Overview of incoming advisories.
1553 results found
CVE-2026-61765 is a high-severity vulnerability identified in NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, a well-known class of security weakness that can be exploited by attackers to achieve remote code execution, manipulate data, and exfiltrate sensitive information. NVIDIA has published a security advisory linked through their product-security GitHub repository. The vulnerability is tracked on both the NVD and CVE.org databases. Successful exploitation could have serious consequences for affected deployments, including full system compromise. Organizations using NVIDIA Megatron Bridge are advised to review the advisory and apply any available patches or mitigations promptly. The current criticality rating is High.
View original advisory →A vulnerability was identified in Cleo Harmony versions up to 5.8.1.10 affecting the JWT Refresh Token Handler component at the /api/connections endpoint. The flaw allows manipulation of the Bearer argument, leading to improper privilege management. The vulnerability is remotely exploitable and a public exploit has been released, increasing the risk of active exploitation. Affected users are advised to upgrade to version 5.8.1.11, which resolves the issue. The vulnerability has been assigned CVE-2026-84115 and is tracked by both NVD and VulDB.
View original advisory →CVE-2026-51743 is an incorrect access control vulnerability in the guest_wifi_sync function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Unauthenticated attackers can exploit this flaw by sending a crafted MQTT message to the cs_broker component. Successful exploitation allows attackers to disable guest virtual AP interfaces on the affected device. The vulnerability requires no authentication, lowering the barrier for exploitation significantly. TOTOLINK T6 is a consumer/SOHO router, making this a network infrastructure concern. The issue has been reported via GitHub-based CVE vendor coordination repositories. No patch information is explicitly mentioned in the article. The vulnerability was sourced from the NVD (National Vulnerability Database). Related references include TOTOLINK's official website and firmware download pages.
View original advisory →CVE-2026-61754 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is tracked by NVD and NVIDIA's own product security advisory system. NVIDIA has published a security advisory referencing this CVE. The severity is rated High, indicating significant risk to affected systems. Organizations using NVIDIA Megatron Bridge should review the advisory and apply any available patches or mitigations promptly.
View original advisory →A critical vulnerability (CVE-2026-76657) has been identified in the API of HPE Networking Fabric Composer that allows unauthenticated remote attackers to bypass existing authentication controls. Successful exploitation can grant an attacker full administrative privileges over the affected system. This leads to a complete compromise of the HPE Networking Fabric Composer host. The vulnerability requires no prior authentication, significantly lowering the barrier for exploitation. HPE has published a security bulletin with further details and remediation guidance. The flaw is currently awaiting full analysis on the NVD. Organizations using HPE Networking Fabric Composer should prioritize patching or applying mitigations immediately. The impact is rated high due to the potential for full system takeover by remote, unauthenticated actors.
View original advisory →CVE-2026-61759 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published security guidance through their product security repository on GitHub. The flaw is classified with a high criticality rating, reflecting the severity of potential impacts including full system compromise. No additional technical details or proof-of-concept exploits are referenced in the current advisory. Users of NVIDIA Megatron Bridge should monitor NVIDIA's official security advisories for patches and mitigations.
View original advisory →A SQL injection vulnerability has been identified in Teracity Software Technologies Inc.'s E-OSB product. The vulnerability is classified as an improper neutralization of special elements used in SQL commands (CWE-89). It allows attackers to perform SQL injection attacks against affected installations. All versions of E-OSB prior to V02.26.07.08.01 are affected. The vulnerability has been assigned CVE-2026-18765 and is published on the NVD. Users are advised to upgrade to version V02.26.07.08.01 or later to remediate the issue. The advisory was also published by the Turkish cybersecurity authority siberguvenlik.gov.tr. The criticality has been assessed as High given the nature of SQL injection vulnerabilities.
