{"success":true,"data":{"threats":[{"id":"c501b075-24f9-45f6-b2a1-0cfe3a12e1a5","slug":"cve-2026-106436","externalId":"CVE-2026-106436","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106436 — The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit.","description":"The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit. This can leave the encoder in an invalid state. An unauthenticated actor who can cause an affected application to encode an unusually large data structure can terminate the PHP worker or cause the resulting document to omit fields. No MongoDB server connection or database authentication is required.","cveId":"CVE-2026-106436","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-252"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://jira.mongodb.org/browse/PHPC-2739","type":"advisory","title":"cna@mongodb.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:31.087Z","addedAt":"2026-10-08T21:05:52.835Z","updatedAt":"2026-10-08T21:05:52.835Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106436","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106436","note":"authoritative record"}]},{"id":"e908b7f7-c7a5-4881-9800-32fd3cc8de85","slug":"cve-2026-18397","externalId":"CVE-2026-18397","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-18397 — This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesse…","description":"This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component.\n\nThe attack leverages an unrestricted messaging interface between an attacker-controlled web page and the native host, allowing malicious input to bypass security checks.","cveId":"CVE-2026-18397","cvssScore":9.4,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"critical","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-130","CWE-252","CWE-347","CWE-457"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.thalesgroup.com/en/product-security-incident-response","type":"advisory","title":"psirt@thalesgroup.com"}],"epssScore":0.00337,"epssPercentile":0.25018,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-01T22:17:01.220Z","addedAt":"2026-10-01T23:50:39.516Z","updatedAt":"2026-10-02T21:50:40.069Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18397","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-18397","note":"authoritative record"}]},{"id":"64f73d53-8c38-4552-aa23-6651b59cf1f9","slug":"cve-2026-95316","externalId":"CVE-2026-95316","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-95316 — Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program.","description":"Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program. (Chromium security severity: Low)","cveId":"CVE-2026-95316","cvssScore":2.9,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","severity":"low","vendor":"google","product":"chrome","affectedVersions":["< 154.0.8037.57"],"cwes":["CWE-252"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0856730748.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/552023752","type":"advisory","title":"Permissions Required"}],"epssScore":0.00106,"epssPercentile":0.01038,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-29T18:17:23.807Z","addedAt":"2026-09-29T19:50:41.941Z","updatedAt":"2026-09-30T17:50:46.093Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-95316","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-95316","note":"authoritative record"}]},{"id":"c8e3c532-8996-4e6c-a7b8-9827c2ba6a4d","slug":"cve-2026-67409","externalId":"CVE-2026-67409","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-67409 — RabbitMQ is a messaging and streaming broker.","description":"RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18, JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoS (CWE-252). the JWKS key fetching mechanism in uaajwt.erl does not validate the HTTP response status code when downloading signing keys from the OAuth2 provider's JWKS endpoint. Non-200 responses (including 4xx and 5xx errors) are processed identically to successful responses. When the JWKS endpoint returns an error response with a valid-JSON body that lacks a keys field, all previously cached signing keys are destroyed, causing a persistent authentication denial of Files: deps/rabbitmqauthbackendoauth2/src/uaajwt.erl, lines 50-63 deps/rabbitmqauthbackendoauth2/src/uaajwks.erl, lines 5-7 deps/rabbitmqauthbackendoauth2/src/rabbitoauth2provider.erl, lines 98-107 Bug 1: HTTP status code ignored (uaajwt.erl:50-63): The Erlang httpc module returns {ok, {{HttpVersion, StatusCode, ReasonPhrase}, Headers, Body}}. The pattern {ok, {, , JwksBody}} matches ANY successful HTTP transaction Persistent authentication DoS: Once keys are destroyed, ALL OAuth2/JWT authentication fails for all users until a new successful JWKS refresh occurs Amplification: A