2026-05-13
2026-05-13 19:17Z
CRIT

CVE-2026-0257 — Paloaltonetworks Pan-os: Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS®

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0257

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues. CVSSv3.1 9.1 (CRITICAL)

CWECWE 565VNDPaloaltonetworksTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 19:16Z
HIGH

CVE-2026-0250 — Paloaltonetworks Globalprotect: A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0250

A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between Portal and Gateway. The GlobalProtect app on iOS is not affected. CVSSv3.1 8.1 (HIGH) · EPSS 11th percentile

CWECWE 787VNDPaloaltonetworksTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 19:16Z
HIGH

CVE-2026-0244 — Paloaltonetworks Prisma_sd-wan: An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0244

An improper certificate validation vulnerability in the Palo Alto Networks Prisma SD-WAN ION enables man-in-the-middle (MitM) attacker to impersonate the controller. CVSSv3.1 8.1 (HIGH) · EPSS 1th percentile

CWECWE 295VNDPaloaltonetworksTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 19:16Z
HIGH

CVE-2026-0240 — Paloaltonetworks Trust_protection_foundation: An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0240

An information disclosure vulnerability in Trust Protection Foundation enables an authenticated attacker to obtain sensitive information from the server's vault. Successful exploitation of this issue allows the attacker to impersonate any user within the environment and arbitrarily modify configuration settings. CVSSv3.1 8.7 (HIGH) · EPSS 11th percentile

CWECWE 497VNDPaloaltonetworksVNDTrustTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 18:16Z
CRIT

CVE-2026-45411 — This allows attackers to write code which can escape from the VM2 sandbox and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45411

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the runtime and passed to the yield* iterator as the next value. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host sy CVSSv3.1 9.8 (CRITICAL)

CWECWE 668TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-13
2026-05-13 18:16Z
HIGH

CVE-2026-44578 — Next: From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44578

Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request forgery through crafted WebSocket upgrade requests. An attacker can cause the server to proxy requests to arbitrary internal or external destinations, which may expose internal services or cloud metadata endpoints. Vercel-hosted deployments are not affected. This vu CVSSv3.1 8.6 (HIGH)

CWECWE 918TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-13
2026-05-13 18:16Z
CRIT

CVE-2026-44009 — vm2 is an open source vm/sandbox for Node.js.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44009

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 668TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-13
2026-05-13 18:16Z
CRIT

CVE-2026-44008 — This allows attackers to write code which can escape from the VM2 sandbox and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44008

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to get host objects and get the host Function object. This allows attackers to write code which can escape from the VM2 sandbox and execute arbitrary commands on the host system. This vulnerability is fi CVSSv3.1 9.8 (CRITICAL)

CWECWE 668TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-13
2026-05-13 18:16Z
CRIT

CVE-2026-44007 — vm2 is an open source vm/sandbox for Node.js.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44007

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs a new inner NodeVM with its own unrestricted require settings and executes arbitrary OS commands on the host. Any application that runs untrusted code inside a NodeVM with nesting: true is fully comprom CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-13
2026-05-13 18:16Z
CRIT

CVE-2026-44006 — vm2 is an open source vm/sandbox for Node.js.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44006

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-13
2026-05-13 18:16Z
CRIT

CVE-2026-44005 — vm2 is an open source vm/sandbox for Node.js.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44005

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled JavaScript running in a default VM or inherited NodeVM mutate shared host Object.prototype, Array.prototype, and Function.prototype from inside the sandbox This vulnerability is fi CVSSv3.1 10.0 (CRITICAL)

CWECWE 94CWECWE 1321TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-13
2026-05-13 18:16Z
HIGH

CVE-2026-44001 — Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44001

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a single Promise constructor that triggers an unhandled rejection propagating to the host. The fix for CVE-2026-22709 (v3.10.2) only sanitized the onRejected callback in .then() and .catch() overrides and did not address the executor-to-unhandledRejection path. This vulnerability is fixed in 3.11.0. CVSSv3.1 8.6 (HIGH)

CWECWE 248TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-05-13
2026-05-13 18:16Z
CRIT

CVE-2026-43999 — This allows sandboxed code to load excluded builtins like child_process and achieve remote code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43999

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads any module by name directly in the host context, completely bypassing vm2's builtin restriction. This allows sandboxed code to load excluded builtins like child_process and achieve remote code execution. This vulnerability is fixed in 3.11.0. CVSSv3.1 9.9 (CRITICAL)

