2026-08-19
2026-08-19 22:17Z
HIGH

CVE-2026-76316 — Splunk: The SPL injection is possible because Deployment Server client identifiers are placed into dispatched

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76316

In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the Splunk management port could store a Search Processing Language (SPL) pipeline that runs when an administrator opens the Add Data forwarder workflow. The SPL pipeline could access all relevant data, affect system integrity, and affect availability of the Splunk platform instance. The SPL injection is possible because Deployment Server client identifiers are placed CVSSv3.1 8.8 (HIGH)

CWECWE 943VNDSplunkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 22:17Z
HIGH

CVE-2026-76315 — Splunk: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76315

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could execute arbitrary code on the Splunk platform instance through Splunk Web Manager Configuration. The user could then access all relevant data and affect system integrity and availability on the Splunk platform instance. The vulnerability is possible because Splunk Web Manager Configuration evaluates manager configuration values, and the Re CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDSplunkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 22:17Z
HIGH

CVE-2026-76314 — Splunk: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76314

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by submitting crafted Splunk Web Manager Configuration content. The user could then access all relevant data and affect system integrity and availability. The vulnerability is possible because Splunk Web evaluates manager Extensible Markup Language expressions without sufficient input restrictions, and t CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDSplunkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 22:17Z
HIGH

CVE-2026-76313 — Splunk: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76313

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by distributed search, which can allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Representational State Transfer (REST) API endpoint for knowledge bundle uploa CVSSv3.1 8.8 (HIGH)

CWECWE 284VNDSplunkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 22:17Z
CRIT

CVE-2026-76312 — Splunk: In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76312

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) source of a page that embeds a Splunk report could use exposed session material to access all relevant data and affect system integrity. The vulnerability is possible because the dispatch archive download path does not correctly enforce the embedded-report authorization boundary and includes sensitive session material in archived se CVSSv3.1 9.4 (CRITICAL)

CWECWE 284VNDSplunkTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-19
2026-08-19 22:17Z
CRIT

CVE-2026-76311 — Splunk: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76311

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the dispatch archive for an embedded report search job and use exposed session material to access all relevant data and affect system integrity on the Splunk platform instance. The vulnerability is possible because the embedded report authorization flow does not block dispatch archive download requests before Splunk Enterprise begins CVSSv3.1 9.4 (CRITICAL)

CWECWE 284VNDSplunkTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
2026-08-19
2026-08-19 22:17Z
CRIT

CVE-2026-76310 — Splunk: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76310

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the associated search job dispatch archive, recover session material, and use it to access all relevant data available to the report owner and affect system integrity, including by performing administrative actions when the owner holds the "admin" Splunk role. The vulnerability is possible because embedded report access does not block CVSSv3.1 9.4 (CRITICAL)

CWECWE 284VNDSplunkTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-19
2026-08-19 22:17Z
HIGH

CVE-2026-76259 — Splunk: In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76259

In Splunk Enterprise for Windows versions below 10.4.2, 10.2.6, 10.0.9, 9.4.13, and 9.3.14, a local user with access to the Windows host could bind to the management port before Splunk Enterprise starts, intercept authentication tokens from child processes, and use those tokens to compromise all relevant data and system integrity available to the user account running Splunk Enterprise. The vulnerability is possible because the Windows management-port listener does not apply e CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDSplunkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 22:17Z
HIGH

CVE-2026-76253 — Splunk: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76253

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitrary Search Processing Language (SPL) commands with the highest level of system privilege and read every credential stored in the credential store, which can allow for disclosure and modification of all relevant data and affect system integrity and availability. The vulnerability is possible because scheduled search alert action c CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDSplunkTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 22:00Z
HIGH

Defeating AI-Assisted Reverse Engineering (or at Least Trying To)

Quarkslab·blog.quarkslab.com

Quarkslab conducted a multi-week empirical study on whether LLM-assisted reverse engineering defeats obfuscation by deploying Claude Code agents against progressively hardened AArch64 binaries. The agents consistently routed around static protections via dynamic analysis and emulation, but also hallucinated plausible-sounding results and exploited sandbox conveniences; the research concludes that obfuscation remains a cost multiplier but must be paired with runtime application self-protection (RASP) and environment-binding to resist autonomous agents.

SRFApplicationTACTA0005TYPResearchSTGDefense EvasionTECT1140TECT1027TECT1600
82
Edit Score
2026-08-19
2026-08-19 21:17Z
CRIT

CVE-2026-76584 — The manipulation of the argument Currenttime results in stack-based buffer overflow.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76584

A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin/set_time.cgi of the component alphapd. The manipulation of the argument Currenttime results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. CVSSv3.1 9.9 (CRITICAL)

CWECWE 121CWECWE 119TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-08-19
2026-08-19 21:17Z
HIGH

CVE-2026-76139 — A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76139

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as GitHub access tokens and registry passwords, used in the build environment. A remote attacker could exploit this vulnerability to inject malicious code, leading to unauthorized access to build resources and potential compromise of the resulting CVSSv3.1 8.0 (HIGH)

CWECWE 829TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-08-19
2026-08-19 21:16Z
CRIT

CVE-2026-53548 — Termix: Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user's numeric

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53548

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user's numeric host ID and the field=password or field=sudoPassword query without enforcing host ownership during credential resolution. A failed requester-scoped lookup can resolve the host with the owner's context and return the owner's plainte CVSSv3.1 9.6 (CRITICAL)

