2026-07-14
2026-07-14 19:17Z
HIGH

CVE-2026-45075 — Sensiolabs Symfony: Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45075

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check is skipped, allowing protected controllers to execute and leak headers or perform side effects. This issue is fixed in versions 7.4.12 and 8.0.12. CVSSv3.1 8.2 (HIGH)

CWECWE 863VNDSensiolabsVNDSymfonyTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 19:17Z
CRIT

CVE-2026-45069 — Sensiolabs Symfony: Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45069

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted those claims could pass verification. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12. CVSSv3.1 9.1 (CRITICAL)

CWECWE 345CWECWE 1287VNDSensiolabsVNDSymfonyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 19:17Z
CRIT

CVE-2026-45063 — Sensiolabs Symfony: Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN']

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45063

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in CVSSv3.1 9.1 (CRITICAL)

CWECWE 290VNDSensiolabsVNDSymfonyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-07-14
2026-07-14 19:16Z
HIGH

CVE-2026-15720 — Open5GS: In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-15720

In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service. CVSSv3.1 8.6 (HIGH)

CWECWE 125VNDOpen5gsTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-58626 — Use: after free in Windows Remote Desktop Services allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58626

Use after free in Windows Remote Desktop Services allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-58617 — Microsoft: Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58617

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 284VNDMicrosoftTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-58594 — Integer: overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58594

Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-58534 — Heap: Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58534

Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-58277 — Microsoft: Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58277

Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 285VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-57102 — Inclusion: of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57102

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 200CWECWE 829VNDInclusionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-57094 — Heap: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57094

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 125CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
CRIT

CVE-2026-57092 — Use: after free in Windows VMSwitch allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57092

Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.9 (CRITICAL)

CWECWE 416TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-57090 — Heap: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57090

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-57087 — Heap: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57087

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-56647 — Integer: overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56647

Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 190TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-56642 — Stack: Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56642

Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDStackTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-56197 — Improper neutralization of special elements used in a command ('command injection') in Windows Admin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56197

Improper neutralization of special elements used in a command ('command injection') in Windows Admin Center allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 77TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-56196 — Relative: path traversal in Windows Admin Center allows an authorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56196

Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 23VNDRelativeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-56194 — Heap: Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56194

Heap-based buffer overflow in Windows Network File System allows an authorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 122CWECWE 190VNDHeapTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-07-14
2026-07-14 18:18Z
CRIT

CVE-2026-56190 — Use: of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56190

Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 908TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 18:18Z
CRIT

CVE-2026-56188 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows Server Network

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56188

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 362VNDConcurrentTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-56186 — Out: Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56186

Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network. CVSSv3.1 8.1 (HIGH)

CWECWE 125TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-07-14
2026-07-14 18:18Z
HIGH

CVE-2026-56181 — Origin: validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56181

Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. CVSSv3.1 8.3 (HIGH)

CWECWE 346VNDOriginTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-07-14
2026-07-14 18:18Z
CRIT

CVE-2026-56159 — Heap: Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56159

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 122VNDHeapTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-07-14
2026-07-14 18:18Z
CRIT

CVE-2026-55944 — Deserialization: of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55944

Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score