2w ago
2026-09-01 13:20Z
HIGH

CVE-2026-84131 — Privilege: escalation due to invalid pointer in the Graphics component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84131

Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. CVSSv3.1 8.8 (HIGH)

CWECWE 763TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84129 — Site: isolation issue in the DOM: Navigation component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84129

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. CVSSv3.1 9.8 (CRITICAL)

CWECWE 346TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:20Z
HIGH

CVE-2026-84128 — Privilege: escalation in the WebDriver BiDi component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84128

Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 13:20Z
HIGH

CVE-2026-84123 — Privilege: escalation due to use-after-free in the Graphics: WebGPU component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84123

Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2. CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84121 — Sandbox: escape due to use-after-free in the DOM: Security component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84121

Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-09-01 13:20Z
CRIT

CVE-2026-84119 — Sandbox: escape due to use-after-free in the DOM: Navigation component.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84119

Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. CVSSv3.1 9.6 (CRITICAL)

CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2w ago
2026-09-01 13:20Z
HIGH

CVE-2026-84117 — Privilege: escalation in Firefox for Android.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84117

Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2w ago
2026-09-01 13:19Z
HIGH

CVE-2026-79683 — Dell: PowerStore contains a Protection Mechanism Failure vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-79683

Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths. CVSSv3.1 8.8 (HIGH)

CWECWE 693VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 13:19Z
HIGH

CVE-2026-58575 — Dell: PowerStore contains an Authentication Bypass by Spoofing vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58575

Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator. CVSSv3.1 8.8 (HIGH)

CWECWE 290VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 13:19Z
CRIT

CVE-2026-51747 — Incorrect: access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51747

Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:19Z
CRIT

CVE-2026-51744 — Incorrect: access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51744

Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:19Z
CRIT

CVE-2026-51743 — Incorrect: access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51743

Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker component. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2w ago
2026-09-01 13:19Z
CRIT

CVE-2026-51741 — Incorrect: access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51741

Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi. CVSSv3.1 9.8 (CRITICAL)

CWECWE 284TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 13:18Z
CRIT

CVE-2026-18765 — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18765

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 12:17Z
CRIT

CVE-2026-84200 — Kyverno: When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84200

Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that matches the second exception's name pattern (e.g., '*ingress*'). This can be used to circumvent policies such as one blocking hostPath volumes. Fixed in v1.13.0. CVSSv3.1 9.0 (CRITICAL)

CWECWE 284VNDKyvernoTYPVulnerability
9.0
CVSS v3.1
95
Edit Score
2w ago
2026-09-01 12:17Z
HIGH

CVE-2026-84189 — LibreNMS: An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can cause

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84189

LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who points the Oxidized URL at an attacker-controlled server (SSRF) can cause it to return malicious JSON, resulting in stored/persistent cross-site scripting affecting all users who view any device's showconfig tab. Fixed in 26.7.0. CVSSv3.1 8.1 (HIGH)

CWECWE 79VNDLibrenmsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 12:17Z
HIGH

CVE-2026-84187 — AVideo: contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-84187

AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with schedule identifiers. Attackers can exploit the unguarded RTMP callback endpoint to modify scheduled broadcast status fields by supplying fabricated stream keys matching the pattern -ps-<N>, silently canceling any scheduled live broadcast without credentials or authoriz CVSSv3.1 8.2 (HIGH)

CWECWE 284VNDAvideoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 12:17Z
HIGH

CVE-2026-83595 — AVideo: contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83595

AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers can navigate a victim's browser to a malicious URL with API parameters to delete videos, deactivate accounts, or modify playlists without user interaction. CVSSv3.1 8.1 (HIGH)

CWECWE 352VNDAvideoTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2w ago
2026-09-01 12:17Z
HIGH

CVE-2026-76111 — Dell: PowerStore contains an Incorrect Authorization vulnerability.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-76111

Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation. CVSSv3.1 8.8 (HIGH)

CWECWE 863VNDDellTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 12:17Z
CRIT

CVE-2026-18550 — Nokri: The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-18550

The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token validation in the `nokri_reset_password()` function, which allows empty attacker-supplied reset tokens to match empty or unset `sb_password_forget_token` user meta values. This makes it possible for unauthenticated attackers to reset the password of any user, including administrators CVSSv3.1 9.8 (CRITICAL)

CWECWE 269VNDNokriTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2w ago
2026-09-01 10:17Z
HIGH

CVE-2026-59681 — A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59681

A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the configured host. Auth::AuthConf in src/lib/auth/authconf.rb assembles the Samba net ads join, net ads lookup -S and net ads testjoin invocations by interpolating configuration values into a single command string and passing that string to Open3.popen2 / Open3.capture2, which causes Ruby to run it through CVSSv3.1 8.8 (HIGH)

CWECWE 78TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2w ago
2026-09-01 10:17Z
HIGH

CVE-2026-59680 — An OS command injection vulnerability was found in yast2-users.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-59680

An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to format_days_after_epoch(). That helper interpolated the value into a shell command executed via Ruby backticks without quoting or escaping. Impact: an administrator wh CVSSv3.1 8.0 (HIGH)

CWECWE 78CWECWE 1287TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2w ago
2026-09-01 10:01Z
CRIT

Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586

Horizon3.ai·horizon3.aiCVE-2026-9586in the wild

Horizon3 discovered and disclosed CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox leading to remote code execution via the /pa endpoint. The vulnerability was patched in version 8.4.0.2 on July 14, 2026, but active exploitation in the wild was observed by August 30, 2026, with attackers targeting approximately 4,000 internet-exposed instances. The attack chain involves XML parsing of phone notification messages, direct SQL concatenation of the PhoneIP field, and execution as a PostgreSQL superuser.

SRFApplicationTACTA0001TACTA0002SRFNetworkSWSwitchvoxVNDSangomaTYPResearchTYPVulnerability
92
Edit Score
2w ago
2026-09-01 07:00Z
HIGH

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Kaspersky Securelist·securelist.com

Kaspersky discovered NodeRabbit and PollCat, two previously undocumented Node.js and JavaScript-based RATs deployed by Mirage Kitten APT group targeting aviation and FinTech sectors across Middle East and Africa. The malware is delivered via trojanized coding challenge archives distributed through fake recruiter outreach on job platforms, with three NodeRabbit variants showing progressive sophistication including sandbox evasion, proxy support, and dual persistence mechanisms via VS Code extensions and Git hooks.

SRFApplicationTACTA0005TACTA0001TACTA0003TACTA0011SRFSupply ChainVNDKasperskyTYPResearch
82
Edit Score
2w ago
2026-09-01 06:16Z
CRIT

CVE-2026-83772 — Cobham: The manipulation of the argument sender/recipients results in command injection.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-83772

A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. CVSSv3.1 9.9 (CRITICAL)

CWECWE 74CWECWE 77VNDCobhamTYPVulnerability
9.9
CVSS v3.1
100
Edit Score