The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
CVSSv3.1 8.8 (HIGH)
CWECWE 287VNDAcerVNDScreen ClickTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-04
2026-06-04 07:16Z
CRIT
CVE-2026-49191 — Acer Connect_m6e_5g_firmware: The production build of the M3WebServer hard-codes its backend API keys, which can be
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 287VNDAcerVNDM3webserverTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-04
2026-06-04 07:16Z
HIGH
CVE-2026-49190 — Acer Connect_m6e_5g_firmware: The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
CVSSv3.1 8.8 (HIGH)
Sekoia.io's third report in their Gamaredon trilogy documents GammaSteel, the FSB-operated intrusion set's final-stage stealer payload targeting Ukrainian government and critical infrastructure. The malware operates fileless via PowerShell, leveraging Windows DPAPI encryption in the registry, and deploys three concurrent data-acquisition mechanisms: hourly filesystem scans, USB hardware event monitoring, and real-time file-change surveillance. Exfiltration routes through S3-compatible cloud storage (Tebi.io) with fallback to operator-controlled C2 and Dead Drop Resolvers, with local MD5-based deduplication to minimize network noise.
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 489VNDAcerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-04
2026-06-04 04:17Z
CRIT
CVE-2026-49186 — Acer Connect_m6e_5g_firmware: This allows any client to subscribe using wildcard characters (# or +) to enumerate
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish rogue control commands.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 287VNDMqttVNDAcerTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-04
2026-06-04 04:17Z
CRIT
CVE-2026-49185 — Acer Connect_m6e_5g_firmware: The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
CVSSv3.1 9.9 (CRITICAL)
CWECWE 863VNDOpenstackTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-04
2026-06-04 04:17Z
HIGH
CVE-2026-41010 — File: ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where
ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where name returns @job_meta['name'], a value taken verbatim from the jobs: array of the attacker-supplied release.MF inside the uploaded tarball. These paths are then interpolated into a shell string: Bosh::Common::Exec.sh("tar -C #{job_dir} -xf #{job_tgz} 2>&1", :on_error => :return). Bosh::Common::Exec.sh executes via %x{#{command}} (bosh-co
CVSSv3.1 8.2 (HIGH)
CWECWE 78TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-04
2026-06-04 03:16Z
HIGH
CVE-2026-41860 — CWE: CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA
CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials.
Affected versions:
- BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later
CVSSv3.1 8.8 (HIGH)
CWECWE 326VNDCweTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-04
2026-06-04 03:16Z
HIGH
CVE-2026-41011 — PackagePersister: PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name
PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uploaded tarball. The string is passed to Bosh::Common::Exec.sh, which executes via %x{} — i.e., /bin/sh -c. No Shellwords.escape is applied. The Models::Package Sequel validation (VALID_ID = /^[-0-9A-Za-z_+.]+$/i) would reject the name, but in create_package (lines 74–79) the shell-o
CVSSv3.1 8.2 (HIGH)
CWECWE 78VNDPackagepersisterTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-04
2026-06-04 00:00Z
HIGH
You do surprise me.exe: An unexpected executable in Hola Browser
Sophos X-Ops·news.sophos.com
Sophos X-Ops discovered me.exe, an undeclared crypto-miner executable, bundled with Hola Browser v1.251.91.0 during AppEsteem certification testing. The binary exhibited suspicious characteristics (obfuscation, unsigned, no timestamp, memory-write capability) and was inconsistently delivered across build channels, indicating a supply-chain integrity issue. Hola confirmed the compromise, halted the affected pipeline, engaged Sygnia for forensic investigation, and rebuilt their distribution infrastructure with enhanced code-signing and access controls.
CVE-2026-22055 — Netapp Active_iq_onecollect: Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker
Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile
CWECWE 259VNDNetappVNDActiveTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-03
2026-06-03 22:16Z
HIGH
CVE-2026-22054 — Netapp Active_iq_config_advisor: Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated
Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
CVSSv3.1 8.8 (HIGH) · EPSS 15th percentile
CWECWE 259VNDNetappVNDActiveTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-03
2026-06-03 22:00Z
INFO
"Practical Android Software Protection in the Wild" - An Appetizer
Quarkslab·blog.quarkslab.com
Quarkslab publishes a comprehensive survey of Android software protection techniques based on a PhD thesis analyzing 2.5 million apps. The research organizes anti-analysis defenses into four families: adversarial execution environment checks, anti-disassembly/decompilation, code/data obfuscation, and program loading abuse. Key findings show only ~4% of analyzed apps use protections, concentrated in finance/gaming categories, with significantly higher adoption (up to 40%) in Chinese app markets.
