Последние посты

CVE Notify
23 сент., 12:21
🚨 CVE-2026-96446 A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent authentication path prompt=none is used, which allows the authorization process to skip certain steps if a user is already logged in. Due to this bypass, the security rule that ensures a pushed request URI is used only once is not enforced. An attacker could potentially reuse a request URI to obtain multiple authorization codes for a user who is already signed in, violating security standards like FAPI-2.🎖@cveNotifyRedhatCVE-2026-96446 - Red Hat Customer PortalCVE Details App
CVE Notify
23 сент., 12:21
🚨 CVE-2026-96445 A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow an attacker who already has a user's password to bypass the second-factor authentication by providing a specially crafted header in their request.🎖@cveNotifyRedhatCVE-2026-96445 - Red Hat Customer PortalCVE Details App
CVE Notify
23 сент., 12:21
🚨 CVE-2026-87022 Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121.The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.56 through 7.0.109. Other unsupported versions may also be affected.Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.1.22, which fix the issue.🎖@cveNotify
CVE Notify
23 сент., 12:21
🚨 CVE-2026-86350 Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused by a regression in fix for CVE-2026-41293 can trigger request header mix-up.This issue affects Apache Tomcat: from 11.0.22 through 11.0.25, from 10.1.55 through 10.1.59, from 9.0.118 through 9.0.121.Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.🎖@cveNotify
CVE Notify
23 сент., 12:21
🚨 CVE-2026-86248 CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.25, from 10.1.22 through 10.1.59, from 9.0.92 through 9.0.121.Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.🎖@cveNotify
CVE Notify
23 сент., 12:21
🚨 CVE-2026-84791 ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to modify Change Management report schedule configurations for firewalls outside their assigned scope.🎖@cveNotifyManageEngineSecurity Updates - CVE-2026-19599 | ManageEngine OpManagerBroken Access Control vulnerability- CVE-2026-84791Severity: HighCVE ID: CVE-2026-84791
CVE Notify
23 сент., 12:21
🚨 CVE-2026-84789 ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.710 and below were vulnerable to a Broken Access Control vulnerability that allowed an authenticated low-privilege user to create alert notifications for firewalls outside their assigned scope.🎖@cveNotifyManageEngineSecurity Updates - CVE-2026-19599 | ManageEngine OpManagerBroken Access Control vulnerability- CVE-2026-84789Severity: HighCVE ID: CVE-2026-84789
CVE Notify
23 сент., 12:21
🚨 CVE-2026-80444 URL redirection to untrusted site ('open redirect') vulnerability in Abis Technology Ltd. Co. AVESİS allows Input Data Manipulation.This issue affects AVESİS: from 202608201331 before 202608240351.🎖@cveNotifysiberguvenlik.gov.trT.C. Siber Güvenlik BaşkanlığıTürkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
CVE Notify
22 сент., 20:03
🚨 CVE-2026-95862 A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.🎖@cveNotify
CVE Notify
22 сент., 20:03
🚨 CVE-2026-95861 A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.🎖@cveNotify
CVE Notify
22 сент., 20:03
🚨 CVE-2026-89277 CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.🎖@cveNotifyAdobeAdobe Security BulletinSecurity updates available for Content Credentials SDK | APSB26-147
CVE Notify
22 сент., 20:03
🚨 CVE-2026-88415 MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). The article content field contentDetails is excluded from the global XSS filter.🎖@cveNotifyGitHubStored XSS via CMS Article Content (contentDetails) in MCMS · Issue #2 · 15536818056/CVEAffected Environment Project: MCMS (MengCMS / 铭飞MCMS) Repository: https://github.com/ming-soft/MCMS,https://gitee.com/mingSoft/MCMS Affected Version: 6.1.1, 6.2.0, 6.2.1 Technology Stack: Java, Spr...
CVE Notify
22 сент., 20:03
🚨 CVE-2026-88414 MCMS 6.1.1 through 6.2.1 contains a SQL injection vulnerability in the PageAction.verify endpoint (GET /ms/mdiy/page/verify.do).🎖@cveNotifyGitHubStacked SQL Injection in MCMS PageAction.verify via Dynamic Column Name Concatenation · Issue #1 · 15536818056/CVE0. Submission Metadata Field Value CVE ID (To be assigned by MITRE) Vulnerability Title Stacked SQL Injection in MCMS PageAction.verify via Dynamic Column Name Concatenation Product MCMS (铭飞 CMS / ...
CVE Notify
22 сент., 20:03
🚨 CVE-2026-84396 InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.🎖@cveNotifyAdobeAdobe Security BulletinSecurity Update Available for Adobe InDesign | APSB26-145
CVE Notify
22 сент., 20:03
🚨 CVE-2026-84395 Premiere Pro [NEEDS REVIEW: environment mismatch — product 'Premiere Pro' is only known to appear in the 'Bucket A' bucket but environment_type 'Desktop' is in the 'Bucket A' bucket. This changes the exploitation clause and/or ATO eligibility — verify before publishing.] is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.🎖@cveNotifyAdobeAdobe Security BulletinSecurity Updates Available for Adobe Premiere Pro | APSB26-157
CVE Notify
22 сент., 20:02
🚨 CVE-2026-83963 Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.🎖@cveNotifyAdobeAdobe Security BulletinSecurity updates available for Adobe Substance3D - Modeler | APSB26-155
CVE Notify
22 сент., 20:02
🚨 CVE-2026-83962 Substance3D - Modeler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.🎖@cveNotifyAdobeAdobe Security BulletinSecurity updates available for Adobe Substance3D - Modeler | APSB26-155
CVE Notify
22 сент., 20:02
🚨 CVE-2026-82000 Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.🎖@cveNotifyAdobeAdobe Security BulletinSecurity updates available for Adobe Experience Manager (AEM) Forms | APSB26-97
CVE Notify
22 сент., 20:02
🚨 CVE-2026-81999 Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to internal resources. Exploitation of this issue does not require user interaction. Scope is changed.🎖@cveNotifyAdobeAdobe Security BulletinSecurity updates available for Adobe Experience Manager (AEM) Forms | APSB26-97
CVE Notify
22 сент., 20:02
🚨 CVE-2026-81998 Substance3D - Modeler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.🎖@cveNotifyAdobeAdobe Security BulletinSecurity updates available for Adobe Substance3D - Modeler | APSB26-155
