a specific, privileged CLI 'request' command which will cause complete traffic impact until the system automatically recovers.\n\nThis issue affects Junos OS on EX2300, EX4000, EX4100, EX4300-MP (Multigigabit) and EX4400:\n\n\n  *  23.2R2 versions before 23.2R2-S6,\n  *  23.4 versions before 23.4R2-S8,\n  *  24.2 versions before 24.2R2-S4,\n  *  24.4 versions before 24.4R2-S3,\n  *  25.2 versions before 25.2R2,\n  *  25.4 versions before 25.4R1-S1.","score":6.8,"severity":"MEDIUM","products":["juniper junos 23.2","juniper junos 23.4","juniper junos 24.2","juniper junos 24.4","juniper junos 25.2","juniper junos 25.4"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110077","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T22:17:03.633","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-33801","published":"2026-07-09T21:16:55.330","modified":"2026-07-13T20:36:12.860","description":"An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated attacker sending a specific BGP update over an established BGP session to cause a Denial-of-Service (DoS).\n\nUpon receipt of a specifically malformed non-inet/inet6 unicast BGP update, an RPD crash and restart is triggered, which will cause a complete service outage until routing has reconverged. The rpd crash occurs before the update can be readvertised, so there is no downstream propagation.\n\n\nThis issue affects:\n\n\n\n  *  Junos OS versions 25.2 before 25.2R2;\n\n\n  *  Junos OS Evolved versions 25.2 before 25.2R2-EVO.\n\n\n\n\nThis issue doesn't affect Junos OS versions before 25.2R1 nor Junos OS Evolved versions before 25.2R1-EVO.","score":7.1,"severity":"HIGH","products":["juniper junos 25.2","juniper junos os evolved 25.2"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110076","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T21:16:55.330","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-33800","published":"2026-07-09T21:16:55.163","modified":"2026-07-20T14:16:55.823","description":"An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series allows an unauthenticated, adjacent attacker to cause a Denial-of-Service (DoS).Micro-BFD session flaps generate respective up/down events which are queued by PFEMAN for processing. Especially in a Virtual-Chassis (VC) scenario with locality‑bias configured, processing takes a significant amount of time for each event. If these sessions keep flapping, new events are constantly added, and in turn PFEMAN never completes processing these events. This results in the PFEMAN watchdog timer expiring, which causes the FPC to crash and restart, representing a complete service outage.\n\n\nThis issue only affects MX series FPCs up to and including MPC9, and LC2101/2103 and LC480. It does not affect MPC10/11, LC4800/9600, and MX304.\n\nThis issue affects Junos OS on MX Series:\n\n\n  *  all versions before 23.2R2-S7,\n  *  23.4 versions before 23.4R2-S8,\n  *  24.2 versions before 24.2R2-S4,\n  *  24.4 versions before 24.4R2-S3,\n  *  25.2 versions before 25.2R2.","score":7.1,"severity":"HIGH","products":[],"vendors":[],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110075","label":"supportportal.juniper.net"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T21:16:55.163","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-33799","published":"2026-07-09T21:16:54.963","modified":"2026-07-13T12:55:46.097","description":"An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated network-based attacker sending specific valid SNMPv3 queries to trigger a memory leak. Over time, continuous receipt of these queries will result in snmpd process memory exhaustion, resulting in a process crash and restart, impacting the ability to monitor the system via SNMP.\n\nMemory usage can be monitored using the following command:\n\nuser@device> show system processes extensive | match snmpd\n\n\n\n\nThis issue affects:\n\nJunos OS:\n\n\n  *  all versions before 21.2R3-S8;\n  *  from 21.4 before 21.4R3-S7;\n  *  from 22.1 before 22.1R3-S6;\n  *  from 22.2 before 22.2R3-S4;\n  *  from 22.3 before 22.3R3-S3;\n  *  from 22.4 before 22.4R3-S2;\n  *  from 23.2 before 23.2R2;\n  *  from 23.4 before 23.4R2.\n\n\n\nJunos OS Evolved:\n  *  all versions before 21.2R3-S8-EVO;\n  *  from 21.4 before 21.4R3-S7-EVO;\n  *  all versions of 22.1-EVO,\n  *  from 22.2 before 22.2R3-S4-EVO;\n  *  from 22.3 before 22.3R3-S3-EVO;\n  *  all versions of 22.4-EVO,\n  *  from 23.2 before 23.2R2-EVO;\n  *  from 23.4 before 23.4R2-EVO.","score":5.3,"severity":"MEDIUM","products":["juniper junos","juniper junos 21.2","juniper junos 21.4","juniper junos 22.1","juniper junos 22.2","juniper junos 22.3","juniper junos 22.4","juniper junos 23.2"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110074","label":"Mitigation"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T21:16:54.963","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-33794","published":"2026-07-09T21:16:54.790","modified":"2026-07-13T12:57:12.750","description":"An Improper Check for Unusual or Exceptional Conditions vulnerability in the \n\nadvanced forwarding toolkit (evo-aftmand)\n\n of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated network-based attacker generating continuous routing updates, resulting in unilist ECMP routes, to crash the \n\nevo-aftmand process on the PFE, leading to a Denial-of-Service (DoS). The conditions required for successful exploitation are based on a sequence of events that are outside an attacker's direct control.\n\nUnified list (unilist) ECMP routes are a specific ECMP behavior where multiple equal-cost routes share a single logical next-hop list entry. The router treats them as one route with multiple next hops and load balances traffic across that unified list. Due to an issue processing unilist ECMP routing updates, internal state corruption may occur, especially in large-scale ECMP unilist deployments, leading to the evo-aftmand process crashing, resulting in an evo-aftmand-bx core. Manual intervention is required to recover by rebooting the system or restarting the FPC.\n\nThis issue affects Junos OS Evolved on PTX :\n\n\n  *  from 24.4R2-EVO before 24.4R2-S3-EVO;\n  *  from 25.2 before 25.2R2-EVO.","score":8.2,"severity":"HIGH","products":["juniper junos os evolved 24.4","juniper junos os evolved 25.2"],"vendors":["Juniper"],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://supportportal.juniper.net/JSA110073","label":"Mitigation"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T21:16:54.790","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-21901","published":"2026-07-09T21:16:54.467","modified":"2026-07-10T17:49:57.737","description":"A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolved allows a local, high-privileged attacker setting or deactivating a specific SSH configuration parameter to create a Denial of Service (DoS).\n\nA local high-privileged user configuring or deactivating a specific 'system services ssh' configuration parameter can exploit a null pointer dereference in one of the functions used by SSH. The function attempts to dereference a null pointer when accessing certain configuration data, resulting in an mgd process crash and restart. Continued execution of these configuration commands will create a sustained Denial of Service (DoS) condition.\n\nThis issue affects:\nJunos OS:\n\n\n  *  from 22.3 before 22.3R3-S5;\n  *  from 22.4 before 22.4R3-S10;\n  *  from 23.2 before 23.2R2-S7;\n  *  from 23.4 before 23.4R2-S8.\n\n\n\n\nThis issue does not affect Junos OS before 22.3R1.\n\n\n\nJunos OS Evolved:\n  *  from 22.3R1-EVO before 23.2R2-S7-EVO;\n  *  from 23.4 before 23.4R2-S8-EVO.\n\n\nThis issue does not affect Junos OS Evolved before 22.3R1-EVO.","score":6.7,"severity":"MEDIUM","products":[],"vendors":[],"windowsVersions":[],"primaryVendor":"Juniper Networks","vendorCategory":"Networking & Security","references":[{"url":"https://github.com/orangecertcc/security-research/security/advisories/GHSA-g4f7-w2rc-hpj6","label":"github.com"},{"url":"https://supportportal.juniper.net/JSA110072","label":"supportportal.juniper.net"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-09T21:16:54.467","changedFields":["remediation"],"lastChangedAt":"2026-08-24T16:30:47.792Z"},{"id":"CVE-2026-24700","published":"2026-07-08T15:16:27.047","modified":"2026-07-10T17:49:52.123","description":"An OS command injection vulnerability exists in the start_lltd() function of the \"rc\" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.","score":7.2,"severity":"HIGH","products":["cisco rv130 firmware 1.0.3.55","cisco rv130w firmware 1.0.3.55","cisco rv110w firmware 1.2.2.5","cisco rv110w firmware 1.2.2.8"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://github.com/glkfc/IoT-Vulnerability/blob/main/cisco/RV130/1/wp-en.md","label":"Exploit"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-08T15:16:27.047","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-24699","published":"2026-07-08T15:16:26.943","modified":"2026-07-10T17:50:43.990","description":"An OS command injection vulnerability exists in the