5d ago
2026-09-09 01:16Z
HIGH

CVE-2026-87430 — Buffer: overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-87430

Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low) CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDBufferTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-09 00:47Z
CRIT

LSPromise — Android complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination

GitHub · LPE exploits·github.comGITHUB POCCVE-2026-49881CVE-2026-432840day

LSPromise is a complete Android privilege escalation exploit chain combining a 0-day logic bug in Android 17's Telecom service (CVE-2026-49881) with the DirtyFrag kernel vulnerability (CVE-2026-43284). The chain achieves arbitrary code execution in system_server via a malicious AppComponentFactory, then pivots through the network stack to exploit DirtyFrag for kernel-level code execution and SELinux bypass, ultimately achieving root access with 100% success rate on vulnerable devices.

SRFOsTACTA0004TACTA0005OSAndroidTYPExploitSTGPrivescSTGExecutionTECT1548
95
Edit Score
5d ago
2026-09-09 00:17Z
CRIT

CVE-2026-53939 — In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53939

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). In versions 0.6.1 through 0.6.2.5, when cjose encrypts a JWE using an AES-CBC-HMAC content-encryption algorithm (`A128CBC-HS256`, `A192CBC-HS384`, or `A256CBC-HS512`) together with any key-management algorithm that generates a fresh content-encryption key (CEK), the CEK is all zero bytes instead of being randomly generated. The resulting JWE is therefore encrypted and authenticated CVSSv3.1 9.1 (CRITICAL)

CWECWE 330CWECWE 321TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
5d ago
2026-09-09 00:17Z
HIGH

CVE-2026-53938 — A remote, unauthenticated attacker who can submit a crafted JWE to an application that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53938

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`alg` = `A128KW`, `A192KW`, `A256KW`) does not validate the length of the attacker-supplied `encrypted_key` (JWE Encrypted Key) before unwrapping it into a fixed-size, heap-allocated Content Encryption Key (CEK) buffer. A remote, unauthenticated attacker who can submit a crafted JWE CVSSv3.1 8.2 (HIGH)

CWECWE 787CWECWE 122TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 23:17Z
CRIT

CVE-2026-53581 — OPNsense: Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-53581

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration module allows an attacker to overwrite arbitrary files on the system as the root user. By manipulating the GPS or PPS serial port parameter, an attacker with access to the NTP configuration can escape the intended directory and force the system to write user-controlled data to any f CVSSv3.1 9.0 (CRITICAL)

CWECWE 22CWECWE 73VNDOpnsenseTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
5d ago
2026-09-08 22:19Z
HIGH

CVE-2026-86083 — N8n N8n: is an open source workflow automation platform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86083

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and interpolating timezone data. An expression could replace JSON.stringify and cause later generated source to contain executable attacker-controlled code. The affected code-generation paths include packages/@n8n/expression-runtime/src/bridge/isolated CVSSv3.1 8.8 (HIGH) · EPSS 20th percentile

CWECWE 94VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 22:19Z
HIGH

CVE-2026-86076 — N8n N8n: is an open source workflow automation platform.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86076

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named __sanitize could rebind the sanitizer and reach the Function constructor, enabling backend code execution and editor-preview JavaScript execution. The affected AST hook is PrototypeSanitizer in packages/workflow/src/expression-sandboxing.ts. This CVSSv3.1 8.8 (HIGH) · EPSS 26th percentile

CWECWE 94VNDN8nTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
5d ago
2026-09-08 21:18Z
CRIT

CVE-2026-85982 — Auth0: The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-85982

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to modify directory attributes, or a low-privileged local user on the host where the connector is installed, could insert script content. This script content could then execute in an administrator's browser when they view the affected search resu CVSSv3.1 9.0 (CRITICAL)

CWECWE 79VNDAuth0TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
5d ago
2026-09-08 21:18Z
HIGH

CVE-2026-81996 — Acrobat: Reader is affected by an Incorrect Authorization vulnerability that could result in privilege

