Aggregator
Red Hat security advisory (AV26-531)
3 weeks 1 day ago
Canadian Centre for Cyber Security
CVE-2026-10157 | Open5GS up to 2.7.6 NGAP PathSwitchRequest Message src/amf/ngap-handler.c improper authentication (Issue 4393 / EUVD-2026-33476)
3 weeks 1 day ago
A vulnerability was found in Open5GS up to 2.7.6. It has been rated as critical. This impacts an unknown function of the file src/amf/ngap-handler.c of the component NGAP PathSwitchRequest Message Handler. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2026-10157. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is suggested to install a patch to address this issue.
vuldb.com
[Control systems] CISA ICS security advisories (AV26–530)
3 weeks 1 day ago
Canadian Centre for Cyber Security
Ubuntu security advisory (AV26-529)
3 weeks 1 day ago
Canadian Centre for Cyber Security
Investigating suspicious AI workflows in Microsoft Entra Agent ID: Agent’s user account
3 weeks 1 day ago
Entra ID agent users can send malicious content to human users via Microsoft Teams. Here’s what to look out for.
Matt Graeber
Dell security advisory (AV26-528)
3 weeks 1 day ago
Canadian Centre for Cyber Security
Infosecurity Europe: Tabletop Exercise to Test How CISOs Respond to Major Supermarket Cyber-Attack
3 weeks 1 day ago
Semperis is set to bring ‘Enter the War Room: A Tabletop Experience’ to Infosecurity Europe to help cybersecurity leaders prepare to face real incidents
CVE-2026-46174 | Linux Kernel up to 7.1-rc3 x86 privilege escalation (EUVD-2026-32801 / Nessus ID 317933)
3 weeks 1 day ago
A vulnerability identified as critical has been detected in Linux Kernel up to 7.1-rc3. Affected by this vulnerability is an unknown functionality of the component x86. The manipulation leads to privilege escalation.
This vulnerability is documented as CVE-2026-46174. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-8716 | GitLab Community Edition/Enterprise Edition up to 18.10.6/18.11.3/19.0.0 name resolution (EUVD-2026-32617 / Nessus ID 317942)
3 weeks 1 day ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.10.6/18.11.3/19.0.0. It has been rated as problematic. This issue affects some unknown processing. Performing a manipulation results in incorrectly-resolved name.
This vulnerability was named CVE-2026-8716. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-9807 | GitLab Community Edition/Enterprise Edition up to 18.10.6/18.11.3/19.0.0 Access Token authorization (Nessus ID 317940 / WID-SEC-2026-1727)
3 weeks 1 day ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.10.6/18.11.3/19.0.0. It has been classified as problematic. This impacts an unknown function of the component Access Token Handler. The manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2026-9807. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-47104 | libusb up to 1.0.29 descriptor.c parse_iad_array out-of-bounds (ID 1813 / Nessus ID 317946)
3 weeks 1 day ago
A vulnerability was found in libusb up to 1.0.29. It has been rated as problematic. Affected is the function parse_iad_array of the file descriptor.c. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-47104. The attack requires a local approach. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-2601 | GitLab Enterprise Edition up to 18.10.6/18.11.3/19.0.0 authorization (EUVD-2026-32621 / Nessus ID 317947)
3 weeks 1 day ago
A vulnerability, which was classified as problematic, was found in GitLab Enterprise Edition up to 18.10.6/18.11.3/19.0.0. Affected is an unknown function. Executing a manipulation can lead to missing authorization.
This vulnerability appears as CVE-2026-2601. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-9759 | Wireshark up to 4.4.15/4.6.5 ROHC Protocol Dissector null pointer dereference (EUVD-2026-32629 / Nessus ID 317943)
3 weeks 1 day ago
A vulnerability identified as problematic has been detected in Wireshark up to 4.4.15/4.6.5. The affected element is an unknown function of the component ROHC Protocol Dissector. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-9759. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-47760 | TinyMCE up to 7.0.x cross site scripting (GHSA-mh5m-5hw4-5c69 / Nessus ID 317945)
3 weeks 1 day ago
A vulnerability described as problematic has been identified in TinyMCE up to 7.0.x. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-47760. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-44465 | zed-industries zed up to 0.227.0 os command injection (GHSA-fj2r-rmw6-h222 / Nessus ID 317948)
3 weeks 1 day ago
A vulnerability was found in zed-industries zed up to 0.227.0 and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to os command injection.
This vulnerability is registered as CVE-2026-44465. The attack needs to be launched locally. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-6713 | GitLab Community Edition/Enterprise Edition up to 18.10.6/18.11.3/19.0.0 Private Project authorization (EUVD-2026-32618 / Nessus ID 317949)
3 weeks 1 day ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.10.6/18.11.3/19.0.0. It has been declared as problematic. This vulnerability affects unknown code of the component Private Project Handler. Such manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2026-6713. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts
3 weeks 1 day ago
pretalx XSS flaw lets attackers hijack conference organizer accounts, steal sessions, auto-accept talks, and demote admins. Patched in v2026.1.0.
Deeba Ahmed
IBM security advisory (AV26-527)
3 weeks 1 day ago
Canadian Centre for Cyber Security
Искали советские бомбы, а нашли далекие галактики. Как американские военные спутники случайно открыли гамма-всплески
3 weeks 1 day ago
Военные спутники США случайно открыли самые мощные взрывы во Вселенной.