sub_34984() function of the \"rc\" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.","score":7.2,"severity":"HIGH","products":["cisco rv130 firmware 1.0.3.55","cisco rv130w firmware 1.0.3.55","cisco rv110w firmware 1.2.2.5","cisco rv110w firmware 1.2.2.8"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://github.com/glkfc/IoT-Vulnerability/blob/main/cisco/RV130/4/wp-en.md","label":"Third Party Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-08T15:16:26.943","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-24698","published":"2026-07-08T15:16:26.827","modified":"2026-07-10T17:51:09.083","description":"An OS command injection vulnerability exists in the save_syslog_to_file() function of the \"httpd\" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.","score":7.2,"severity":"HIGH","products":["cisco rv130 firmware 1.0.3.55","cisco rv130w firmware 1.0.3.55","cisco rv110w firmware 1.2.2.5","cisco rv110w firmware 1.2.2.8"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://github.com/glkfc/IoT-Vulnerability/blob/main/cisco/RV130/3/wp-en.md","label":"Third Party Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-08T15:16:26.827","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-24697","published":"2026-07-08T15:16:26.697","modified":"2026-07-10T17:54:30.890","description":"An OS command injection vulnerability exists in the start_bonjour() function of the \"rc\" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.","score":7.2,"severity":"HIGH","products":["cisco rv130 firmware 1.0.3.55","cisco rv130w firmware 1.0.3.55","cisco rv110w firmware 1.2.2.5","cisco rv110w firmware 1.2.2.8"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://github.com/glkfc/IoT-Vulnerability/blob/main/cisco/RV130/2/wp-en.md","label":"Third Party Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-08T15:16:26.697","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20191","published":"2026-07-01T17:16:29.330","modified":"2026-07-01T18:16:30.850","description":"A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.&nbsp;\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.","score":7.5,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-catc-file-read-wLH2vf8X","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-07-01T17:16:29.330","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20178","published":"2026-06-17T18:17:35.587","modified":"2026-06-22T14:17:11.023","description":"A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed.\r\n\r This vulnerability existed due to improper input validation of URL parameters in an HTTP request. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to click a crafted URL. A successful exploit could have allowed the attacker to redirect a user to a malicious website.","score":4.3,"severity":"MEDIUM","products":["cisco webex web app"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-app-redirect-KOyxhffH","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-17T18:17:35.587","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20246","published":"2026-06-17T17:16:43.423","modified":"2026-06-22T13:24:17.140","description":"A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using certain commands at the CLI. A successful exploit could allow the attacker to elevate privileges to root.","score":6,"severity":"MEDIUM","products":["cisco umbrella virtual appliance"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-umbrella-priv-esc-F4wJB7AU","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-17T17:16:43.423","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20220","published":"2026-06-17T17:16:43.253","modified":"2026-06-22T14:16:26.503","description":"A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an&nbsp;authenticated, remote attacker to execute arbitrary commands on an affected device.\r\n\r\nThis vulnerability is due to insufficient input validation in the configuration&nbsp;template engine of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system in limited areas of the file system. This vulnerability affects only areas of the operating system for which the template user has write permissions.&nbsp;\r\nTo exploit this vulnerability, the attacker must have valid template user credentials with write permissions. Template users with read permissions cannot exploit this vulnerability.&nbsp;","score":6.3,"severity":"MEDIUM","products":["cisco crosswork network controller","cisco crosswork network controller 7.2.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cnc-inj-QNMeEmxk","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-17T17:16:43.253","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20190","published":"2026-06-17T17:16:43.130","modified":"2026-06-22T14:30:44.327","description":"A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device.\r\n\r\nThis vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.","score":7.5,"severity":"HIGH","products":["cisco identity services engine 3.4.0","cisco identity services engine 3.5.0","cisco identity services engine passive identity connector 3.4.0","cisco identity services engine passive identity connector 3.5.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-17T17:16:43.130","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20181","published":"2026-06-17T17:16:42.990","modified":"2026-06-22T14:31:46.277","description":"A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.","score":9.1,"severity":"CRITICAL","products":["cisco identity services engine","cisco identity services engine 3.3.0","cisco identity services engine 3.4.0","cisco identity services engine 3.5.0","cisco identity services engine passive identity connector","cisco identity services engine passive identity connector 3.3.0","cisco identity services engine passive identity connector 3.4.0","cisco identity services engine passive identity connector 3.5.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-G5WP8vv","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-17T17:16:42.990","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20262","published":"2026-06-15T18:16:34.820","modified":"2026-07-24T19:10:00.160","description":"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.\r\n\r\nThis vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account.","score":6.5,"severity":"MEDIUM","products":["cisco catalyst sd-wan manager"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-arbfw-c2rZvQ","label":"Vendor Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20262","label":"US Government Resource"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-15T18:16:34.820","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-49938","published":"2026-06-09T16:16:43.323","modified":"2026-07-23T08:10:00.137","description":"A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here>","score":6.5,"severity":"MEDIUM","products":["fortinet fortiportal"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-140","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-09T16:16:43.323","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-25089","published":"2026-06-09T16:16:39.943","modified":"2026-07-23T08:10:00.137","description":"A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests","score":9.8,"severity":"CRITICAL","products":["fortinet fortisandbox","fortinet fortisandbox cloud","fortinet fortisandbox paas"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-141","label":"Vendor Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-25089","label":"US Government Resource"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-09T16:16:39.943","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2025-67862","published":"2026-06-09T16:16:35.500","modified":"2026-07-23T08:10:00.137","description":"An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0 all versions may allow an authenticated admin to execute lua scripts via crafted CLI commands.","score":6.7,"severity":"MEDIUM","products":["fortinet fortios","fortinet fortiproxy"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-143","label":"Vendor Advisory"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-864900.html","label":"cert-portal.siemens.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-09T16:16:35.500","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-20245","published":"2026-06-04T23:17:31.763","modified":"2026-07-23T07:10:00.113","description":"A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to perform command injection attacks on an affected system and elevate their privileges as the root user.\r\nTo exploit this vulnerability, the attacker must have netadmin privileges on the affected system. This would require valid credentials or exploitation of  or . Cisco is not aware of successful exploitation by other methods. Cisco has observed limited cases where the exploitation of this bug resulted in a configuration change pushed to edge devices.