In the Linux kernel, the following vulnerability has been resolved:
ibmveth: Disable GSO for packets with small MSS
Some physical adapters on Power systems do not support segmentation
offload when the MSS is less than 224 bytes. Attempting to send such
packets causes the adapter to freeze, stopping all traffic until
manually reset.
Implement ndo_features_check to disable GSO for packets with small MSS
values. The network stack will perform software segmentation instead.
T
CVSSv3.1 8.6 (HIGH)
TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-03
2026-06-03 18:16Z
HIGH
CVE-2026-46270 — Linux: In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix
In the Linux kernel, the following vulnerability has been resolved:
power: supply: rt9455: Fix use-after-free in power_supply_changed()
Using the `devm_` variant for requesting IRQ _before_ the `devm_`
variant for allocating/registering the `power_supply` handle, means that
the `power_supply` handle will be deallocated/unregistered _before_ the
interrupt handler (since `devm_` naturally deallocates in reverse
allocation order). This means that during removal, there is a rac
CVSSv3.1 8.4 (HIGH)
TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-03
2026-06-03 18:16Z
CRIT
CVE-2026-46266 — Linux: In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using
In the Linux kernel, the following vulnerability has been resolved:
inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
Yizhou Zhao reported that simply having one RAW socket on protocol
IPPROTO_RAW (255) was dangerous.
socket(AF_INET, SOCK_RAW, 255);
A malicious incoming ICMP packet can set the protocol field to 255
and match this socket, leading to FNHE cache changes.
inner = IP(src="192.168.2.1", dst="8.8.8.8", proto=255)/Raw("TEST")
pkt = IP(src="192.168.1.
CVSSv3.1 9.1 (CRITICAL)
TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-03
2026-06-03 18:16Z
HIGH
CVE-2026-46264 — Linux: This may lead to errors like: [ ] kobject: '(null)' (ff110001393608e0): is not initialized
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/pf: Fix sysfs initialization
In case of devm_add_action_or_reset() failure the provided cleanup
action will be run immediately on the not yet initialized kobject.
This may lead to errors like:
[ ] kobject: '(null)' (ff110001393608e0): is not initialized, yet kobject_put() is being called.
[ ] WARNING: lib/kobject.c:734 at kobject_put+0xd9/0x250, CPU#0: kworker/0:0/9
[ ] RIP: 0010:kobject_put+0xdf
CVSSv3.1 8.8 (HIGH)
TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-03
2026-06-03 18:16Z
HIGH
CVE-2026-46251 — Linux: This is apparent on a subsequent list_del on the prev if we enable CONFIG_DEBUG_LIST
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix block_group_tree dirty_list corruption
When the incompat flag EXTENT_TREE_V2 is set, we unconditionally add the
block group tree to the switch_commits list before calling
switch_commit_roots, as we do for the tree root and the chunk root.
However, the block group tree uses normal root dirty tracking and in any
transaction that does an allocation and dirties a block group, the block
group root wil
CVSSv3.1 8.4 (HIGH)
TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-03
2026-06-03 18:16Z
CRIT
CVE-2026-46244 — Linux: This creates a desync between inner_thoff (wrong — points to extension header start) and
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_inner: Fix IPv6 inner_thoff desync
In nft_inner_parse_l2l3(), when processing inner IPv6 packets,
ipv6_find_hdr() correctly computes the transport header offset
traversing all extension headers, but the result is immediately
overwritten with nhoff + sizeof(_ip6h) (40 bytes), which only
accounts for the IPv6 base header. This creates a desync between
inner_thoff (wrong — points to extension he
CVSSv3.1 9.1 (CRITICAL)
TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-03
2026-06-03 18:16Z
HIGH
CVE-2026-36608 — Mercusys: AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin interface by accepting its own IP (192.168.1.1) or localhost (127.0.0.1) as InternalClient. An unauthenticated LAN attacker can expose the admin panel to the internet with a single SOAP request.
CVSSv3.1 8.8 (HIGH)
CWECWE 441VNDMercusysTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-03
2026-06-03 18:16Z
HIGH
CVE-2026-36607 — Mercusys: AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (code=10), which lacks the rate limiting applied to the login endpoint (code=7). An attacker on the adjacent network can attempt unlimited passwords without triggering account lockout.
CVSSv3.1 8.8 (HIGH)
CWECWE 307VNDMercusysTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-03
2026-06-03 18:16Z
HIGH
CVE-2026-36603 — Mercusys: AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, including AddPortMapping and GetExternalIPAddress. UPnP is enabled by default through the admin interface, allowing any unauthenticated LAN device to create arbitrary port forwarding rules and access WAN traffic statistics.
CVSSv3.1 8.1 (HIGH)
CWECWE 306VNDMercusysTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-03
2026-06-03 18:16Z
HIGH
CVE-2026-20230 — Cisco: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A succes
CVSSv3.1 8.6 (HIGH)