{"success":true,"data":{"threats":[{"id":"be3fd0b6-b5a9-4ffb-9332-d748603925d0","slug":"cve-2026-84230","externalId":"CVE-2026-84230","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84230 — IBM Guardium Data Protection 12.2.2 could allow a remote attacker to cause a denial of service due to a race condition resulting from concurrent un…","description":"IBM Guardium Data Protection 12.2.2 could allow a remote attacker to cause a denial of service due to a race condition resulting from concurrent unsynchronized writes to a shared map.","cveId":"CVE-2026-84230","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362"],"tags":["nvd","status:received"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288627","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T22:17:33.727Z","addedAt":"2026-10-08T23:06:40.595Z","updatedAt":"2026-10-08T23:06:40.595Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84230","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84230","note":"authoritative record"}]},{"id":"bf0728c8-348b-4e5d-98d8-32a7b1942e85","slug":"cve-2026-84271","externalId":"CVE-2026-84271","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-84271 — IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer.","description":"IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer. An attacker with local access could exploit this vulnerability to execute arbitrary code with root privileges.","cveId":"CVE-2026-84271","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://www.ibm.com/support/pages/node/7288035","type":"advisory","title":"psirt@us.ibm.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T20:17:37.610Z","addedAt":"2026-10-08T21:05:53.557Z","updatedAt":"2026-10-08T21:05:53.557Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84271","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-84271","note":"authoritative record"}]},{"id":"fe7eee2d-d2c4-4985-a11e-348a4f1fd659","slug":"cve-2026-42698","externalId":"CVE-2026-42698","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-42698 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Themeum Tutor LMS tutor allows Leverag…","description":"Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Themeum Tutor LMS tutor allows Leveraging Race Conditions.This issue affects Tutor LMS: from n/a through 4.1.1.","cveId":"CVE-2026-42698","cvssScore":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362"],"tags":["nvd","status:received","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://patchstack.com/database/wordpress/plugin/tutor/vulnerability/wordpress-tutor-lms-plugin-4-1-1-race-condition-vulnerability?_s_id=cve","type":"advisory","title":"audit@patchstack.com"}],"epssScore":null,"epssPercentile":null,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T14:16:54.857Z","addedAt":"2026-10-08T14:40:02.976Z","updatedAt":"2026-10-08T18:39:31.428Z","epssUpdatedAt":null,"nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42698","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-42698","note":"authoritative record"}]},{"id":"48d59e2e-d0c6-4b70-b497-adacfb681b57","slug":"cve-2026-94584","externalId":"CVE-2026-94584","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94584 — A race condition and thread-safety vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1.","description":"A race condition and thread-safety vulnerability exists in the web management daemon of Brocade Fabric OS versions before 10.0.1. When handling user authentication requests across a multi-threaded execution pool, this race condition causes PAM modules to process stale or incorrect client IP addresses and switch context numbers. This leads to inaccurate audit records and potential access control bypasses where AAA evaluation or Calling-Station-ID ACL policies rely on client IP attributes.","cveId":"CVE-2026-94584","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39158","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00146,"epssPercentile":0.03341,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T04:18:00.600Z","addedAt":"2026-10-08T04:39:33.113Z","updatedAt":"2026-10-08T21:05:46.219Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94584","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94584","note":"authoritative record"}]},{"id":"2c0d69d5-2385-4567-abbe-d2fbd9b877f9","slug":"cve-2026-94583","externalId":"CVE-2026-94583","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-94583 — A race condition vulnerability exists in the request processing logic of the REST management interface on Brocade Fabric OS versions before 10.0.1.","description":"A race condition vulnerability exists in the request processing logic of the REST management interface on Brocade Fabric OS versions before 10.0.1. When handling concurrent incoming network management FCIP requests, a timing window exists between when a request populates the address variable and when the service constructs and returns the response context. As a result, the first request adopts the modified context, causing the service to return sensitive management details or configuration data belonging to the second context back to the original