\r\nCisco recommends that customers upgrade to the fixed software that is documented in the  that was published on May 14, 2026, and verify the configuration of the edge devices.","score":7.8,"severity":"HIGH","products":["cisco catalyst sd-wan manager","cisco catalyst sd-wan manager 20.12.7","cisco sd-wan vsmart controller","cisco sd-wan vsmart controller 20.12.7"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx","label":"Vendor Advisory"},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW","label":"Vendor Advisory"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20245","label":"US Government Resource"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-04T23:17:31.763","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20233","published":"2026-06-03T18:16:20.320","modified":"2026-07-22T19:10:00.120","description":"A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings service, and no customer action is needed.\r\n\r\nThis vulnerability existed because of insufficient validation of user input. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to follow a malicious link. A successful exploit could have allowed the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.","score":6.1,"severity":"MEDIUM","products":["cisco webex meetings 39.6.0","cisco webex meetings 39.7.0","cisco webex meetings 39.7.4","cisco webex meetings 39.7.7","cisco webex meetings 39.8.0","cisco webex meetings 39.8.2","cisco webex meetings 39.8.3","cisco webex meetings 39.8.4"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-xss-jw3NeQzS","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-03T18:16:20.320","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20230","published":"2026-06-03T18:16:20.160","modified":"2026-07-22T19:10:00.120","description":"A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.\r\n\r\nThis vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to write files to the underlying operating system that could be used later to elevate to root.\r\nNote: Cisco has assigned this security advisory a Security Impact Rating (SIR) of Critical rather than High as the score indicates. The reason is that exploitation of this vulnerability could result in an attacker elevating privileges to root.\r\nNote: To exploit this vulnerability, the WebDialer service must be enabled. WebDialer is disabled by default.","score":8.6,"severity":"HIGH","products":["cisco unified communications manager"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssrf-cXPnHcW","label":"Vendor Advisory"},{"url":"https://denizhalil.com/2026/06/12/cve-2026-20230-cisco-unified-cm-ssrf/","label":"Exploit"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20230","label":"US Government Resource"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-03T18:16:20.160","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20175","published":"2026-06-03T18:16:19.960","modified":"2026-07-22T19:10:00.120","description":"A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link that contains the affected device address. A successful exploit could allow the attacker to conduct browser-based attacks and execute arbitrary script code in the context of the affected interface or access sensitive information on the affected device.","score":6.1,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-rfi-gwpkdc89","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-06-03T18:16:19.960","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20223","published":"2026-05-20T17:16:20.400","modified":"2026-07-23T12:10:00.110","description":"A vulnerability in the&nbsp;access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the&nbsp;Site Admin role.\r\n\r\nThis vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the&nbsp;Site Admin user.&nbsp;","score":10,"severity":"CRITICAL","products":["cisco secure workload"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-20T17:16:20.400","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20206","published":"2026-05-20T17:16:20.243","modified":"2026-07-23T12:10:00.110","description":"A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEyes Enterprise Agent, and no customer action is needed.\r\n\r\nThis vulnerability was due to insufficient input validation of command arguments that are supplied by the user. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by authenticating to the ThousandEyes SaaS and submitting crafted input into the affected parameter. A successful exploit could have allowed the attacker to execute arbitrary commands within the BrowserBot container as the node user.\r\nTo exploit this vulnerability, the attacker must have valid user credentials for the ThousandEyes SaaS and the ability to manage transaction tests.","score":6.3,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tebbot-cmdinj-wN3yQ5gn","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-20T17:16:20.243","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20199","published":"2026-05-20T17:16:20.100","modified":"2026-07-23T12:10:00.110","description":"A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user.\r\n\r This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.","score":4.7,"severity":"MEDIUM","products":["cisco thousandeyes virtual appliance"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tevacert-rce-RMJVEym5","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-20T17:16:20.100","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20171","published":"2026-05-20T17:16:19.813","modified":"2026-07-23T12:10:00.110","description":"A vulnerability in the Border Gateway Protocol (BGP)&nbsp;enforce-first-as feature of&nbsp;Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition.\r\n\r\nThis vulnerability is due to incorrect parsing of a transitive BGP attribute. An attacker could exploit this vulnerability by sending a crafted BGP update through an established BGP peer session. If the update propagates to an affected device, it could cause the device to drop the BGP session and flap with the BGP peer that is forwarding this update, resulting in a DoS condition.","score":6.8,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bgp-iefab-3hb2pwtx","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-20T17:16:19.813","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20224","published":"2026-05-14T17:16:20.353","modified":"2026-06-29T14:51:28.800","description":"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials.\r\n\r\nThis vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to read arbitrary files that are stored in the affected system.","score":8.6,"severity":"HIGH","products":["cisco catalyst sd-wan manager","cisco catalyst sd-wan manager 20.12.7"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R","label":"Vendor Advisory"},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk","label":"Not Applicable"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-14T17:16:20.353","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20210","published":"2026-05-14T17:16:20.057","modified":"2026-06-29T17:35:57.443","description":"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform unauthorized actions on an affected system.\r\n\r\nThis vulnerability exists because of a failure to redact sensitive information within device configurations and templates. An attacker could exploit this vulnerability by elevating their read-only permissions to those of a high-privileged user. A successful exploit could allow the attacker to access or modify configuration settings within Cisco Catalyst SD-WAN Manager as a high-privileged user.","score":5.4,"severity":"MEDIUM","products":["cisco catalyst sd-wan manager","cisco catalyst sd-wan manager 20.12.7"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R","label":"Vendor Advisory"},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk","label":"Not Applicable"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-14T17:16:20.057","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20209","published":"2026-05-14T17:16:19.750","modified":"2026-06-29T17:33:57.353","description":"A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user.\r\n\r\nThis vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their read-only permissions in Cisco Catalyst SD-WAN Manager to those of a high-privileged user. A successful exploit could allow the attacker to perform actions as a high-privileged user.","score":5.4,"severity":"MEDIUM","products":["cisco catalyst sd-wan manager","cisco catalyst sd-wan manager 20.12.7"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R","label":"Vendor Advisory"},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk","label":"Not Applicable"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-14T17:16:19.750","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20182","published":"2026-05-14T17:16:19.387","modified":"2026-06-17T15:06:02.767","description":"May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the  was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The  section of this advisory includes Show Control Connections guidance to help with system checks.&nbsp;\r\n\r\nA vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.