2026-05-28
2026-05-28 10:16Z
HIGH

CVE-2026-46138 — Linux: Since the out-of-bounds values typically exceed HCI_CONN_HANDLE_MAX (0x0EFF), hci_conn_set_handle() rejects them and the connection

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46138

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt hci_le_create_big_complete_evt() iterates over BT_BOUND connections for a BIG handle using a while loop, accessing ev->bis_handle[i++] on each iteration. However, there is no check that i stays within ev->num_bis before the array access. When a controller sends a LE_Create_BIG_Complete event with fewer bis_handle entrie CVSSv3.1 8.1 (HIGH)

TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-28
2026-05-28 10:16Z
CRIT

CVE-2026-46137 — Linux: In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46137

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race This mptcp_pm_add_timer() helper is executed as a timer callback in softirq context. To avoid any data races, the socket lock needs to be held with bh_lock_sock(). If the socket is in use, retry again soon after, similar to what is done with the keepalive timer. CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-28
2026-05-28 10:16Z
CRIT

CVE-2026-46135 — Linux: That defeats the DISCONNECTING-state guard in nvmet_tcp_schedule_release_queue() and allows a later socket state change

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46135

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix race between ICReq handling and queue teardown nvmet_tcp_handle_icreq() updates queue->state after sending an Initialization Connection Response (ICResp), but it does so without serializing against target-side queue teardown. If an NVMe/TCP host sends an Initialization Connection Request (ICReq) and immediately closes the connection, target-side teardown may start in softirq context before i CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-28
2026-05-28 10:16Z
HIGH

CVE-2026-46125 — Linux: This fixes a use-after-free/double-free in debugfs if that's enabled, because a vif going from

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46125

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: remove station if connection prep fails If connection preparation fails for MLO connections, then the interface is completely reset to non-MLD. In this case, we must not keep the station since it's related to the link of the vif being removed. Delete an existing station. Any "new_sta" is already being removed, so that doesn't need changes. This fixes a use-after-free/double-free in debugfs CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 10:16Z
CRIT

CVE-2026-46119 — Linux: In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46119

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix slab-out-of-bounds access in auth message processing If a (potentially corrupted) message of type CEPH_MSG_AUTH_REPLY contains a positive value in its result field, it is treated as an error code by ceph_handle_auth_reply() and returned to handle_auth_reply(). Thereafter, an attempt is made to send the preallocated message of type CEPH_MSG_AUTH, where the returned value is interpreted as the si CVSSv3.1 9.1 (CRITICAL)

TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-28
2026-05-28 10:16Z
CRIT

CVE-2026-46115 — Linux: In the Linux kernel, the following vulnerability has been resolved: block: add pgmap check

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46115

In the Linux kernel, the following vulnerability has been resolved: block: add pgmap check to biovec_phys_mergeable biovec_phys_mergeable() is used by the request merge, DMA mapping, and integrity merge paths to decide if two physically contiguous bvec segments can be coalesced into one. It currently has no check for whether the segments belong to different dev_pagemaps. When zone device memory is registered in multiple chunks, each chunk gets its own dev_pagemap. A single CVSSv3.1 9.8 (CRITICAL)

TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-28
2026-05-28 10:16Z
HIGH

CVE-2026-46113 — Linux: In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46113

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN The shadow MMU computes GFNs for direct shadow pages using sp->gfn plus the SPTE index. This assumption breaks for shadow paging if the guest page tables are modified between VM entries (similar to commit aad885e77496, "KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE", 2026-03-27). The flow is as follows: - a PDE CVSSv3.1 8.8 (HIGH)

TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-28
2026-05-28 09:16Z
HIGH

CVE-2026-6226 — Frontend: The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6226

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2. This is due to insecure form submission handling that accepts arbitrary form definitions from user input instead of securely loading them from the backend. When $_POST['_acf_form'] is an array (rather than a form ID), the validate_form() function bypasses database lookup and directly processes the attacker-controlled structure. Th CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDFrontendTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 09:16Z
CRIT

CVE-2026-4408 — Samba: This vulnerability allows an attacker to achieve remote command execution on the affected system.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configura CVSSv3.1 9.0 (CRITICAL)

CWECWE 78VNDSambaTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-05-28
2026-05-28 08:16Z
HIGH

CVE-2026-9227 — GutenBee: The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9227

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.20.1 via the gutenbee_file_and_ext_json function. This is due to a flawed strpos() substring check that only verifies whether the filename contains the string '.json' rather than confirming the filename ends with a .json extension, allowing double-extension filenames like shell.json.php to bypass validation. This makes it possible for authenticat CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDGutenbeeTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-28
2026-05-28 08:16Z
HIGH

CVE-2026-6455 — Contact: The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6455

The WP Contact Form 7 DB Handler plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Arbitrary File Deletion via SQL Injection and PHP Object Injection in versions up to and including 3.0. This is due to a missing nonce verification in the process_bulk_action() function, the nonce check is only executed when _wpnonce is present in the POST body, allowing it to be trivially bypassed by omitting the field, combined with the use of an unsanitized, unparam CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDContactTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-28
2026-05-28 06:55Z
HIGH

Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years

Kaspersky Securelist·securelist.com

Kaspersky researchers documented a multi-year campaign distributing cryptominers and RAT malware via pirated content sites (movies, TV, ebooks). The infection chain uses fake video-player plugin updates to deliver a ZIP containing a legitimate executable and malicious DLL that side-loads into process memory, establishing persistence via a fake Google Chrome service and deploying CPU/GPU miners, a watchdog module, and a RAT with four remote commands. The campaign has been active since at least 2022, reaching 40 million monthly visits across compromised piracy platforms.

