A vulnerability classified as critical was found in F5 BIG-IP. This affects an unknown function of the component Security Policy Handler. Executing a manipulation can lead to unchecked return value.
This vulnerability is registered as CVE-2026-40060. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
A vulnerability marked as critical has been reported in F5 BIG-IP. Affected by this vulnerability is an unknown functionality of the component iControl REST/TMOS Shell. The manipulation leads to least privilege violation.
This vulnerability is referenced as CVE-2026-39459. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability, which was classified as critical, was found in F5 BIG-IP. This issue affects some unknown processing of the component iControl REST Endpoint. Such manipulation leads to os command injection.
This vulnerability is traded as CVE-2026-34176. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability has been found in F5 BIG-IP and classified as critical. Impacted is an unknown function of the component Traffic Management Microkernel. Performing a manipulation results in uninitialized pointer.
This vulnerability is known as CVE-2026-39458. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
A vulnerability classified as critical has been found in F5 BIG-IP. The impacted element is an unknown function of the component LDAP. Performing a manipulation results in missing release of resource.
This vulnerability is cataloged as CVE-2026-39455. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability labeled as problematic has been found in F5 BIG-IP. Affected is an unknown function. Executing a manipulation can lead to incorrect privilege assignment.
The identification of this vulnerability is CVE-2026-35062. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability labeled as problematic has been found in F5 BIG-IP. This issue affects some unknown processing of the component iControl REST Endpoint. The manipulation results in path traversal: '.../...//'.
This vulnerability is identified as CVE-2026-24464. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability described as problematic has been identified in F5 BIG-IP. The affected element is an unknown function. Such manipulation leads to execution with unnecessary privileges.
This vulnerability is listed as CVE-2026-32673. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability categorized as problematic has been discovered in F5 BIG-IP. This affects an unknown function of the component iControl REST. Such manipulation of the argument ssh-password leads to cleartext storage of sensitive information.
This vulnerability is uniquely identified as CVE-2026-28758. Local access is required to approach this attack. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability identified as problematic has been detected in F5 BIG-IP and BIG-IQ. This impacts an unknown function. Performing a manipulation results in execution with unnecessary privileges.
This vulnerability was named CVE-2026-32643. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
A vulnerability described as problematic has been identified in GStreamer Good Plug-ins up to 1.28.1. Affected is the function qtdemux_parse_trak. Such manipulation leads to divide by zero.
This vulnerability is documented as CVE-2026-46469. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability classified as problematic has been found in GStreamer Good Plug-ins up to 1.28.1. Affected by this vulnerability is the function qtdemux_audio_caps. Performing a manipulation results in divide by zero.
This vulnerability is reported as CVE-2026-46470. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executing a manipulation of the argument KILO_CONFIG_CONTENT can lead to information disclosure.
This vulnerability is registered as CVE-2026-8766. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability marked as critical has been reported in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component File Diff API Endpoint. Performing a manipulation of the argument File results in path traversal.
This vulnerability is cataloged as CVE-2026-8765. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability labeled as critical has been found in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of the file /goform/aspForm. Such manipulation of the argument param leads to buffer overflow.
This vulnerability is listed as CVE-2026-8764. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.