\r\nThis vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.","score":10,"severity":"CRITICAL","products":["cisco catalyst sd-wan manager","cisco catalyst sd-wan manager 20.12.7","cisco sd-wan vbond orchestrator","cisco sd-wan vbond orchestrator 20.12.7","cisco sd-wan vsmart controller","cisco sd-wan vsmart controller 20.12.7"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW","label":"Vendor Advisory"},{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk","label":"Not Applicable"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20182","label":"US Government Resource"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-14T17:16:19.387","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-44279","published":"2026-05-12T18:17:30.330","modified":"2026-06-26T09:16:34.213","description":"An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions, FortiTokenAndroid 5.2 all versions may allow attacker to disclose information via an exported Content Provider URI.","score":5.5,"severity":"MEDIUM","products":["fortinet fortitoken mobile 5.2.0","fortinet fortitoken mobile 5.2.1","fortinet fortitoken mobile 5.2.2","fortinet fortitoken mobile 6.1.0","fortinet fortitoken mobile 6.2.0"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-130","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-12T18:17:30.330","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-44278","published":"2026-05-12T18:17:30.177","modified":"2026-06-17T10:50:26.020","description":"A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>","score":2.3,"severity":"LOW","products":["fortinet forticlient"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-129","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-12T18:17:30.177","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-44277","published":"2026-05-12T18:17:30.040","modified":"2026-06-17T10:50:25.907","description":"A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted requests.","score":9.8,"severity":"CRITICAL","products":["fortinet fortiauthenticator"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-128","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-12T18:17:30.040","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-26083","published":"2026-05-12T18:16:39.817","modified":"2026-07-08T14:16:57.307","description":"A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all versions, FortiSandbox PaaS 22.2 all versions, FortiSandbox PaaS 22.1 all versions, FortiSandbox PaaS 21.4 all versions, FortiSandbox PaaS 21.3 all versions, FortiSandbox PaaS 5.0.0 through 5.0.1, FortiSandbox PaaS 4.4.5 through 4.4.8 may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests.","score":9.8,"severity":"CRITICAL","products":["fortinet fortisandbox","fortinet fortisandbox cloud","fortinet fortisandbox cloud 24.1.4436","fortinet fortisandbox paas"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-136","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-12T18:16:39.817","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-25690","published":"2026-05-12T18:16:39.540","modified":"2026-06-17T10:25:03.870","description":"An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, FortiDeceptor 5.3.0 through 5.3.3, FortiDeceptor 5.2.0 through 5.2.1, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with at least read-only admin permission to read log files via HTTP crafted requests.","score":4.3,"severity":"MEDIUM","products":["fortinet fortideceptor","fortinet fortideceptor 5.2.0","fortinet fortideceptor 5.2.1"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-138","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-12T18:16:39.540","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2026-25088","published":"2026-05-12T18:16:39.327","modified":"2026-06-17T10:24:06.140","description":"An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 through 7.4.9, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via  specifically crafted HTTP requests.","score":5.4,"severity":"MEDIUM","products":["fortinet fortindr"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-134","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-12T18:16:39.327","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2025-67604","published":"2026-05-12T18:16:36.470","modified":"2026-06-17T09:57:54.987","description":"A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing crashes. This happens if internal locks are aligned, which is out of control of the attacker.","score":5.3,"severity":"MEDIUM","products":["fortinet fortianalyzer","fortinet fortimanager"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-137","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-12T18:16:36.470","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2025-53870","published":"2026-05-12T18:16:36.140","modified":"2026-06-17T09:39:03.567","description":"An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-W2 7.4.0 through 7.4.4, FortiAP-W2 7.2 all versions, FortiAP-W2 7.0 all versions may allow  an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command.","score":6.7,"severity":"MEDIUM","products":["fortinet fortiap","fortinet fortiap-w2"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-133","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-12T18:16:36.140","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2025-53844","published":"2026-05-12T18:16:35.983","modified":"2026-06-17T09:39:01.180","description":"A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacker to execute unauthorized code or commands via specially crafted packets.","score":8.8,"severity":"HIGH","products":["fortinet fortios"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-123","label":"Vendor Advisory"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-864900.html","label":"cert-portal.siemens.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-12T18:16:35.983","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2025-53681","published":"2026-05-12T18:16:35.860","modified":"2026-06-17T09:38:42.760","description":"An improper neutralization of special elements used in an SQL Command (\"SQL Injection&\") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.3, FortiMail 7.4.0 through 7.4.5, FortiMail 7.2.0 through 7.2.8 allows an authenticated privileged attacker to execute unauthorized code or commands via specifically crafted HTTP or HTTPS requests.","score":7.2,"severity":"HIGH","products":["fortinet fortimail"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-132","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-12T18:16:35.860","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2025-53680","published":"2026-05-12T18:16:35.687","modified":"2026-07-08T14:16:54.283","description":"An improper neutralization of special elements used in an OS command (\"OS Command Injection\") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versions, FortiAP 7.0 all versions, FortiAP 6.4 all versions, FortiAP-U 7.0.0 through 7.0.5, FortiAP-U 6.2 all versions, FortiAP-W2 7.4.0 through 7.4.4, FortiAP-W2 7.2 all versions, FortiAP-W2 7.0 all versions allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.","score":6.7,"severity":"MEDIUM","products":["fortinet fortiap","fortinet fortiap-u","fortinet fortiap-w2"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-131","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-12T18:16:35.687","changedFields":["remediation"],"lastChangedAt":"2026-08-27T09:59:01.979Z"},{"id":"CVE-2022-50994","published":"2026-05-08T13:16:34.150","modified":"2026-06-17T05:24:33.860","description":"DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login handler that allows unauthenticated remote attackers to execute arbitrary commands by injecting shell metacharacters into the formpassword parameter. Attackers can exploit unsanitized input passed to the otp_check.sh script to achieve remote code execution with web server privileges. Exploitation requires knowledge of a valid username and that the target account has MOTP authentication enabled.","score":9.2,"severity":"CRITICAL","products":[],"vendors":[],"windowsVersions":[],"primaryVendor":"DrayTek","vendorCategory":"Networking & Security","references":[{"url":"https://www.draytek.co.uk/support/downloads/vigor-2960/older-firmware/firmware-1514?task=download.send&id=2597:readme-v2960-1514&catid=1251","label":"draytek.co.uk"},{"url":"https://www.draytek.com/about/newsroom/2021/2021/end-of-life-notification-vigor2960","label":"draytek.com"},{"url":"https://www.vulncheck.com/advisories/draytek-vigor-2960-os-command-injection-via-mainfunction-cgi","label":"vulncheck.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-08T13:16:34.150","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:11:46.979Z"},{"id":"CVE-2026-20219","published":"2026-05-06T17:16:21.760","modified":"2026-06-17T10:17:18.293","description":"A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile data of other users or affect quiz and poll results. Cisco has addressed this vulnerability in Cisco Slido and no customer action is needed.\r\n\r This vulnerability existed because of the presence of an insecure direct object reference. