1w ago
2026-09-07 23:16Z
CRIT

CVE-2026-86543 — knowns versions before 0.30.0 serve the management API without authentication on all network interfaces

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86543

knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-07 23:16Z
CRIT

CVE-2026-86542 — knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86542

knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files writable by the server process. CVSSv3.1 9.1 (CRITICAL)

CWECWE 22TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-07 23:16Z
HIGH

CVE-2026-86541 — knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86541

knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or relative paths containing directory traversal sequences to write malicious content to sensitive files like shell startup scripts or SSH configuration files. CVSSv3.1 8.3 (HIGH)

CWECWE 22TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
1w ago
2026-09-07 23:16Z
HIGH

CVE-2026-86439 — Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86439

knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments containing directory traversal sequences to access arbitrary Markdown files accessible to the server process. CVSSv3.1 8.8 (HIGH)

CWECWE 22TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-07 21:17Z
CRIT

CVE-2026-75650 — Adobe: Commerce is affected by an Improper Neutralization of Special Elements Used in a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-75650

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 1336VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
1w ago
2026-09-07 17:17Z
HIGH

CVE-2026-86502 — JetBrains: In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86502

In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts CVSSv3.1 8.4 (HIGH)

CWECWE 306VNDJetbrainsTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
1w ago
2026-09-07 17:17Z
HIGH

CVE-2026-86492 — JetBrains: In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86492

In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens CVSSv3.1 8.5 (HIGH)

CWECWE 488VNDJetbrainsTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
728 × 90 / responsive · programmatic ad slot
1w ago
2026-09-07 17:17Z
HIGH

CVE-2026-86482 — JetBrains: In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86482

In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation CVSSv3.1 8.8 (HIGH)

CWECWE 266VNDJetbrainsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-07 17:17Z
CRIT

CVE-2026-86480 — JetBrains: In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86480

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDJetbrainsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-07 17:17Z
HIGH

CVE-2026-86479 — JetBrains: In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86479

In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDJetbrainsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-07 17:17Z
CRIT

CVE-2026-86478 — JetBrains: In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86478

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address CVSSv3.1 9.8 (CRITICAL)

CWECWE 290VNDJetbrainsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-07 15:17Z
CRIT

CVE-2026-7861 — Deserialization: of untrusted data vulnerability in Next4Biz Information Technologies Inc.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7861

Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-07 15:17Z
HIGH

CVE-2026-79645 — Dell: SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79645

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. CVSSv3.1 8.2 (HIGH)

CWECWE 306VNDDellTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
1w ago
2026-09-07 15:17Z
HIGH

CVE-2026-19843 — A flaw was found in 389-ds-base.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-19843

A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privilege CVSSv3.1 8.4 (HIGH)

CWECWE 78TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
1w ago
2026-09-07 15:17Z
CRIT

CVE-2026-18922 — An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18922

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the s CVSSv3.1 9.8 (CRITICAL)

CWECWE 287TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-07 13:20Z
HIGH

CVE-2026-86427 — LibreNMS: before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86427

LibreNMS before 26.8.0 contains an argument injection vulnerability in the graph_title parameter that allows authenticated attackers to inject arbitrary rrdtool arguments by breaking out of double-quote escaping. Attackers can inject DEF and LINE arguments to read RRD files from unauthorized devices, or use newline injection to execute arbitrary rrdtool commands, bypassing per-device authorization checks. CVSSv3.1 8.8 (HIGH)

CWECWE 77VNDLibrenmsTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-07 13:20Z
CRIT

CVE-2026-86419 — Misp-project Misp: Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86419

Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme or destination. The original request headers were reused across redirect hops, meaning authentication headers or API credentials configured for a feed could be forwarded to a different host. Redirects could also target internal network resour CVSSv3.1 9.1 (CRITICAL) · EPSS 25th percentile

CWECWE 918CWECWE 200VNDMispVNDMisp ProjectTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
1w ago
2026-09-07 13:20Z
CRIT

CVE-2026-80238 — Dell: An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80238

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a passw CVSSv3.1 9.3 (CRITICAL)

CWECWE 250VNDDellTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
1w ago
2026-09-07 13:20Z
HIGH

CVE-2026-80132 — SCG: ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-80132

ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. CVSSv3.1 8.1 (HIGH)

CWECWE 306VNDScgTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-07 13:20Z
HIGH

CVE-2026-79678 — This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79678

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion. CVSSv3.1 8.1 (HIGH)

CWECWE 95TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
1w ago
2026-09-07 13:20Z
CRIT

CVE-2026-76578 — FreeIPA: This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76578

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker t CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDFreeipaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
1w ago
2026-09-07 13:20Z
CRIT

CVE-2026-6223 — Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6223

Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: from 2.1.7 through 07092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.4 (CRITICAL)

CWECWE 307TYPVulnerability
9.4
CVSS v3.1
97
Edit Score
1w ago
2026-09-07 13:20Z
CRIT

CVE-2026-61410 — Dell: SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-61410

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability is considered critical because it allows an attacker to execute commands remotely on a target system by sending a specially crafted request to the application, bypassing intended r CVSSv3.1 9.4 (CRITICAL)

CWECWE 862VNDDellTYPVulnerability
9.4
CVSS v3.1
97
Edit Score
1w ago
2026-09-07 12:17Z
HIGH

CVE-2026-86404 — Artemis: EAP's Artemis deserialization configuration permits deserialization by default.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86404

EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the allow-list is empty (size == 0), isTrustedType() returns true for ALL classes. This means all classes are deserializable by default. CVSSv3.1 8.8 (HIGH)

CWECWE 502VNDArtemisTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
1w ago
2026-09-07 12:17Z
CRIT

CVE-2026-86299 — Linksys: The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-86299

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used. CVSSv3.1 9.9 (CRITICAL)

CWECWE 77CWECWE 78VNDLinksysTYPVulnerability
9.9
CVSS v3.1
100
Edit Score