requester.","cveId":"CVE-2026-94583","cvssScore":2.1,"cvssVector":"CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://support.broadcom.com/external/content/SecurityAdvisories/0/39159","type":"advisory","title":"sirt@brocade.com"}],"epssScore":0.00109,"epssPercentile":0.01144,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-08T03:16:38.120Z","addedAt":"2026-10-08T04:39:32.997Z","updatedAt":"2026-10-08T21:05:45.825Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94583","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-94583","note":"authoritative record"}]},{"id":"626445f1-5b45-4076-b9ea-382a1c34b660","slug":"cve-2026-107276","externalId":"CVE-2026-107276","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-107276 — MISP contains a race condition in the email-based one-time password (OTP) login flow.","description":"MISP contains a race condition in the email-based one-time password (OTP) login flow. When two HTTP requests carrying the same valid OTP are submitted concurrently, both can successfully authenticate and establish a session. The root cause is that the OTP value is read from the shared store, validated, and then deleted in separate non-atomic steps, allowing a second in-flight request to read the same value before the first request's deletion takes effect.\n\nPreconditions:\n\n- The target MISP instance has email OTP login enabled.\n\n- The attacker possesses a valid, unexpired OTP (e.g., via email interception or social engineering).\n\n- The attacker can issue two HTTP POST requests in close temporal proximity.\n\nImpact:\n\n- The one-time-use guarantee of the OTP is violated; a single code can yield two authenticated sessions.\n\n- This weakens the authentication control and may facilitate unauthorized access if the OTP is shared or intercepted.\n\nAffected versions: <2.5.48","cveId":"CVE-2026-107276","cvssScore":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"medium","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362","CWE-367"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/MISP/MISP/commit/ba95e67d5","type":"advisory","title":"5a6e4751-2f3f-4070-9419-94fb35b644e8"}],"epssScore":0.00213,"epssPercentile":0.10634,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T16:17:47.213Z","addedAt":"2026-10-07T16:39:32.766Z","updatedAt":"2026-10-07T22:39:36.401Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107276","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-107276","note":"authoritative record"}]},{"id":"1bd31109-3603-4fc3-af65-5ab728935bd6","slug":"cve-2026-105140","externalId":"CVE-2026-105140","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105140 — Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships ju…","description":"Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships just revoked in the identity provider. When overlapping refreshes for the same user commit out of order, stale memberships are persisted and the user retains revoked group-based access for about ten minutes.","cveId":"CVE-2026-105140","cvssScore":2.3,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"low","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/obot-platform/obot","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/group.go#L652-L734","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/blob/2d2aaca9dc9b26777f8a2d213e0e1ec47f47508e/pkg/gateway/client/identity.go#L444-L456","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/blob/6f81dac8d344cf6b2161f500460fb7b2a975c415/pkg/gateway/client/group.go#L741-L757","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/commit/09e4d5b5d1e4a5f35a6cbcff96f3c460c3f9e278","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/commit/6f81dac8d344cf6b2161f500460fb7b2a975c415","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/releases/tag/v0.26.1","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://github.com/obot-platform/obot/security/advisories/GHSA-929v-v9hq-5xhr","type":"advisory","title":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/obot-0.25.0-before-0.25.6-and-0.26.0-before-0.26.1-race-condition-restores-revoked-group-membership","type":"advisory","title":"disclosure@vulncheck.com"}],"epssScore":0.00179,"epssPercentile":0.06815,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-07T13:17:19.590Z","addedAt":"2026-10-07T14:39:35.095Z","updatedAt":"2026-10-07T22:39:36.328Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105140","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105140","note":"authoritative record"}]},{"id":"04492aec-2a6c-49e6-9586-fe65ffc31997","slug":"cve-2026-106500","externalId":"CVE-2026-106500","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106500 — Backstage is an open framework for building developer portals.","description":"Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated user with permission to create and access Scaffolder tasks may, under specific timing and deployment conditions, affect files accessible to the Backstage backend. If backend application files are writable, the confidentiality, integrity, and availability of the backend may be compromised. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.","cveId":"CVE-2026-106500","cvssScore":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","severity":"high","vendor":"npm","product":"@backstage/plugin-scaffolder-backend","affectedVersions":["pkg:npm/%40backstage/plugin-scaffolder-backend < 4.1.0"],"cwes":["CWE-59","CWE-362"],"tags":["nvd","status:received","status:awaiting-analysis","osv","osv:ghsa-xvgh-hmx8-9xxf","ecosystem:npm"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/backstage/backstage/commit/0d24f1b8701f3dde6cd597f81997c1ea873a43ae","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/56be299dd3ef6706e13e76ea2f8a9b0dd0b6413d","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/commit/9e86c95a1a3ddfd54db03731cd8678aa63495175","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.49.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.50.5","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.6","type":"other","title":"OSV web"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-xvgh-hmx8-9xxf","type":"other","title":"OSV web"},{"url":"https://osv.dev/vulnerability/GHSA-xvgh-hmx8-9xxf","type":"advisory","title":"OSV GHSA-xvgh-hmx8-9xxf"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106500","type":"advisory","title":"OSV advisory"},{"url":"https://github.com/backstage/backstage","type":"vendor","title":"OSV package"}],"epssScore":0.00328,"epssPercentile":0.23914,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T22:17:05.060Z","addedAt":"2026-10-06T22:39:33.197Z","updatedAt":"2026-10-07T18:42:42.572Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106500","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106500","note":"authoritative record"},{"label":"OSV","url":"https://osv.dev/vulnerability/GHSA-XVGH-HMX8-9XXF"}]},{"id":"a5569da5-6032-4f8b-a599-43174bfe0fc0","slug":"cve-2026-56906","externalId":"CVE-2026-56906","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-56906 — In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition.","description":"In ep_free of eventpoll.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-56906","cvssScore":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://source.android.com/docs/security/bulletin/pixel/2026/2026-10-01","type":"advisory","title":"dsap-vuln-management@google.com"}],"epssScore":0.00054,"epssPercentile":0.00002,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:14.920Z","addedAt":"2026-10-06T20:39:32.496Z","updatedAt":"2026-10-07T04:39:33.911Z","epssUpdatedAt":"2026-10-07T12:00:27.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56906","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-56906","note":"authoritative record"}]},{"id":"004ffeb9-3faa-4279-ab7a-e1a1e59c470d","slug":"cve-2026-106426","externalId":"CVE-2026-106426","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106426 — Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox…","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106426","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-362"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/547065823","type":"advisory","title":"Permissions Required"}],"epssScore":0.00236,"epssPercentile":0.13406,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:12.483Z","addedAt":"2026-10-06T20:39:32.401Z","updatedAt":"2026-10-07T14:39:33.729Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106426","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106426","note":"authoritative record"}]},{"id":"9f956aed-dbdd-4acc-afa2-90e3d7d4104a","slug":"cve-2026-106385","externalId":"CVE-2026-106385","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106385 — Race condition in Chromoting in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially bypass …","description":"Race condition in Chromoting in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to potentially bypass system access restrictions via crafted network traffic. (Chromium security severity: Low)","cveId":"CVE-2026-106385","cvssScore":null,"cvssVector":null,"severity":"unknown","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362"],"tags":["nvd","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"advisory","title":"chrome-cve-admin@google.com"},{"url":"https://issues.chromium.org/issues/554874487","type":"advisory","title":"chrome-cve-admin@google.com"}],"epssScore":0.0014,"epssPercentile":0.02858,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:07.740Z","addedAt":"2026-10-06T20:39:32.090Z","updatedAt":"2026-10-06T20:39:32.090Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106385","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106385","note":"authoritative record"}]},{"id":"30fd7b4c-fcb7-42e6-a0e0-f87f5cdef9b9","slug":"cve-2026-106377","externalId":"CVE-2026-106377","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106377 — Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbit…","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106377","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-362"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/520179149","type":"advisory","title":"Permissions Required"}],"epssScore":0.00258,"epssPercentile":0.16034,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:18:06.853Z","addedAt":"2026-10-06T20:39:32.028Z","updatedAt":"2026-10-07T14:39:33.412Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106377","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106377","note":"authoritative