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by sending a crafted request to the vulnerable API endpoint. A successful exploit could have allowed the attacker to view the social profiles of other users or affect quiz and poll results.","score":5.4,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-slido-idor-CpsFmKxN","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:21.760","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20195","published":"2026-05-06T17:16:21.630","modified":"2026-06-29T15:27:17.027","description":"A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device.\r\n\r\nThis vulnerability exists because error messages are observed when the affected API endpoint is called. An attacker could exploit this vulnerability by sending a series of crafted requests to the affected endpoint and analyzing the differentiated responses. A successful exploit could allow the attacker to compile a list of valid usernames on an affected system.","score":5.3,"severity":"MEDIUM","products":["cisco identity services engine","cisco identity services engine 3.3.0","cisco identity services engine 3.4.0","cisco identity services engine 3.5.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-bypass-uxjRXGpb","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:21.630","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20193","published":"2026-05-06T17:16:21.500","modified":"2026-07-01T13:27:03.933","description":"A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an&nbsp;authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device.\r\n\r\nThis vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the web-based management interface and directly calling an affected endpoint. A successful exploit could allow the attacker to gain unauthorized&nbsp;read access to sensitive RADIUS Policy details that are restricted for their role.","score":4.3,"severity":"MEDIUM","products":["cisco identity services engine","cisco identity services engine 3.3.0","cisco identity services engine 3.4.0","cisco identity services engine 3.5.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-bypass-uxjRXGpb","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:21.500","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20189","published":"2026-05-06T17:16:21.360","modified":"2026-06-29T16:53:33.077","description":"A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an&nbsp;authenticated, remote attacker to download arbitrary log files from the server.\r\n\r\nThis vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this vulnerability by submitting a crafted URL request to an affected device. A successful exploit could allow the attacker to download sensitive log files that they would otherwise not have authorization to access.\r\nTo exploit this vulnerability, the attacker must have valid credentials to access the web-based management interface of the affected device.","score":4.3,"severity":"MEDIUM","products":["cisco prime infrastructure","cisco prime infrastructure 3.10.6"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-unauth-infodiscl-LFnLgmey","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:21.360","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20188","published":"2026-05-06T17:16:21.190","modified":"2026-06-17T10:17:16.700","description":"Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO), additional information has been made available to the Cisco Product Security Incident Response Team (PSIRT).\r\n\r\nUpon further analysis, the Cisco PSIRT has reclassified this issue as a customer-configurable, resource management issue rather than a security vulnerability.","score":0,"severity":"NONE","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-dos-7Egqyc","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:21.190","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20185","published":"2026-05-06T17:16:21.050","modified":"2026-06-17T10:17:16.493","description":"A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of&nbsp;Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X)&nbsp;firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&nbsp;\r\n\r\nThis vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.\r\nThis vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMPv2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMPv3, the attacker must have valid SNMP user credentials for the affected system.","score":7.7,"severity":"HIGH","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg350-snmp-dos-GEFZr2Tj","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:21.050","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20172","published":"2026-05-06T17:16:20.880","modified":"2026-06-17T10:17:15.700","description":"A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Agent.\r\n\r\nThis vulnerability is due to inadequate validation of file contents during file upload operations. An attacker could exploit this vulnerability by uploading a file that contains malicious scripts or HTML code, which the application could make available to other users to access. A successful exploit could allow the attacker to execute the contents of that file in the browser of a user and conduct browser-based attacks.&nbsp;","score":4.3,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-lite-agent-BCgSN8eb","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:20.880","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20169","published":"2026-05-06T17:16:20.743","modified":"2026-06-29T17:28:14.693","description":"A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router.\r\n\r\nThis vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by submitting crafted input in the web-based management interface. A successful exploit could allow the attacker to create, read, or delete files and execute limited commands in&nbsp;user EXEC mode on a remote router.","score":6.4,"severity":"MEDIUM","products":["cisco iot field network director"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:20.743","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20168","published":"2026-05-06T17:16:20.590","modified":"2026-06-30T20:38:57.423","description":"A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access.\r\n\r\nThis vulnerability is due to insufficient file access checks. An attacker could exploit this vulnerability by submitting crafted input in the web-based management interface. A successful exploit could allow the attacker to read files that they are not authorized to access.","score":6.5,"severity":"MEDIUM","products":["cisco iot field network director"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:20.590","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20167","published":"2026-05-06T17:16:20.433","modified":"2026-06-30T20:39:20.010","description":"A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router.\r\n\r\nThis vulnerability is due to improper error handling. An attacker could exploit this vulnerability by submitting crafted input to the web-based management interface. A successful exploit could allow the attacker to request unauthorized files from a remote router, causing the router to reload and resulting in a DoS condition.","score":7.7,"severity":"HIGH","products":["cisco iot field network director"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:20.433","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20035","published":"2026-05-06T17:16:20.280","modified":"2026-07-08T13:15:03.710","description":"A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device.\r\n\r\nThis vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device.","score":7.2,"severity":"HIGH","products":["cisco unity connection","cisco unity connection 14.0","cisco unity connection 14su1","cisco unity connection 14su2","cisco unity connection 14su3","cisco unity connection 14su4","cisco unity connection 15.0","cisco unity connection 15su1"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:20.280","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-20034","published":"2026-05-06T17:16:20.093","modified":"2026-07-01T16:01:11.203","description":"A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to execute arbitrary code as root, possibly resulting in the complete compromise of a targeted device.&nbsp;To exploit this vulnerability, the attacker must have valid user credentials on the affected device.","score":8.8,"severity":"HIGH","products":["cisco unity connection","cisco unity connection 14.0","cisco unity connection 14su1","cisco unity connection 14su2","cisco unity connection 14su3","cisco unity connection 14su4","cisco unity connection 15.0","cisco unity connection 15su1"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-05-06T17:16:20.093","changedFields":["remediation"],"lastChangedAt":"2026-08-31T21:45:36.229Z"},{"id":"CVE-2026-5944","published":"2026-04-28T14:16:13.853","modified":"2026-06-17T10:59:56.077","description":"An improper access control vulnerability exists in the Cisco Intersight Device Connector for Nutanix Prism Central. The service exposes an API passthrough endpoint on TCP port 7373 that is accessible within the network scope of the deployment environment without authentication.