single attacker can deny access to all legitimate OAuth2 users across the entire RabbitMQ. This issue is fixed in versions 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18.","cveId":"CVE-2026-67409","cvssScore":8.2,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"broadcom","product":"rabbitmq server","affectedVersions":[">= 3.13.0, < 3.13.18",">= 4.0.0, < 4.0.23",">= 4.1.0, < 4.1.14",">= 4.2.0, < 4.2.9",">= 4.3.0, < 4.3.3"],"cwes":["CWE-252"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.9","type":"advisory","title":"Release Notes"},{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.3","type":"advisory","title":"Release Notes"},{"url":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-qw3h-qqm9-jrw8","type":"advisory","title":"Exploit"}],"epssScore":0.0049,"epssPercentile":0.40216,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-25T17:17:12.943Z","addedAt":"2026-09-25T17:50:40.196Z","updatedAt":"2026-10-08T16:39:34.257Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67409","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-67409","note":"authoritative record"}]},{"id":"63586666-5cf7-4cb4-b12e-5d8f5984f90d","slug":"cve-2026-71180","externalId":"CVE-2026-71180","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-71180 — Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability.","description":"Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.","cveId":"CVE-2026-71180","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"dell","product":"update package framework","affectedVersions":["< 26.07.03"],"cwes":["CWE-252"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000509455/dsa-2026-417-security-update-for-dell-update-package-dup-framework-vulnerabilities","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.0015,"epssPercentile":0.03672,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-16T17:18:06.100Z","addedAt":"2026-09-16T17:50:39.022Z","updatedAt":"2026-09-21T17:50:41.163Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71180","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-71180","note":"authoritative record"}]},{"id":"fb3a636b-0afe-4b45-b4b0-0b4e39a6127b","slug":"cve-2026-90648","externalId":"CVE-2026-90648","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-90648 — wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a \"table flip\" attack.","description":"wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platforms, aka a \"table flip\" attack. It does not check the return value of calloc() in wasm_rt_allocate_funcref_table() (wasm2c/wasm-rt-impl-tableops.inc). When the funcref table allocation fails, table->data is left NULL while table->size keeps the guest-declared element count; thus, bounds checks still pass and table element accesses resolve to absolute memory addresses (i * sizeof(wasm_rt_funcref_t)). This gives arbitrary read and write of host process memory and - via table.get, table.set, and call_indirect - arbitrary code execution, defeating the isolation that wasm2c exists to provide (a full sandbox escape). wasm2c is used as an in-process sandboxing boundary by RLBox and WasmBoxC, including in Firefox, which compiles the Graphite, Hunspell, Ogg, Expat, and Woff2 libraries via wasm2c to contain untrusted font, media, and XML input. Therefore, sandboxing in these applications is potentially affected. Exploitation requires the funcref table allocation to fail, for example under an address-space limit (RLIMIT_AS), on 32-bit hosts, with vm.overcommit_memory=2, or under memory pressure. On 64-bit Linux with default overcommit the allocation succeeds and the defect is not triggered. The wasm2c memory allocator aborts on calloc failure in the same runtime; the table allocator lacks this abort behavior. This was introduced in commit ab9e0b55 (PR #813).","cveId":"CVE-2026-90648","cvssScore":7.1,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-252"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1827704","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/WebAssembly/wabt","type":"advisory","title":"cve@mitre.org"},{"url":"https://github.com/trustsig-eu/wasm2c-tableflip","type":"advisory","title":"cve@mitre.org"},{"url":"https://https//blog.mozilla.org/attack-and-defense/2021/12/06/webassembly-and-back-again-fine-grained-sandboxing-in-firefox-95","type":"advisory","title":"cve@mitre.org"},{"url":"https://rlbox.dev/","type":"advisory","title":"cve@mitre.org"}],"epssScore":0.00191,"epssPercentile":0.08021,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-13T00:17:07.023Z","addedAt":"2026-09-13T01:50:34.100Z","updatedAt":"2026-09-22T21:50:38.719Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90648","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-90648","note":"authoritative