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81996

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDAcrobatTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 21:18Z
HIGH

CVE-2026-81994 — Acrobat: Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-81994

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.2 (HIGH)

CWECWE 1321VNDAcrobatTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 21:17Z
HIGH

CVE-2026-30754 — A memory corruption vulnerability exists in FFmpeg before 8.1.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-30754

A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC streams via RTP using a crafted input file. This was detected using AddressSanitizer. CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 20:18Z
HIGH

CVE-2026-84942 — Vega: Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84942

Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation. CVSSv3.1 8.7 (HIGH)

CWECWE 79VNDVegaTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 20:18Z
CRIT

CVE-2026-84869 — ScreenConnect: A condition in the ScreenConnect client may allow files to be transferred and executed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84869

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted. CVSSv3.1 9.9 (CRITICAL)

CWECWE 862CWECWE 269VNDScreenconnectTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
5d ago
2026-09-08 20:18Z
HIGH

CVE-2026-78834 — A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78834

A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing crafted external or uploaded text content through the affected content import feature. CVSSv3.1 8.8 (HIGH)

CWECWE 94TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
5d ago
2026-09-08 20:18Z
HIGH

CVE-2026-78626 — Okta: The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-78626

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protected Rule policy on one or more application resources. CVSSv3.1 8.1 (HIGH)

CWECWE 863VNDOktaTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
5d ago
2026-09-08 20:18Z
HIGH

CVE-2026-76199 — Photoshop: Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76199

Photoshop Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 427VNDPhotoshopTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5d ago
2026-09-08 20:18Z
HIGH

CVE-2026-76190 — ColdFusion: is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76190

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 95VNDColdfusionTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5d ago
2026-09-08 20:18Z
HIGH

CVE-2026-75999 — ColdFusion: is affected by an Improper Input Validation vulnerability that could result in arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75999

ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.4 (HIGH)

CWECWE 20VNDColdfusionTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
5d ago
2026-09-08 20:18Z
HIGH

CVE-2026-75993 — ColdFusion: is affected by a reflected Cross-Site Scripting (XSS) vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75993

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.5 (HIGH)

CWECWE 79VNDColdfusionTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
5d ago
2026-09-08 20:18Z
HIGH

CVE-2026-75991 — Illustrator: is affected by an Improper Input Validation vulnerability that could result in arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75991

Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 20VNDIllustratorTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5d ago
2026-09-08 20:18Z
HIGH

CVE-2026-75990 — Illustrator: is affected by an Incorrect Authorization vulnerability that could result in arbitrary code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75990

Illustrator is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 8.6 (HIGH)

CWECWE 863VNDIllustratorTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
5d ago
2026-09-08 20:18Z
CRIT

CVE-2026-75746 — ColdFusion: is affected by an Improper Neutralization of Special Elements used in an SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75746

ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.1 (CRITICAL)

CWECWE 89VNDColdfusionTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
5d ago
2026-09-08 20:17Z
CRIT

CVE-2026-48273 — ColdFusion: is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48273

ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.9 (CRITICAL)

CWECWE 95VNDColdfusionTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
5d ago
2026-09-08 20:17Z
CRIT

CVE-2026-19232 — Adobe: Experience Manager is affected by an Incorrect Authorization vulnerability that could result in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19232

Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim's account or session. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.9 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
5d ago
2026-09-08 19:20Z
HIGH

CVE-2026-82537 — Roo: Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-82537

Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability that allows attackers to execute denied shell commands by exploiting a word-boundary mismatch in comment handling between the approval gate's shell parser and bash. Attackers can craft a command string with an allowlisted word immediately followed by a hash character, separator, and denied command to pass the approval gate while bash executes the denied command with the agent's auto-execute privileges on th CVSSv3.1 8.8 (HIGH)

CWECWE 436VNDRooTYPVulnerability
8.8
CVSS v3.1
94
Edit Score