Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)
CVSSv3.1 8.1 (HIGH)
CWECWE 863TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-02 00:18Z
CRIT
CVE-2026-84333 — Use: after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75
Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 9.6 (CRITICAL)
CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-09-02 00:18Z
HIGH
CVE-2026-84326 — Uninitialized: resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker
Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
CVSSv3.1 8.8 (HIGH)
CWECWE 908VNDUninitializedTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-02 00:18Z
CRIT
CVE-2026-84325 — DataTransfer: Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
CVSSv3.1 9.8 (CRITICAL)
CWECWE 20VNDDatatransferTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-02 00:18Z
CRIT
CVE-2026-84324 — Use: after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote
Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
CVSSv3.1 9.0 (CRITICAL)
SonicWall disclosed two critical vulnerabilities in SMA1000 appliances (models 6210, 7210, 8200v): CVE-2026-83548 is an unauthenticated SSRF (CVSS 10.0) in the Workplace interface enabling unauthorized access, and CVE-2026-83549 is an authenticated OS command injection (CVSS 7.8) in the Appliance Management Console. Both are confirmed in active exploitation in the wild.
REVSTEALER ramps up: analysis of up-and-coming infostealer
Elastic Security Labs·elastic.co
Elastic Security Labs published a comprehensive analysis of REVSTEALER, an emerging infostealer malware family with ~4,700 samples detected over the past year. The malware targets browser credentials, cryptocurrency wallets, gaming accounts (Battle.net, Steam, Roblox, Minecraft), and implements sophisticated anti-analysis features including a weighted sandbox scoring system, CIS-locale exclusion checks, and Polygon blockchain-based dead-drop C2 resilience. Distribution occurs primarily through YouTube account takeovers promoting fake game cheats and mod menus, with four follow-on modules (ProManager, WinUpdate, SoftManager, LockAppHost) delivering wallet theft, clipboard hijacking, reverse proxy access, and XMRig cryptomining.
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration changes.
CVSSv3.1 8.8 (HIGH)
CWECWE 346VNDWwbnTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 23:17Z
CRIT
CVE-2026-84480 — WWBN: AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 613VNDWwbnTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 23:17Z
CRIT
CVE-2026-84479 — WWBN: AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on
WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. An attacker who submits valid credentials and sets User-Agent: AVideoEncoder bypasses two-factor authentication, skips brute-force captcha escalation, and avoids being r
CVSSv3.1 9.1 (CRITICAL)
CWECWE 290VNDWwbnTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-09-01 22:17Z
CRIT
CVE-2026-84639 — Triggering: an error condition in certain MIME bodies would cause uninitialized memory to be
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 457VNDTriggeringTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-09-01 22:17Z
CRIT
CVE-2026-84637 — Malicious: calendar invitations could use file URI attachments to launch local or network-hosted executables
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading filename. This vulnerability was fixed in Thunderbird 154 and Thunderbird 153.2.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 434VNDMaliciousTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 22:17Z
CRIT
CVE-2026-84372 — Predis: From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF sequences can therefore be interpreted by Command::deserializeCommand() as additi
CVSSv3.1 9.8 (CRITICAL)
CWECWE 93VNDPredisTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 22:17Z
HIGH
CVE-2026-83549 — Sonicwall Sma8200v: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83549in the wild
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
CVSSv3.1 7.8 (HIGH) · EPSS 58th percentile
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CVSSv3.1 10.0 (CRITICAL)
CWECWE 918CWECWE 441VNDPreTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2w ago
2026-09-01 22:17Z
HIGH
CVE-2026-76851 — Github Enterprise_server: A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an internal service and redirect trusted internal requests to a privileged service, leading to elevated code execution. Exploitation required pre-receive hook networking to be enabled and either site administrator privileges or write access to a re
CVSSv3.1 8.8 (HIGH) · EPSS 37th percentile
CWECWE 918VNDGithubTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 22:17Z
CRIT
CVE-2026-75604 — Next: Disclosure of that key can enable remote code execution in the affected application.
Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before constructing incremental-cache paths. In packages/next/src/shared/lib/router/utils/escape-path-delimiters.ts and packages/next/src/server/lib/incremental-cache/file-system-cache.ts, a remote request can
CVSSv3.1 9.0 (CRITICAL)
CWECWE 22TYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2w ago
2026-09-01 22:17Z
CRIT
CVE-2023-54391 — Proxmox: Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification
CVSSv3.1 9.8 (CRITICAL)
CWECWE 304VNDProxmoxTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 21:18Z
HIGH
CVE-2026-84370 — SVGO: When an application processes attacker-controlled SVG input and serves the result in an active
SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, incompletely filters executable links in plugins/removeScripts.js and lib/svgo/tools.js. The plugin does not recognize namespace-prefixed SVG anchor elements such as svg:a with href or namespaced *:href values, and it does not remove
CVSSv3.1 8.2 (HIGH)
CWECWE 79CWECWE 184VNDSvgoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 21:18Z
HIGH
CVE-2026-73782 — A format string vulnerability exists in the command line interface of AOS-CX that could
A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVSSv3.1 8.8 (HIGH)
TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 21:18Z
HIGH
CVE-2026-73781 — A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote
A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
CVSSv3.1 8.4 (HIGH)
TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2w ago
2026-09-01 21:18Z
HIGH
CVE-2026-73780 — A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to
A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL.
CVSSv3.1 8.3 (HIGH)
TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2w ago
2026-09-01 21:18Z
HIGH
CVE-2026-73779 — Vulnerabilities: have been identified in the operating system of AOS-CX switches that could potentially
Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive information.
CVSSv3.1 8.2 (HIGH)
VNDVulnerabilitiesTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 21:18Z
HIGH
CVE-2026-73778 — Credential: A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative
A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative control of the affected device during the initial setup process.
CVSSv3.1 8.1 (HIGH)
TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 21:18Z
HIGH
CVE-2026-73777 — Vulnerabilities: have been identified in the API endpoint of AOS-CX switches that could potentially
Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.
CVSSv3.1 8.1 (HIGH)