record"}]},{"id":"dee04707-a261-4be1-b246-328edb6f7e40","slug":"cve-2026-86749","externalId":"CVE-2026-86749","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86749 — Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages().","description":"Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not check the return value of storage write operations in ImageUploadRequest::handleImages(). Because Laravel's default disk mode does not throw on failure, a silently failed Storage::disk('public')->put(...) call still caused the application to delete the previous image via deleteExistingImage() and to reassign and persist the model's image reference to the new filename, destroying the existing image and leaving the database row pointing at a file that was never written. A mirror problem existed in deleteExistingImage(), where a failed Storage::delete() still nulled the model's image field, orphaning the file on disk. The condition is not directly attacker-controlled: it is triggered when any legitimate authenticated user submits an image upload while the storage backend transiently fails (for example an S3 network error, a local filesystem permission problem, or quota exhaustion). The result is unrecoverable loss of the prior image and a durable inconsistency between the database and disk that requires manual reconciliation. All models whose controllers route through ImageUploadRequest::handleImages (assets, asset models, users, companies, manufacturers, locations, categories, suppliers, departments, and other image-carrying models) are affected.","cveId":"CVE-2026-86749","cvssScore":7,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":"snipeitapp","product":"snipe-it","affectedVersions":["< 8.7.0"],"cwes":["CWE-252"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/grokability/snipe-it/security/advisories/GHSA-v37p-hr9x-5w85"],"references":[{"url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-v37p-hr9x-5w85","type":"patch","title":"Exploit"},{"url":"https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-data-loss-via-failed-image-write","type":"advisory","title":"Third Party Advisory"}],"epssScore":0.00339,"epssPercentile":0.25265,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T14:17:23.880Z","addedAt":"2026-09-09T15:50:40.112Z","updatedAt":"2026-09-19T15:50:36.088Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86749","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86749","note":"authoritative record"}]},{"id":"8216ea66-3e72-40da-a44d-c81d574ee064","slug":"cve-2026-86739","externalId":"CVE-2026-86739","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86739 — Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Accou…","description":"Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Account\\AcceptanceController::store(). On filesystem drivers that return false instead of throwing on a write failure (for example the local disk with restrictive permissions, S3 with expired credentials, or a storage backend that is out of quota), execution continues into $acceptance->accept(), which sets accepted_at and the signature_filename/eula_filename fields, creates the 'accepted' action-log entry, and dispatches completion notifications even though the evidence files were never stored. The result is an acceptance record marked complete whose supporting evidence files do not exist, yielding a materially incomplete compliance artifact for EULA acknowledgement or equipment-receipt workflows. The condition is triggered when an authenticated user completes an acceptance while the storage backend is silently failing writes; an attacker cannot directly force the storage backend into that state. Fixed in Snipe-IT 8.7.0.","cveId":"CVE-2026-86739","cvssScore":2.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":"snipeitapp","product":"snipe-it","affectedVersions":["< 8.7.0"],"cwes":["CWE-252"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/grokability/snipe-it/security/advisories/GHSA-h543-58f9-v6mj"],"references":[{"url":"https://github.com/grokability/snipe-it/security/advisories/GHSA-h543-58f9-v6mj","type":"patch","title":"Exploit"},{"url":"https://www.vulncheck.com/advisories/snipe-it-before-8.7.0-acceptance-finalization-without-stored-evidence","type":"advisory","title":"Third Party Advisory"}],"epssScore":0.00357,"epssPercentile":0.27325,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-09T14:17:22.387Z","addedAt":"2026-09-09T15:50:40.058Z","updatedAt":"2026-09-18T19:50:36.714Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86739","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86739","note":"authoritative record"}]},{"id":"69e7f0d6-11a6-4605-be5c-9ef4ded8a966","slug":"cve-2026-86141","externalId":"CVE-2026-86141","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-86141 — xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a stri…","description":"xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.","cveId":"CVE-2026-86141","cvssScore":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","severity":"low","vendor":"xmlsoft","product":"libxml2","affectedVersions":["< 2.15.4"],"cwes":["CWE-252"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://github.com/GNOME/libxml2/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55"],"references":[{"url":"https://github.com/GNOME/libxml2/commit/e89a8aae4c9b40cdafcf66b3f9e57c62db37bb55","type":"patch","title":"Patch"},{"url":"https://github.com/GNOME/libxml2/compare/v2.15.3...v2.15.4","type":"advisory","title":"Release Notes"},{"url":"https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1107","type":"vendor","title":"Vendor Advisory"}],"epssScore":0.00165,"epssPercentile":0.05259,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-05T05:17:13.007Z","addedAt":"2026-09-05T05:50:31.924Z","updatedAt":"2026-09-15T19:50:35.432Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86141","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-86141","note":"authoritative record"}]},{"id":"5fdd692b-f6be-4a33-b2b5-f0748648d2f5","slug":"cve-2026-19534","externalId":"CVE-2026-19534","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-19534 — undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client …","description":"undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.","cveId":"CVE-2026-19534","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":"nodejs","product":"undici","affectedVersions":[">= 6.7.0, < 6.28.1",">= 7.0.0, < 7.29.1",">= 8.0.0, < 8.10.2","pkg:npm/undici >= 6.7.0, < 6.28.1","pkg:npm/undici >= 7.0.0, < 7.29.1","pkg:npm/undici >= 8.0.0, < 8.10.2"],"cwes":["CWE-248","CWE-252"],"tags":["nvd","status:received","status:undergoing-analysis","status:analyzed","osv","osv:ghsa-rfgv-xxqx-mfg5","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cna.openjsf.org/security-advisories.html","type":"other","title":"OSV web"},{"url":"https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-rfgv-xxqx-mfg5","type":"advisory","title":"OSV GHSA-rfgv-xxqx-mfg5"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19534","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/nodejs/undici/commit/2af0faf88b906d3127a360c3ac75164c0f95e5a5","type":"other","title":"OSV web"},{"url":"https://github.com/nodejs/undici/commit/6615e0175e9b635bcd2e3e87a47daa82f6f5b728","type":"other","title":"OSV web"},{"url":"https://github.com/nodejs/undici/commit/66e12816064cf3068f63bd134748b7fc4e779bad","type":"other","title":"OSV web"},{"url":"https://github.com/nodejs/undici","type":"vendor","title":"OSV package"},{"url":"https://github.com/nodejs/undici/releases/tag/v6.28.1","type":"other","title":"OSV web"},{"url":"https://github.com/nodejs/undici/releases/tag/v7.29.1","type":"other","title":"OSV web"},{"url":"https://github.com/nodejs/undici/releases/tag/v8.10.2","type":"other","title":"OSV web"}],"epssScore":0.00394,"epssPercentile":0.31457,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-04T18:17:51.647Z","addedAt":"2026-09-04T19:50:33.233Z","updatedAt":"2026-09-29T19:54:25.302Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19534","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-19534","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-RFGV-XXQX-MFG5"}]},{"id":"b4575347-9ab7-4e79-93c6-7ed47736e4bc","slug":"cve-2026-85649","externalId":"CVE-2026-85649","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-85649 — (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user pas…","description":"(Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not check the command's return value and unconditionally accepts the result. If mkpasswd fails to generate a yescrypt hash, for example because an incompatible mkpasswd implementation or an environment without yescrypt support is used, the resulting password hash variable can be empty and the build proceeds. The resulting image can therefore contain empty password fields for the root and alpha accounts, potentially permitting passwordless authentication depending on the authentication configuration.","cveId":"CVE-2026-85649","cvssScore":7.9,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-252","CWE-636"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://doi.org/10.5281/zenodo.22169659","type":"advisory","title":"5a6e4751-2f3f-4070-9419-94fb35b644e8"},{"url":"https://github.com/ChewKeanHo/software-actualizer/blob/v1.2.0/Shell/debian-minbase-install.sh#L788","type":"advisory","title":"5a6e4751-2f3f-4070-9419-94fb35b644e8"},{"url":"https://github.com/ChewKeanHo/software-actualizer/commit/50a0932ac705635d9af62955c353e7c6df003a61.patch","type":"advisory","title":"5a6e4751-2f3f-4070-9419-94fb35b644e8"},{"url":"https://github.com/ChewKeanHo/software-actualizer/releases/tag/v1.2.1","type":"advisory","title":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}],"epssScore":0.00204,"epssPercentile":0.09517,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-04T13:20:11.760Z","addedAt":"2026-09-04T13:50:46.201Z","updatedAt":"2026-09-08T15:50:37.757Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-85649","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-85649","note":"authoritative