record"}]},{"id":"d73e8c71-7393-443e-9ef4-19c0e5952f14","slug":"cve-2026-106255","externalId":"CVE-2026-106255","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106255 — Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via…","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)","cveId":"CVE-2026-106255","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-362"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/559780376","type":"advisory","title":"Permissions Required"}],"epssScore":0.00242,"epssPercentile":0.14089,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:52.640Z","addedAt":"2026-10-06T20:39:31.064Z","updatedAt":"2026-10-07T14:39:32.821Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106255","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106255","note":"authoritative record"}]},{"id":"a6ca1fed-62c9-4c81-8c4a-8ceb299b9ed4","slug":"cve-2026-106238","externalId":"CVE-2026-106238","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106238 — Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially e…","description":"Race condition in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106238","cvssScore":8.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-362"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/492374387","type":"advisory","title":"Permissions Required"}],"epssScore":0.00296,"epssPercentile":0.20428,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:50.690Z","addedAt":"2026-10-06T20:39:30.926Z","updatedAt":"2026-10-07T14:39:32.645Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106238","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106238","note":"authoritative record"}]},{"id":"b01e18eb-9210-4a8b-b22e-bc0fff37e0aa","slug":"cve-2026-106213","externalId":"CVE-2026-106213","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106213 — Race condition in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HT…","description":"Race condition in WebAudio in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106213","cvssScore":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","severity":"medium","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-362"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/520153320","type":"advisory","title":"Permissions Required"}],"epssScore":0.00183,"epssPercentile":0.07218,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:47.777Z","addedAt":"2026-10-06T20:39:30.741Z","updatedAt":"2026-10-08T14:40:01.907Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106213","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106213","note":"authoritative record"}]},{"id":"8e30cb82-cc1f-4f4e-ac46-d266dc556b09","slug":"cve-2026-106201","externalId":"CVE-2026-106201","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-106201 — Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted H…","description":"Race condition in V8 in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)","cveId":"CVE-2026-106201","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"chrome","affectedVersions":["< 155.0.8059.39"],"cwes":["CWE-362"],"tags":["nvd","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","type":"vendor","title":"Release Notes"},{"url":"https://issues.chromium.org/issues/517546096","type":"advisory","title":"Exploit"}],"epssScore":0.00268,"epssPercentile":0.17358,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-06T19:17:46.370Z","addedAt":"2026-10-06T20:39:30.644Z","updatedAt":"2026-10-08T12:39:40.965Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106201","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-106201","note":"authoritative record"}]},{"id":"de6334f9-b19d-4004-873b-21b3a821685f","slug":"cve-2026-105773","externalId":"CVE-2026-105773","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-105773 — Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability in the Privileged Helper Tool caused by a race co…","description":"Canimaan Software ClamXAV versions 3.3 - 3.11 contains a local privilege escalation vulnerability in the Privileged Helper Tool caused by a race condition and insufficient file validation, allowing a local attacker to execute arbitrary code with system privileges. Fixed in 3.11.1.","cveId":"CVE-2026-105773","cvssScore":7.3,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362"],"tags":["nvd","status:received","status:awaiting-analysis"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://clamxav.com/version-history","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-278-01.json","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-105773","type":"advisory","title":"9119a7d8-5eab-497f-8521-727c672e3725"}],"epssScore":0.00136,"epssPercentile":0.02576,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T21:16:36.093Z","addedAt":"2026-10-05T21:50:41.200Z","updatedAt":"2026-10-06T15:50:58.706Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105773","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-105773","note":"authoritative record"}]},{"id":"a8201758-0352-4ccc-bf21-8adea23def70","slug":"cve-2026-58880","externalId":"CVE-2026-58880","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-58880 — In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition.","description":"In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.","cveId":"CVE-2026-58880","cvssScore":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"google","product":"android","affectedVersions":["16.0","17.0"],"cwes":["CWE-362"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":true,"patchLinks":["https://source.android.com/docs/security/bulletin/2026/2026-10-01"],"references":[{"url":"https://source.android.com/docs/security/bulletin/2026/2026-10-01","type":"patch","title":"Patch"}],"epssScore":0.00071,"epssPercentile":0.00046,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:25.377Z","addedAt":"2026-10-05T19:50:42.986Z","updatedAt":"2026-10-07T16:39:30.480Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58880","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-58880","note":"authoritative record"}]},{"id":"e1f1d368-13b0-49ec-861d-b70ca3f3a251","slug":"cve-2026-104714","externalId":"CVE-2026-104714","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104714 — Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts.","description":"Concurrent execution using shared resource with improper synchronization ('race condition') vulnerability in Apache Struts. Where a localized message formats a date or time argument, the formatter retained for that message by the application-wide text provider is used by concurrently served requests without isolation, so a value belonging to one user can appear in another user's response, or the rendering can fail and surface as a server error. Applications whose localized messages format no date or time arguments are not affected.\n\nThis issue affects Apache Struts: from 2.0.0 through 2.3.37, from 2.5.0 through 2.5.33, from 6.0.0 through 6.11.0, from 7.0.0 through 7.3.0.\n\nUsers are recommended to upgrade to version 6.12.0 or 7.4.0, which fixes the issue.","cveId":"CVE-2026-104714","cvssScore":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":"apache","product":"struts","affectedVersions":[">= 2.0.0, <= 2.3.37",">= 2.5.0, <= 2.5.33",">= 6.0.0, < 6.12.0",">= 7.0.0, < 7.4.0"],"cwes":["CWE-362"],"tags":["nvd","status:received","status:awaiting-analysis","status:analyzed"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://cwiki.apache.org/confluence/display/WW/S2-078","type":"vendor","title":"Vendor Advisory"},{"url":"http://www.openwall.com/lists/oss-security/2026/10/05/13","type":"advisory","title":"Mailing List"}],"epssScore":0.00489,"epssPercentile":0.40156,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T19:17:14.883Z","addedAt":"2026-10-05T19:50:42.744Z","updatedAt":"2026-10-08T19:33:16.452Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104714","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104714","note":"authoritative record"}]},{"id":"4b1d7720-0973-42ce-ae64-86faa65bc890","slug":"cve-2026-104970","externalId":"CVE-2026-104970","source":"NVD","sourceType":"cve-db","type":"vulnerability","title":"CVE-2026-104970 — Plane is an open-source project management tool.","description":"Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs account creation without an atomic transaction, row lock, uniqueness guard, or advisory lock. Two concurrent unauthenticated requests with different email addresses can both observe that no instance administrator exists, create separate User and InstanceAdmin rows, and receive sessions with instance-admin authority. This allows an attacker to share unrestricted instance administration with the legitimate operator. This issue is fixed in 1.4.0.","cveId":"CVE-2026-104970","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","severity":"high","vendor":null,"product":null,"affectedVersions":[],"cwes":["CWE-362"],"tags":["nvd","status:deferred"],"relatedCves":[],"titleFingerprint":null,"countryCodes":[],"knownExploited":false,"patchAvailable":false,"patchLinks":[],"references":[{"url":"https://github.com/makeplane/plane/commit/7fbf14a6cb494bbf5866e2b293b28a6d8a7e52c3","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/pull/9332","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/releases/tag/v1.4.0","type":"advisory","title":"security-advisories@github.com"},{"url":"https://github.com/makeplane/plane/security/advisories/GHSA-p548-28jp-wr4p","type":"advisory","title":"security-advisories@github.com"}],"epssScore":0.00265,"epssPercentile":0.16868,"nucleiTemplatePath":null,"nucleiSeverity":null,"enrichment":null,"publishedAt":"2026-10-05T17:17:12.937Z","addedAt":"2026-10-05T17:50:43.047Z","updatedAt":"2026-10-06T15:50:57.829Z","epssUpdatedAt":"2026-10-08T12:00:21.000Z","nucleiUpdatedAt":null,"links":[{"label":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104970","note":"ingested from NVD"},{"label":"CVE Program","url":"https://www.cve.org/CVERecord?id=CVE-2026-104970","note":"authoritative record"}]}],"pagination":{"page":1,"limit":20,"total":636,"totalPages":32,"hasNext":true,"hasPrev":false}},"meta":{"apiVersion":"v1","requestedAt":"2026-10-08T23:17:23.010Z","durationMs":42,"filters":{"search":null,"severity":[],"type":[],"country":[],"tag":[],"cwe":["CWE-362"],"vendor":null,"product":null,"cve":null,"source":[],"days":null,"publishedAfter":null,"publishedBefore":null,"minCvss":null,"maxCvss":null,"minEpss":null,"knownExploited":null,"hasPatch":null,"hasNucleiTemplate":null},"sort":"newest","unknownParams":[],"warnings":[]}}