\n\n\n\nAn unauthenticated attacker with network access can exploit this vulnerability by sending crafted requests to the exposed endpoint to enumerate cluster metadata, including virtual machine information and cluster configuration details. While the API primarily supports read-only operations, it also allows certain cluster maintenance workflows to be invoked.\n\n\n\nAlthough this vulnerability does not allow persistent modification of system configurations or access to credentials or sensitive user data, successful exploitation may result in disruption of active workloads, leading to loss of service availability within the affected environment.","score":6.7,"severity":"MEDIUM","products":["cisco intersight device connector"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://download.nutanix.com/alerts/Security_Advisory_0046.pdf","label":"Third Party Advisory"},{"url":"https://portal.nutanix.com/page/documents/list?type=software&filterKey=software&filterVal=Prism","label":"Product"},{"url":"https://www.nutanix.com/support","label":"Product"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-28T14:16:13.853","changedFields":["remediation"],"lastChangedAt":"2026-08-24T21:30:44.553Z"},{"id":"CVE-2026-20186","published":"2026-04-15T17:17:03.933","modified":"2026-06-29T15:28:03.217","description":"A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to&nbsp;root. In single-node ISE deployments, successful exploitation of these vulnerabilities could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.","score":9.9,"severity":"CRITICAL","products":["cisco identity services engine","cisco identity services engine 3.2.0","cisco identity services engine 3.3.0","cisco identity services engine 3.4.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:03.933","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20184","published":"2026-04-15T17:17:03.677","modified":"2026-06-17T10:17:16.380","description":"A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service.\r\n\r\nThis vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token. A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services.","score":9.8,"severity":"CRITICAL","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:03.677","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20180","published":"2026-04-15T17:17:03.460","modified":"2026-07-08T14:24:46.213","description":"A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to&nbsp;root. In single-node ISE deployments, successful exploitation of these vulnerabilities could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.","score":9.9,"severity":"CRITICAL","products":["cisco identity services engine","cisco identity services engine 3.2.0","cisco identity services engine 3.3.0","cisco identity services engine 3.4.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:03.460","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20170","published":"2026-04-15T17:17:03.297","modified":"2026-07-01T15:55:49.693","description":"A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, remote attacker to conduct cross-site scripting attacks. Cisco has addressed this vulnerability in the Cisco Webex Contact Center service, and no customer action is needed.\r\n\r This vulnerability existed because HTML and script content was not properly handled. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to follow a malicious link. A successful exploit could have allowed the attacker to steal sensitive information from the browser, including authentication and session information.","score":6.1,"severity":"MEDIUM","products":["cisco webex contact center"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webexcc-xss-WEX5nUnA","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:03.297","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20161","published":"2026-04-15T17:17:03.120","modified":"2026-06-17T10:17:14.457","description":"A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device.\r\n\r\nThis vulnerability is due to improper access controls on files that are on the local file system&nbsp;of an affected device. An attacker could exploit this vulnerability by placing a symbolic link in a specific location on the local file system. A successful exploit could allow the attacker to bypass file system permissions and overwrite arbitrary files on the affected device.","score":5.5,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-te-agentfilewrite-tqUw3SMU","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:03.120","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20152","published":"2026-04-15T17:17:02.870","modified":"2026-06-17T10:17:13.347","description":"A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements.\r\n\r\nThis vulnerability is due to improper validation of user-supplied authentication input in HTTP requests. An attacker could exploit this vulnerability by sending HTTP requests that contain specific authentication requests to an affected device. A successful exploit could allow the attacker to bypass policy enforcement on the device. There is no direct impact to the Cisco Secure Web Appliance. However, as a result of exploiting this vulnerability, an attacker could send HTTP requests that should be restricted through the device.","score":5.3,"severity":"MEDIUM","products":[],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-auth-bypass-6YZkTQhd","label":"sec.cloudapps.cisco.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:02.870","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20148","published":"2026-04-15T17:17:02.637","modified":"2026-07-08T14:20:10.177","description":"A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.\r\n\r\nThis vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files on the affected system.","score":4.9,"severity":"MEDIUM","products":["cisco identity services engine","cisco identity services engine 3.1.0","cisco identity services engine 3.2.0","cisco identity services engine 3.3.0","cisco identity services engine 3.4.0","cisco identity services engine 3.5.0","cisco identity services engine passive identity connector","cisco identity services engine passive identity connector 3.1.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:02.637","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20147","published":"2026-04-15T17:17:02.410","modified":"2026-07-08T14:20:19.670","description":"A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node ISE deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.","score":9.9,"severity":"CRITICAL","products":["cisco identity services engine passive identity connector","cisco identity services engine passive identity connector 3.1.0","cisco identity services engine passive identity connector 3.2.0","cisco identity services engine passive identity connector 3.3.0","cisco identity services engine passive identity connector 3.4.0","cisco identity services engine passive identity connector 3.5.0","cisco identity services engine","cisco identity services engine 3.1.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:02.410","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20136","published":"2026-04-15T17:17:02.150","modified":"2026-07-02T18:39:20.640","description":"A vulnerability in the&nbsp;CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to root.\r\n\r\nThis vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by providing crafted input to a specific CLI command. A successful exploit could allow the attacker to elevate their privileges to root on the underlying operating system.","score":6,"severity":"MEDIUM","products":["cisco identity services engine","cisco identity services engine 3.3.0","cisco identity services engine 3.4.0","cisco identity services engine 3.5.0","cisco identity services engine passive identity connector","cisco identity services engine passive identity connector 3.3.0","cisco identity services engine passive identity connector 3.4.0","cisco identity services engine passive identity connector 3.5.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-5WSJcYJB","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:02.150","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20132","published":"2026-04-15T17:17:01.967","modified":"2026-07-02T18:38:16.367","description":"Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative&nbsp;write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management interface of an affected device.\r\n\r\nThese vulnerabilities are due to insufficient sanitization of user-supplied data that is stored in the web page. An attacker could exploit these vulnerabilities by convincing a user of the interface to click a specific link or view an affected web page. The injected script code may be executed in the context of the web-based management interface or allow the attacker to access sensitive browser-based information.","score":4.8,"severity":"MEDIUM","products":["cisco identity services engine","cisco identity services engine 3.2.0","cisco identity services engine 3.3.0","cisco identity services engine 3.4.