record"}]},{"id":"f5af7fe0-c2cb-44bc-ac40-d9b8ce34f95c","slug":"cve-2026-14957","externalId":"CVE-2026-14957","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-14957 — In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL.","description":"In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.","cveId":"CVE-2026-14957","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-252","CWE-617"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://libreswan.org/security/CVE-2026-14957/","type":"advisory","title":"d42dc95b-23f1-4e06-9076-20753a0fb0df"},{"url":"https://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.txt","type":"advisory","title":"d42dc95b-23f1-4e06-9076-20753a0fb0df"}],"epssScore":0.00468,"epssPercentile":0.38558,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-09-02T03:16:47.490Z","addedAt":"2026-09-02T03:50:30.887Z","updatedAt":"2026-09-09T15:50:35.686Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14957","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-14957","note":"authoritative record"}]},{"id":"5d95dc21-f6d5-4bd9-b319-942d2a4b62c2","slug":"cve-2026-78699","externalId":"CVE-2026-78699","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-78699 — Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existi…","description":"Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data.\n\nAshPostgres.MultiTenancy.rename_tenant/3 issues the ALTER SCHEMA ... RENAME TO ... with the non-raising Ecto.Adapters.SQL.query/2, discards its {:ok, _} | {:error, _} result, and unconditionally returns :ok. PostgreSQL rejects the rename when the target schema already exists (and on insufficient privilege or lock timeout), but that failure never reaches the caller. The calling manage_tenant update action therefore sees success and commits the tenant row with the new name, which is the schema of a different existing tenant, so subsequent reads and writes for that tenant run against the other tenant's data.\n\nThis issue affects ash_postgres: from 0.25.0 before 2.13.0.","cveId":"CVE-2026-78699","cvssScore":7.2,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-252"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cna.erlef.org/cves/CVE-2026-78699.html","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ash-project/ash_postgres/commit/8544ab15fe45784553c2d2da8ee1a388eee0174b","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"},{"url":"https://github.com/ash-project/ash_postgres/security/advisories/GHSA-6fqq-j9c4-5766","type":"advisory","title":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-78699","type":"advisory","title":"6b3ad84c-e1a6-4bf7-a703-f496b71e49db"}],"epssScore":0.0016,"epssPercentile":0.04634,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-30T16:16:42.623Z","addedAt":"2026-08-30T17:50:30.205Z","updatedAt":"2026-09-01T21:50:32.934Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78699","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-78699","note":"authoritative record"}]},{"id":"bbd5f065-4462-4445-abee-8d6d26464526","slug":"ghsa-xqqh-3w52-q8p7","externalId":"GHSA-xqqh-3w52-q8p7","source":"OSV","sourceType":"ghsa","type":"vulnerability","title":"Duplicate Advisory: Nokogiri does not check the return value from xmlC14NExecute","description":"## Duplicate Advisory\n\nThis advisory has been withdrawn because it is a duplicate of GHSA-wx95-c6cv-8532. This link is maintained to preserve external references.\n\n## Original Description\nNokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid.","cveId":null,"cvssScore":null,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"RubyGems","product":"nokogiri","affectedVersions":["pkg:gem/nokogiri >= 1.5.1"],"cwes":["CWE-252"],"tags":["osv","osv:ghsa-xqqh-3w52-q8p7","ecosystem:rubygems","withdrawn"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://osv.dev/vulnerability/GHSA-xqqh-3w52-q8p7","type":"advisory","title":"OSV GHSA-xqqh-3w52-q8p7"},{"url":"https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wx95-c6cv-8532","type":"other","title":"OSV web"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79772","type":"advisory","title":"OSV advisory"},{"url":"https://www.vulncheck.com/advisories/nokogiri-before-unchecked-return-value-canonicalize","type":"other","title":"OSV