HOT NEWS 2026 OCTOBER January(174) February(168) March(221) April(222) May(261) June(255) July(464) August(446) September(518) October(45) November(0) December(0) | STATISTICS (7049)
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
4.10.26 |
Decoding emergence 2026 Microsoft Digital Defense Report |
The challenge confronting security leaders today is no longer a lack of information. It is the growing complexity of the environments they are responsible for protecting. | REPORT | REPORT |
|
4.10.26 |
CVE-2026-104286 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
FBI INTERNET CRIME REPORT 2025 | In 2025, the FBI Internet Crime Complaint Center (IC3) celebrated its 25th anniversary as the central hub for reporting cyber-enabled crime. This milestone signifies the FBI's enduring commitment to fighting the ever-evolving cyber threat. Our success in protecting individuals and organizations is driven by public participation and robust data analysis. | REPORT | REPORT |
|
4.10.26 |
Warlock | Warlock Ransomware Attackers Hit Water and Telecom Operators | RANSOM | RANSOM |
|
4.10.26 |
CVE-2026-92371 | TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-92369 | TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-19743 | Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-92368 | TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-92370 | An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-102489 | Zammad GmbH Zammad Session Fixation Vulnerability: Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. | ECV | ECV |
|
3.10.26 |
CVE-2026-102490 | Zammad GmbH Zammad Improper Privilege Management Vulnerability: Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. | ECV | ECV |
|
4.10.26 |
CVE-2026-104286 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-92371 | TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-92369 | TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-19743 | Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-92368 | TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-92370 | An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.This vulnerability is due to improper handling of URI encoding | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
Cisco IOS XE Software Security Hardening Release: August 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-90970 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-67273 | (CVSS score: 9.6) - An improper neutralization of special elements used in a template engine vulnerability that a low-privilege attacker with remote access could exploit to escalate privileges, access sensitive information, and carry out unauthorized RBAC tampering. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-61421 | (CVSS score: 9.8) - A use of hard-coded cryptographic key vulnerability in the JWT authentication component of karavi-authorization that a remote unauthenticated attacker with knowledge of this publicly available signing secret could exploit to forge authentication tokens and gain administrative privileges. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-54472 | (CVSS score: 9.8) - A use of hard-coded credentials vulnerability in the CSM Authorization module that a remote unauthenticated attacker could exploit to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM Authorization proxy. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-67269 | (CVSS score: 9.9) - An improper privilege management vulnerability in the ContainerStorageModule Custom Resource reconciler that a low-privilege remote attacker could exploit to escalate privileges and gain root-level access on cluster nodes. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-63692 | (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the authorization proxy and tenant service that an unauthenticated network attacker could exploit to bypass authentication controls and gain administrative-level privileges. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-63688 | (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an unauthenticated remote attacker could exploit to obtain unauthorized access to storage backend administrator credentials for all registered storage arrays. | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86950 | CVE-2026-86950: The Great Glyph Grift | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86134 Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86104 Fireware OS Resource Exhaustion in Login Process Allows Denial of Service | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-18145 Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-13046 Fireware OS Deserialization of Untrusted Data in samld Allows Remote Code Execution | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86101 Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86133 Fireware OS Pre-Authentication Integer Underflow in iked Allows Remote Denial of Service | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-13224 Fireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File Read | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86132 Fireware OS Pre-Authentication Integer Underflow in iked Allows Denial of Service | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86105 Fireware OS Improper Authorization in Access Portal Reverse Proxy | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-90441 Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant B | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86131 Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86136 Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant A | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-81433 Fireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code Execution | Fireware OS>= 2026.3, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86128 Fireware OS NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allows Remote Denial of Service | Default>= 2026.3, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-18105 Fireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of Service | Default>= 2026.3, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-101891 WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access | WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86102 WatchGuard AP Command Injection in Internal Management API Allows Command Execution | WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-87969 WatchGuard AP Authenticated Command Injection in Diagnostic CLI | WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8 | VULNEREBILITY | VULNEREBILITY |
|
|
|
|
|
|