CWECWE 639CWECWE 285VNDTermixTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-19
2026-08-19 21:16Z
HIGH

CVE-2026-53547 — Termix: Successful exploitation results in local-user account takeover and administrative compromise when the victim is

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53547

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /database/export endpoint creates a user export that includes the global settings table even though the rest of the export is user-scoped. The settings table contains reset_code_ and temp_reset_token_ password-reset artifacts, allowing a low-privileged authenticated user to recover another local account's reset code and complete the normal pas CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDTermixTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 21:16Z
CRIT

CVE-2026-53546 — Termix: Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/backend/ssh/host-resolver.ts resolves that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53546

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/backend/ssh/host-resolver.ts resolves that host without requiring ownership or explicit access. When no credential is shared with the requester, resolveHostById performs an owner credential fallback, and src/backend/ssh/terminal.ts combines that credential with attacker-controlled i CVSSv3.1 9.6 (CRITICAL)

CWECWE 862CWECWE 639VNDTermixTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-08-19
2026-08-19 21:16Z
CRIT

CVE-2026-53545 — Termix: Prior to 2.3.2, the DELETE /ssh/tunnel/disconnect/:tunnelName teardown path in src/backend/ssh/tunnel.ts interpolates endpointPort, sourcePort, endpointUsername

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53545

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/disconnect/:tunnelName teardown path in src/backend/ssh/tunnel.ts interpolates endpointPort, sourcePort, endpointUsername, and endpointIP into single-quoted pkill -f patterns. An authenticated user who can edit a tunnel host field can include a single quote to terminate the pattern and append a shell command, which executes when CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDTermixTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-19
2026-08-19 21:16Z
HIGH

CVE-2026-53542 — Termix: The resulting checkpoint action executes commands on the managed SSH host with the privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53542

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the archive creation endpoint in src/backend/ssh/file-manager.ts passes selected file basenames to tar without an end-of-options marker and without making the operands unambiguously relative. A user with access to an SSH file-manager session can select basenames beginning with GNU tar options such as --checkpoint=1 and --checkpoint-action=exec, causing CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDTermixTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 21:16Z
HIGH

CVE-2026-18544 — IBM: Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18544

IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references. CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDIbmTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 21:16Z
HIGH

CVE-2026-12633 — IPv6: This produces an unbounded out-of-bounds memset that zeroes kernel memory well past the 6lo

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12633

The IPv6 neighbor-discovery code in subsys/net/ip/ipv6_nbr.c processes the 6LoWPAN Context Option (6CO, RFC 6775) carried inside ICMPv6 Router Advertisements. In handle_ra_6co() the 8-bit context_len field is taken directly from the packet and was never bounded to the RFC maximum of 128. The function computes context->context_len / 8 and then performs memset(context->prefix + context_len, 0, sizeof(context->prefix) - context_len), where context->prefix is a fixed 16-byte arra CVSSv3.1 8.1 (HIGH)

CWECWE 787VNDIpv6TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-08-19
2026-08-19 21:16Z
HIGH

CVE-2026-12522 — HL7800: A malicious or impersonated cellular network (for example a rogue base station) can return

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12522

The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_standalone/hl7800.c parses the PDP-context dynamic parameters (local address, subnet mask, gateway, and DNS servers) that the cellular network assigns to the device. The response is linearized into a 256-byte stack buffer, after which each address field length is computed from comma/. delimiter positions in the network-supplied data and used directly as the length CVSSv3.1 8.8 (HIGH)

CWECWE 787VNDHl7800TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-76647 — Leantime: JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76647

Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php. The dispatcher does not enforce authorization before invoking service-layer methods, allowing an authenticated user to call methods or act on resources outside their intended permissions. For example, the editOwn method accepts a user-supplied user ID without verifying that it belongs to the caller, allowing an attack CVSSv3.1 8.8 (HIGH) · EPSS 6th percentile

CWECWE 862CWECWE 639CWECWE 200VNDLeantimeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-68899 — Wekan: On deployments with WITH_API=true and no file binary, an authenticated board member could label

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68899

Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was unavailable and the validation fell back to the attacker-controlled fileObj.type supplied through server/routes/attachmentApi.js. On deployments with WITH_API=true and no file binary, an authenticated board member could label HTML containing CVSSv3.1 8.7 (HIGH)

CWECWE 434VNDWekanTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-68561 — Wekan: Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68561

Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldNames included sort. Because Meteor combines allow rules with OR semantics and applies the complete modifier, a comment-only or read-only member could send one Boards.update with $set values for sort, members, permission, and title, make themselve CVSSv3.1 8.8 (HIGH)

CWECWE 269CWECWE 863VNDWekanTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-08-19
2026-08-19 20:17Z
HIGH

CVE-2026-68558 — Wekan: is open source kanban built with Meteor.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-68558

Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked only the literal URL.hostname against regular expressions, so DNS names such as 169-254-169-254.nip.io passed that first-line check. The delivery path's fetchSafe guard already blocked the reported IPv4 destination, but its separate IPv4-only resolver and duplicated blocklist created inconsistent all-address-family enforcement a CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDWekanTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-08-19
2026-08-19 20:17Z
CRIT

CVE-2026-63722 — ICEcoder: 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-63722

ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP POST request to the terminal endpoint with a password parameter to bypass authentication, a non-empty csrf parameter to skip CSRF validation, and an arbitrary command string passed directly to proc_open CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDIcecoderTYPVulnerability
9.8
CVSS v3.1
99
Edit Score