web"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-25T18:31:53.000Z","addedAt":"2026-09-02T19:54:28.459Z","updatedAt":"2026-09-10T07:55:09.076Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"GitHub Advisory","url":"https://github.com/advisories/GHSA-xqqh-3w52-q8p7"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-xqqh-3w52-q8p7"}]},{"id":"66025b68-2134-4a40-9793-9b8ecdf3917b","slug":"cve-2026-79772","externalId":"CVE-2026-79772","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-79772 — Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure…","description":"Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by providing invalid canonicalized XML that is incorrectly accepted as valid.","cveId":"CVE-2026-79772","cvssScore":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":"nokogiri","product":"nokogiri","affectedVersions":["pkg:gem/nokogiri >= 1.5.1, < 1.19.1",">= 1.5.1, < 1.19.1"],"cwes":["CWE-252"],"tags":["nvd","status:received","osv","osv:ghsa-wx95-c6cv-8532","ecosystem:rubygems","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wx95-c6cv-8532","type":"other","title":"OSV web"},{"url":"https://www.vulncheck.com/advisories/nokogiri-before-unchecked-return-value-canonicalize","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-wx95-c6cv-8532","type":"advisory","title":"OSV GHSA-wx95-c6cv-8532"},{"url":"https://github.com/sparklemotion/nokogiri","type":"vendor","title":"OSV package"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79772","type":"advisory","title":"OSV advisory"}],"epssScore":0.00342,"epssPercentile":0.25585,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-25T16:17:28.743Z","addedAt":"2026-08-25T17:50:41.690Z","updatedAt":"2026-09-10T07:55:17.429Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79772","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-79772","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-WX95-C6CV-8532"}]},{"id":"2206bc4d-9813-44f3-9e52-782e412e614b","slug":"cve-2026-77641","externalId":"CVE-2026-77641","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-77641 — tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails.","description":"tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was   ignored, so a send failure (which calls circuit_mark_for_close()  and removes the leg via cfx_del_leg()) would go undetected, causing the caller to write to the now-freed current leg and resulting in a crash. This is TROVE-2026-017.","cveId":"CVE-2026-77641","cvssScore":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","severity":"high","vendor":"torproject","product":"tor","affectedVersions":["< 0.4.9.9"],"cwes":["CWE-252"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://gitlab.torproject.org/tpo/core/tor/-/raw/tor-0.4.9.9/ChangeLog","type":"vendor","title":"Release Notes"}],"epssScore":0.00353,"epssPercentile":0.26919,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-20T21:17:11.517Z","addedAt":"2026-08-20T21:50:28.637Z","updatedAt":"2026-09-08T19:50:35.289Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77641","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-77641","note":"authoritative record"}]},{"id":"4935980d-b07a-415d-a4a7-180465b745b5","slug":"cve-2026-47245","externalId":"CVE-2026-47245","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-47245 — MyBB is free and open source forum software.","description":"MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List component does not validate reciprocal buddy-list updates correctly. The usercp.php?action=do_editlists delete handler removes the selected entry from the acting user's list and then updates mybb_users.buddylist for the target account. The reciprocal update searches for the deleted target UID instead of the acting user's UID and uses the unchecked array_search() return value as an array key. A false result can be converted to index 0, removing the target account's first stored buddy while leaving the actual reciprocal entry unchanged. The uniquely identifying implementation details include false converted to index 0. This issue is fixed in version 1.8.40.","cveId":"CVE-2026-47245","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-252"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/mybb/mybb/commit/0557718f27503034fb1c2768729a2fb8239bba65","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mybb/mybb/releases/tag/mybb_1840","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/mybb/mybb/security/advisories/GHSA-w8gm-j57p-jqpc","type":"advisory","title":"security-advisories@github.com"},{"url":"https://mybb.com/versions/1.8.40","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00366,"epssPercentile":0.28424,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-18T16:17:09.507Z","addedAt":"2026-08-18T17:50:27.643Z","updatedAt":"2026-09-08T21:50:36.546Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47245","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-47245","note":"authoritative