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-isexss-BS8ctE7U","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:01.967","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20081","published":"2026-04-15T17:17:01.783","modified":"2026-06-17T10:17:02.720","description":"Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker&nbsp;to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials.&nbsp;\r\n\r\nThese vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system.","score":6.5,"severity":"MEDIUM","products":["cisco unity connection","cisco unity connection 14.0","cisco unity connection 14su1","cisco unity connection 14su2","cisco unity connection 14su3","cisco unity connection 14su3a","cisco unity connection 14su4","cisco unity connection 14su5"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-file-download-RmKEVWPx","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:01.783","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20078","published":"2026-04-15T17:17:01.610","modified":"2026-06-17T10:17:02.400","description":"Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker&nbsp;to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials.&nbsp;\r\n\r\nThese vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system.","score":6.5,"severity":"MEDIUM","products":["cisco unity connection","cisco unity connection 14.0","cisco unity connection 14su1","cisco unity connection 14su2","cisco unity connection 14su3","cisco unity connection 14su3a","cisco unity connection 14su4","cisco unity connection 14su5"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-file-download-RmKEVWPx","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:01.610","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20061","published":"2026-04-15T17:17:01.433","modified":"2026-06-17T10:17:00.193","description":"A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to perform an SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.\r\n\r\nThis vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP(S) request to the web-based management interface of an affected device. A successful exploit could allow the attacker to view data on the affected device.","score":4.3,"severity":"MEDIUM","products":["cisco unity connection","cisco unity connection 14.0","cisco unity connection 14su1","cisco unity connection 14su2","cisco unity connection 14su3","cisco unity connection 14su3a","cisco unity connection 14su4","cisco unity connection 14su5"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-vulns-n2EJSbbw","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:01.433","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20060","published":"2026-04-15T17:17:01.250","modified":"2026-06-17T10:17:00.083","description":"A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.\r\n\r\nThis vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious web page.","score":4.7,"severity":"MEDIUM","products":["cisco unity connection","cisco unity connection 14.0","cisco unity connection 14su1","cisco unity connection 14su2","cisco unity connection 14su3","cisco unity connection 14su3a","cisco unity connection 14su4","cisco unity connection 15.0"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-vulns-n2EJSbbw","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:01.250","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-20059","published":"2026-04-15T17:17:01.060","modified":"2026-06-17T10:16:59.967","description":"A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface.\r\n\r\nThis vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.","score":6.1,"severity":"MEDIUM","products":["cisco unity connection","cisco unity connection 14.0","cisco unity connection 14su1","cisco unity connection 14su2","cisco unity connection 14su3","cisco unity connection 14su3a","cisco unity connection 14su4","cisco unity connection 14su5"],"vendors":["Cisco"],"windowsVersions":[],"primaryVendor":"Cisco","vendorCategory":"Networking & Security","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-vulns-n2EJSbbw","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-15T17:17:01.060","changedFields":["remediation"],"lastChangedAt":"2026-08-13T16:28:21.919Z"},{"id":"CVE-2026-40688","published":"2026-04-14T23:16:29.633","modified":"2026-07-24T21:10:00.143","description":"An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests.","score":7.2,"severity":"HIGH","products":["fortinet fortiweb"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-127","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T23:16:29.633","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-39815","published":"2026-04-14T16:16:46.383","modified":"2026-06-17T10:42:37.670","description":"A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests","score":8.8,"severity":"HIGH","products":["fortinet fortiddos-f"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-119","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:46.383","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-39814","published":"2026-04-14T16:16:45.850","modified":"2026-06-17T10:42:37.567","description":"A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via <insert attack vector here>","score":6.7,"severity":"MEDIUM","products":["fortinet fortiweb"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-114","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:45.850","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-39813","published":"2026-04-14T16:16:45.680","modified":"2026-06-18T13:25:36.770","description":"A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.","score":9.8,"severity":"CRITICAL","products":["fortinet fortisandbox"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-112","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:45.680","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-39812","published":"2026-04-14T16:16:45.490","modified":"2026-06-17T10:42:37.330","description":"A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandbox PaaS 4.2 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>","score":4.8,"severity":"MEDIUM","products":["fortinet fortisandbox","fortinet fortisandbox cloud","fortinet fortisandbox cloud 5.0.4","fortinet fortisandbox cloud 5.0.5"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-110","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:45.490","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-39811","published":"2026-04-14T16:16:45.310","modified":"2026-06-17T10:42:37.213","description":"A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to denial of service via <insert attack vector here>","score":4.9,"severity":"MEDIUM","products":["fortinet fortiweb"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-108","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:45.310","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-39810","published":"2026-04-14T16:16:45.173","modified":"2026-06-17T10:42:37.103","description":"A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.","score":6,"severity":"MEDIUM","products":["fortinet forticlientems"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-107","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:45.173","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-39809","published":"2026-04-14T16:16:45.017","modified":"2026-06-17T10:42:36.997","description":"A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests","score":6.7,"severity":"MEDIUM","products":["fortinet forticlientems"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-102","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:45.017","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-39808","published":"2026-04-14T16:16:44.860","modified":"2026-07-17T05:16:38.870","description":"A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>","score":9.8,"severity":"CRITICAL","products":["fortinet fortisandbox"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-100","label":"Vendor Advisory"},{"url":"https://github.com/samu-delucas/CVE-2026-39808","label":"Exploit"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-39808","label":"US Government Resource"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:44.860","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-27316","published":"2026-04-14T16:16:37.863","modified":"2026-06-17T10:27:01.983","description":"A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection.","score":2.7,"severity":"LOW","products":["fortinet fortisandbox","fortinet fortisandbox cloud 5.0.4","fortinet fortisandbox cloud 5.0.5"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-113","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:37.863","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-25691","published":"2026-04-14T16:16:37.623","modified":"2026-06-17T10:25:04.030","description":"A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests.","score":6.7,"severity":"MEDIUM","products":["fortinet fortisandbox","fortinet fortisandbox cloud 