TACTA0005TACTA0001SRFWebTACTA0003TACTA0011OSWindowsSWSilentcryptominerSWXmrig
76
Edit Score
2026-05-28
2026-05-28 05:16Z
CRIT

CVE-2026-32999 — Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32999

Insufficient character filtering in backup agent signing module on Comet Backup server allows authenticated tenant administrator to execute an arbitrary code on behalf of a privileged user on the affected server and connected devices. CVSSv3.1 9.0 (CRITICAL)

CWECWE 94TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2026-05-28
2026-05-28 00:16Z
HIGH

CVE-2026-8915 — Out: Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8915

Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31. CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 23:16Z
HIGH

CVE-2026-46414 — Microsoft: The same client registry also allows duplicate client_id registration, overwriting an existing live client's

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46414

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fields in task messages. A client connection can register as a normal device, but later send a TASK message claiming client_type="constellation" and target_id=<victim-device-id>. The server trusts the role and target values from the wire message rather than enforcing the role registe CVSSv3.1 8.8 (HIGH)

CWECWE 862CWECWE 639CWECWE 290VNDMicrosoftTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 23:16Z
HIGH

CVE-2026-46402 — Microsoft: An authenticated client can supply path traversal sequences in task_name and cause UFO to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46402

Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing session log paths. An authenticated client can supply path traversal sequences in task_name and cause UFO to create log directories and log files outside the intended logs/ directory. CVSSv3.1 8.1 (HIGH)

CWECWE 22CWECWE 73VNDMicrosoftTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 22:16Z
HIGH

CVE-2026-9208 — Tanium: addressed an unauthorized code execution vulnerability in Connect.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-9208

Tanium addressed an unauthorized code execution vulnerability in Connect. CVSSv3.1 8.8 (HIGH)

CWECWE 78VNDTaniumTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 22:16Z
CRIT

CVE-2026-45083 — Goobi: The Goobi viewer is a web application that allows digitised material to be displayed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45083

The Goobi viewer is a web application that allows digitised material to be displayed in a web browser. From 4.8.0 to before 26.04.1, the Goobi viewer REST endpoint POST /api/v1/index/stream accepted an arbitrary Solr streaming expression from unauthenticated network clients and forwarded it to the backend Solr server without restriction. An attacker could read the complete Solr index and, in default Solr deployments, also modify or delete indexed records. This vulnerability i CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDGoobiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 21:16Z
HIGH

CVE-2026-45137 — Anchor: In the TryFrom<&'a AccountInfo<'a>> implementation for Program<'a, T>, the id of T is compared

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45137

Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0.2, an logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumptions resulting in potential arbitrary cpi in programs that invoke system program instructions. In the TryFrom<&'a AccountInfo<'a>> implementation for Program<'a, T>, the id of T is compared with Pubkey::default() to check whether anch CVSSv3.1 8.2 (HIGH)

CWECWE 20VNDAnchorTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 21:16Z
HIGH

CVE-2026-44713 — Linux: pam_usb provides hardware authentication for Linux using ordinary removable media.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44713

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the user's $TMUX environment variable, splits it on commas, and interpolates the socket-path component directly into a shell command passed to popen(). Because the value is placed inside double-quotes without sanitisation, any value containing " terminates the quoted string and injects arbitrary shell syntax. popen() runs as root inside the PAM stack. This vulne CVSSv3.1 8.8 (HIGH)

CWECWE 78CWECWE 116TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-27
2026-05-27 21:16Z
HIGH

CVE-2026-44712 — Linux: Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the config causes root

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44712

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such as $(id>/tmp/rce) in the config causes root RCE when pamusb-conf --reset-pads is run. A USB device with a crafted filesystem UUID (some controllers allow this) can inject the payload at --add-device time. Also, userName from the XML config is passed to os.system() in pamusb-agent, which invokes a shell. This vulnerability is fixed in 0.8.7. CVSSv3.1 8.2 (HIGH)

CWECWE 78CWECWE 88TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-27
2026-05-27 20:16Z
CRIT

CVE-2026-8364 — Gladinet: Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8364

Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo, /woshome, /Settings, /schedule, or /DavCache. CVSSv3.1 9.8 (CRITICAL)

CWECWE 306VNDGladinetTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 20:16Z
CRIT

CVE-2026-8363 — A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8363

A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources: CVSSv3.1 9.8 (CRITICAL)

CWECWE 121TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 20:16Z
CRIT

CVE-2026-8362 — A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8362

A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome CVSSv3.1 9.8 (CRITICAL)

CWECWE 121TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-27
2026-05-27 20:16Z
HIGH

CVE-2026-48064 — Linux: Prior to 0.9.1, when a PAM service is configured with deny_remote=false in pam_usb (commonly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48064

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is configured with deny_remote=false in pam_usb (commonly done for display managers such as gdm-password or lightdm to bypass process/TTY heuristics for local sessions), the PAM_RHOST check in pusb_do_auth() is also skipped. PAM_RHOST is set by remote daemons (sshd, XDMCP servers) to identify the remote client address. Because the check is gated inside if (opt CVSSv3.1 8.1 (HIGH)

CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score