record"}]},{"id":"2a652d40-3869-47ec-8efa-96a60ad706eb","slug":"cve-2026-62909","externalId":"CVE-2026-62909","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-62909 — Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.","description":"Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.","cveId":"CVE-2026-62909","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":"microsoft","product":"visual studio 2022","affectedVersions":[">= 17.14.0, < 17.14.38",">= 18.8.0, < 18.8.3",">= 8.0.0, < 8.0.30",">= 9.0.0, < 9.0.19",">= 10.0.0, < 10.0.11"],"cwes":["CWE-248","CWE-252"],"tags":["nvd","status:received","status:awaiting-analysis","status:undergoing-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62909"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62909","type":"patch","title":"Patch"}],"epssScore":0.00264,"epssPercentile":0.16763,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-08-11T17:18:44.817Z","addedAt":"2026-08-11T17:50:29.982Z","updatedAt":"2026-08-14T15:50:26.281Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62909","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-62909","note":"authoritative record"}]},{"id":"83dd5497-9d82-4145-91ba-1ae34870c0ac","slug":"cve-2026-26080","externalId":"CVE-2026-26080","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-26080 — HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled.","description":"HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.","cveId":"CVE-2026-26080","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","severity":"low","vendor":"haproxy","product":"haproxy","affectedVersions":[">= 3.2, < 3.2.12",">= 3.3, < 3.3.3",">= 17.0.0, < 17.0.18",">= 17.5.0, < 17.5.16","3.2r1"],"cwes":["CWE-252"],"tags":["msrc","vendor-advisory","microsoft","cve","nvd","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26080","https://git.haproxy.org/?p=haproxy-3.2.git;a=commit;h=5bb098ce8a656ec5711b4de3e4c87f12b216e7a1"],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26080","type":"vendor","title":"Microsoft MSRC: CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected."},{"url":"https://git.haproxy.org/?p=haproxy-3.2.git;a=commit;h=5bb098ce8a656ec5711b4de3e4c87f12b216e7a1","type":"patch","title":"Patch"},{"url":"https://www.haproxy.org/","type":"advisory","title":"Product"}],"epssScore":0.00546,"epssPercentile":0.44048,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-20T16:16:57.057Z","addedAt":"2026-07-29T20:52:59.960Z","updatedAt":"2026-08-25T15:50:31.650Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26080","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-26080","note":"authoritative record"}]},{"id":"5d4a461e-eccc-4ae0-bf56-709f99ac672d","slug":"cve-2026-64040","externalId":"CVE-2026-64040","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-64040 — In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Fix error return when vfs_mkdir() fails\n\nWhen vfs_mkdir() fails, t…","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Fix error return when vfs_mkdir() fails\n\nWhen vfs_mkdir() fails, the error code is not extracted from the\nreturned error pointer. This causes mkdir_error to be reached with\nret=0, which leads to returning ERR_PTR(0) (NULL) instead of a\nproper error pointer.\n\nFix this by extracting the error code from the error pointer when\nvfs_mkdir() fails.","cveId":"CVE-2026-64040","cvssScore":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","severity":"medium","vendor":"linux","product":"linux kernel","affectedVersions":[">= 6.15, < 7.0.11","7.1"],"cwes":["CWE-252"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://git.kernel.org/stable/c/0940108d27c6995e02819ff832be11892f0b208b","https://git.kernel.org/stable/c/8a220d1c312c66194f4a33dd52d1fba42bc2b341"],"references":[{"url":"https://git.kernel.org/stable/c/0940108d27c6995e02819ff832be11892f0b208b","type":"patch","title":"Patch"},{"url":"https://git.kernel.org/stable/c/8a220d1c312c66194f4a33dd52d1fba42bc2b341","type":"patch","title":"Patch"}],"epssScore":0.00143,"epssPercentile":0.03139,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-07-19T16:17:44.270Z","addedAt":"2026-07-30T15:34:42.865Z","updatedAt":"2026-10-06T20:39:29.159Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64040","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-64040","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":34,"totalPages":2,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:43:10.645Z","durationMs":48,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-252"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}