Posts of last 24 hours
A vulnerability identified as critical has been detected in Linux Kernel up to 7.1.2/7.2. Affected is the function copy_to_user of the component NTFS. This manipulation of the argument volume_label causes use after free.
This vulnerability is tracked as CVE-2026-63793. The attack is restricted to local execution. No exploit exists.
You should upgrade the affected component.
https://vuldb.com/vuln/380138
A vulnerability marked as very critical has been reported in Linux Kernel up to 6.6.143/6.12.94/6.18.37/7.1.2. Affected by this issue is the function rpmsg_chrdev_probe of the component Rpmsg Char. Performing a manipulation results in use after free.
This vulnerability is cataloged as CVE-2026-63797. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/380140
A vulnerability was found in Linux Kernel up to 7.1.2. It has been declared as very critical. The impacted element is the function sev_dbg_crypt of the component Kvm Svm. Executing a manipulation of the argument len can lead to use after free.
The identification of this vulnerability is CVE-2026-63794. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/380135
A vulnerability categorized as critical has been discovered in Linux Kernel up to 7.1.2. This impacts the function fb_new_modelist of the component Fbdev. The manipulation of the argument var results in null pointer dereference.
This vulnerability is identified as CVE-2026-53403. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/380137
A vulnerability was found in Linux Kernel up to 7.1.2. It has been rated as very critical. This affects the function ocfs2_validate_gd_parent of the file fs/ocfs2/suballoc.c of the component Ocfs2. The manipulation of the argument bg_size/bg_bits leads to use after free.
This vulnerability is referenced as CVE-2026-63796. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/380136
A vulnerability labeled as very critical has been found in Linux Kernel up to 6.1.176/6.6.143/6.12.94/6.18.37/7.1.2. Affected by this vulnerability is the function p9_client_walk of the component 9p Client. Such manipulation of the argument clone leads to use after free.
This vulnerability is listed as CVE-2026-63795. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
https://vuldb.com/vuln/380139
A vulnerability was found in Linux Kernel up to 6.12.95/6.18.38/7.1.2/7.2 and classified as problematic. Impacted is the function fbcon_do_set_font of the file drivers/video/fbcon.c of the component Fbcon. Such manipulation of the argument vc_hi_font_mask leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-53402. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/380133
A vulnerability was found in aio-libs aiohttp up to 3.13.x. It has been declared as problematic. This vulnerability affects the function CookieJar.load. The manipulation results in deserialization.
This vulnerability is reported as CVE-2026-34993. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/368053
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/
TP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as CVE-2026-12935, could allow unauthenticated attackers to trigger a denial-of-service condition or achieve remote code execution on vulnerable devices under certain circumstances. The issue lies within the router’s RTSP connection tracking (conntrack) feature. RTSP, or Real-Time […]
The post TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks appeared first on Cyber Security News.
https://cybersecuritynews.com/tp-link-rce-vulnerability/