CWECWE 863TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-05-13
2026-05-13 18:16Z
HIGH

CVE-2026-43998 — Because path validation uses path.resolve() (which does not dereference symlinks) but module loading uses

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43998

vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing sandboxed code to load modules from outside the allowed root directory in host context. Because path validation uses path.resolve() (which does not dereference symlinks) but module loading uses Node's native require() (which does), an attacker can load arbitrary host-realm modules and achieve remote code execution. This vulnerabil CVSSv3.1 8.5 (HIGH)

CWECWE 59TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-13
2026-05-13 18:16Z
CRIT

CVE-2026-43997 — vm2 is an open source vm/sandbox for Node.js.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-43997

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability is fixed in 3.11.0. CVSSv3.1 10.0 (CRITICAL)

CWECWE 94TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-13
2026-05-13 18:16Z
HIGH

CVE-2026-0265 — Paloaltonetworks Pan-os: An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0265

An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to bypass authentication controls when Cloud Authentication Service (CAS) is enabled. The risk is higher if CAS is enabled on the management interface and lower when any other login interfaces are used. The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted intern CVSSv3.1 8.1 (HIGH) · EPSS 35th percentile

CWECWE 347VNDPaloaltonetworksVNDPaloTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 18:16Z
CRIT

CVE-2026-0264 — Paloaltonetworks Pan-os: A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0264

A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows an unauthenticated attacker with network access to cause a denial of service (DoS) condition (all PAN-OS platforms except Cloud NGFW and Prisma Access) or potentially execute arbitrary code by sending specially crafted network traffic (PA-Series hardware only). Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability. CVSSv3.1 9.8 (CRITICAL) · EPSS 33th percentile

CWECWE 122VNDPaloaltonetworksTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-13
2026-05-13 18:16Z
CRIT

CVE-2026-0263 — Paloaltonetworks Pan-os: A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-0263

A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated network-based attacker to execute arbitrary code with elevated privileges on the firewall, or cause a denial of service (DoS) condition. Panorama, Cloud NGFW, and Prisma® Access are not impacted by these vulnerabilities. CVSSv3.1 9.8 (CRITICAL) · EPSS 23th percentile

CWECWE 787VNDPaloaltonetworksTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-13
2026-05-13 17:16Z
HIGH

CVE-2026-44574 — Next: From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44574

Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected deployments, specially crafted query parameters can alter the dynamic route value seen by the page while leaving the visible path unchanged, which can allow protected content to be rendered without passing the expected middleware check. This vulnera CVSSv3.1 8.1 (HIGH)

CWECWE 288TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 16:17Z
HIGH

CVE-2026-6282 — A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6282

A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to other users on the same device. CVSSv3.1 8.1 (HIGH)

CWECWE 22TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 16:17Z
HIGH

CVE-2026-6281 — A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6281

A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device. CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2026-44295 — protobufjs-cli is the command line add-on for protobuf.js.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44295

protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When generating static JavaScript from a crafted schema or JSON descriptor, certain namespace, enum, service, or derived full names could be written into the generated output without sufficient sanitization. This vulnerability is fixed in 1.2.1 and 2.0.2. CVSSv3.1 8.7 (HIGH)

CWECWE 94TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2026-44293 — Protobufjs_project Protobufjs: compiles protobuf definitions into JavaScript (JS) functions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44293

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field default value. A crafted descriptor with a non-string default value for a bytes field could cause attacker-controlled code to be emitted into the generated conversion function. This vulnerability is fixed in 7.5.6 and 8.0.2. CVSSv3.1 8.8 (HIGH)

CWECWE 94VNDProtobufjs ProjectTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2026-44291 — JavaScript: protobufjs compiles protobuf definitions into JavaScript (JS) functions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44291

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode functions. If Object.prototype had already been polluted, those lookup tables could resolve attacker-controlled inherited properties as valid protobuf type information. This could cause attacker-controlled strings to be emitted into generated JavaScript cod CVSSv3.1 8.1 (HIGH)

CWECWE 94TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-13
2026-05-13 16:16Z
HIGH

CVE-2026-42945 — NGINX: This may cause a heap buffer overflow in the NGINX worker process leading to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42945

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This CVSSv3.1 8.1 (HIGH)

CWECWE 122VNDNginxTYPVulnerability
8.1
CVSS v3.1
91
Edit Score