5.0.4"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-115","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:37.623","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-23708","published":"2026-04-14T16:16:37.277","modified":"2026-06-17T10:21:58.683","description":"A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration, which raises the attack complexity.","score":7.5,"severity":"HIGH","products":["fortinet fortisoar"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-101","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:37.277","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-22828","published":"2026-04-14T16:16:37.110","modified":"2026-06-17T10:20:29.637","description":"A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation","score":8.1,"severity":"HIGH","products":["fortinet fortianalyzer cloud","fortinet fortimanager cloud"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-121","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:37.110","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-22576","published":"2026-04-14T16:16:36.937","modified":"2026-06-17T10:20:06.340","description":"A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to retrieve passwords for multiple installed connectors via server address modification in connector configuration.","score":4.3,"severity":"MEDIUM","products":["fortinet fortisoar"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-104","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:36.937","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-22574","published":"2026-04-14T16:16:36.760","modified":"2026-06-17T10:20:06.227","description":"A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to retrieve Service account password via server address modification in LDAP configuration.","score":4.1,"severity":"MEDIUM","products":["fortinet fortisoar"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-105","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:36.760","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-22573","published":"2026-04-14T16:16:36.550","modified":"2026-06-17T10:20:06.100","description":"An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5 all versions, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to perform path traversal attack via File Content Extraction actions.","score":6.5,"severity":"MEDIUM","products":["fortinet fortisoar"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-116","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:36.550","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-22155","published":"2026-04-14T16:16:36.267","modified":"2026-07-08T13:16:30.430","description":"A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow attacker to information disclosure via <insert attack vector here>","score":6.5,"severity":"MEDIUM","products":["fortinet fortisoar"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-106","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:36.267","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-22154","published":"2026-04-14T16:16:36.077","modified":"2026-06-17T10:19:27.117","description":"An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to perform a stored cross site scripting (XSS) attack via crafted HTTP Requests.","score":4.6,"severity":"MEDIUM","products":["fortinet fortisoar"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-117","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:36.077","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-21742","published":"2026-04-14T16:16:35.930","modified":"2026-07-08T13:16:30.300","description":"A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated attacker to view cleartext password in response for Secure Message Exchange and Radius queries, if configured","score":5.7,"severity":"MEDIUM","products":["fortinet fortisoar"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-106","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:35.930","changedFields":[],"lastChangedAt":null},{"id":"CVE-2026-21741","published":"2026-04-14T16:16:35.777","modified":"2026-06-17T10:18:59.710","description":"An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.","score":2.4,"severity":"LOW","products":["fortinet fortinac-f"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-118","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:35.777","changedFields":[],"lastChangedAt":null},{"id":"CVE-2025-68649","published":"2026-04-14T16:16:34.760","modified":"2026-06-17T09:59:22.860","description":"An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4.0 through 7.4.7, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions may allow a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.","score":6,"severity":"MEDIUM","products":["fortinet fortimanager cloud","fortinet fortimanager","fortinet fortianalyzer cloud","fortinet fortianalyzer"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-120","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:34.760","changedFields":[],"lastChangedAt":null},{"id":"CVE-2025-61886","published":"2026-04-14T16:16:31.800","modified":"2026-06-17T09:51:02.897","description":"An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests.","score":5.4,"severity":"MEDIUM","products":["fortinet fortisandbox","fortinet fortisandbox cloud 5.0.4"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-109","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:31.800","changedFields":[],"lastChangedAt":null},{"id":"CVE-2025-61848","published":"2026-04-14T16:16:31.610","modified":"2026-08-11T20:17:23.723","description":"An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.8, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4.0 through 7.4.8, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions may allow a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC API","score":7.2,"severity":"HIGH","products":["fortinet fortianalyzer","fortinet fortianalyzer cloud","fortinet fortimanager","fortinet fortimanager cloud"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-111","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:31.610","changedFields":[],"lastChangedAt":null},{"id":"CVE-2025-61624","published":"2026-04-14T16:16:31.300","modified":"2026-06-17T09:50:40.297","description":"An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSwitchManager 7.2.0 through 7.2.7, FortiSwitchManager 7.0.0 through 7.0.6 may allow an authenticated attacker with admin profile and at least read-write permissions to write or delete arbitrary files via specific CLI commands.","score":6,"severity":"MEDIUM","products":["fortinet fortios","fortinet fortipam","fortinet fortiproxy","fortinet fortiswitchmanager"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-122","label":"Vendor Advisory"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-975644.html","label":"cert-portal.siemens.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:31.300","changedFields":[],"lastChangedAt":null},{"id":"CVE-2025-59809","published":"2026-04-14T16:16:31.103","modified":"2026-06-17T09:46:44.960","description":"A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.4, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated attacker to discover services running on local ports via crafted requests.","score":4.3,"severity":"MEDIUM","products":["fortinet fortisoar","fortinet fortisoar 7.6.4"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-103","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:31.103","changedFields":[],"lastChangedAt":null},{"id":"CVE-2025-53847","published":"2026-04-14T16:16:30.890","modified":"2026-06-17T09:39:01.470","description":"A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or commands via specially crafted packets.","score":6.5,"severity":"MEDIUM","products":["fortinet fortios"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-125","label":"Vendor Advisory"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-975644.html","label":"cert-portal.siemens.com"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:30.890","changedFields":[],"lastChangedAt":null},{"id":"CVE-2024-23104","published":"2026-04-14T16:16:28.723","modified":"2026-06-17T07:12:02.303","description":"An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at least read-only permission on system maintenance to access backup information via crafted HTTP requests","score":5.4,"severity":"MEDIUM","products":["fortinet fortivoice","fortinet fortindr","fortinet fortindr 7.6.0"],"vendors":["Fortinet"],"windowsVersions":[],"primaryVendor":"Fortinet","vendorCategory":"Networking & Security","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-26-124","label":"Vendor Advisory"}],"kev":null,"source":"NIST NVD","firstSeenAt":"2026-04-14T16:16:28.723","changedFields":[],"lastChangedAt":null}],"checkedAt":"2026-10-10T00:45:28.417Z","nvdTimestamp":"2026-10-10T00:45:28.947","kevVersion":"2026.10.08","msrcRelease":"2026-10-08T07:00:00","partial":false,"sourceStatus":{"nvd":"available","cisaKev":"available","microsoftMsrc":"available","epss":"unavailable"},"viewVendor":null,"windowDays":1,"microsoftWindowDays":35,"networkHistoryDays":120}