View original advisory →A vulnerability in the NetStaX EtherNet/IP Stack prior to version 5.6.1 allows a large Class 3 explicit-message request to silently overflow the application-side receive buffer. The flaw is particularly dangerous because no error or warning is generated, meaning the originating device receives no CIP error indicating the request failed. Potential consequences include memory corruption, device crashes, and exploitation as a remote attack vector. The vulnerability affects industrial control system components using the EtherNet/IP protocol stack developed by Pyramid Solutions. The issue is silently exploitable, increasing risk in operational technology (OT) environments. A fix has been issued in NetStaX version 5.6.1. This type of vulnerability is especially concerning in critical infrastructure contexts where reliability and availability are paramount.
View original advisory →CVE-2026-61777 is a high-severity vulnerability identified in NVIDIA Megatron Bridge involving deserialization of untrusted data. An attacker exploiting this flaw could achieve remote code execution, tamper with sensitive data, and exfiltrate information. The vulnerability was published via the National Vulnerability Database (NVD) and is tracked under NVIDIA's product security advisories. Deserialization vulnerabilities are particularly dangerous as they can allow attackers to execute arbitrary code without authentication. NVIDIA has published a security advisory on GitHub detailing the issue. The CVE record is also available through the CVE.org registry. Users and administrators of NVIDIA Megatron Bridge are advised to review the advisory and apply any available patches promptly.
View original advisory →CVE-2026-61759 is a high-severity vulnerability identified in NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, a well-known class of vulnerability that can be exploited by attackers to achieve arbitrary code execution. Beyond code execution, successful exploitation may also result in data tampering and information disclosure. The vulnerability is tracked by NVD (National Vulnerability Database) and has been reported via NVIDIA's product security advisories. No patch or workaround details are included in the current article content, which reflects an early 'Received' status in the NVD workflow. Given the potential impact of code execution and data integrity compromise, the vulnerability is rated as high criticality. Organizations using NVIDIA Megatron Bridge should monitor NVIDIA's official security advisories for mitigations and patches.
View original advisory →CVE-2026-61750 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which could be exploited by an attacker to achieve remote code execution, tamper with data, or disclose sensitive information. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published details in their product-security repository on GitHub. Successful exploitation could have significant impact on confidentiality, integrity, and availability of affected systems. No patch or workaround details are included in the current article content. Organizations using NVIDIA Megatron Bridge should monitor for updates from NVIDIA and the NVD.
View original advisory →Scrapy, a Python web crawling and scraping framework, contains a vulnerability in its S3DownloadHandler prior to version 2.17.0. The handler converts S3-scheme requests into plaintext HTTP requests by default unless 'is_secure' is explicitly enabled, then signs and transmits them with AWS credentials. This exposes sensitive data including bucket paths, AWS Authorization headers, security tokens, and S3 object contents to network observers. An active man-in-the-middle attacker can also tamper with S3 responses, enabling scraped-data poisoning, HTTP cache poisoning, and manipulation of crawl targets via forged redirects. All users making S3-scheme requests with AWS credentials are affected. The vulnerability has been patched in Scrapy version 2.17.0.
View original advisory →A vulnerability was identified in Cleo Harmony versions up to 5.8.1.10 affecting the JWT Refresh Token Handler component at the /api/connections endpoint. The flaw involves improper privilege management triggered by manipulation of the Bearer argument, potentially allowing unauthorized privilege escalation. The vulnerability is remotely exploitable and a public exploit is available, raising the risk of active exploitation. Cleo has released version 5.8.1.11 to address the issue, and users are strongly advised to upgrade immediately. The vulnerability has been documented on NVD and VulDB, with multiple references available for technical details and release notes.
View original advisory →CVE-2026-61770 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and cause information disclosure. The vulnerability is currently undergoing analysis by NVD. NVIDIA has published security advisory details via their product-security GitHub repository. The flaw is classified as high severity given its potential impact on code execution and data integrity. No patch or mitigation details are explicitly mentioned in the article content, but the advisory reference suggests NVIDIA is addressing the issue. This vulnerability is particularly notable given Megatron Bridge's role in AI/ML infrastructure environments.
View original advisory →Multiple vulnerabilities have been identified in a daemon component of HPE's AOS-CX network operating system. The flaws stem from improper processing of malformed input, allowing unauthenticated remote attackers to exploit them by sending specially crafted packets. Successful exploitation can result in remote code execution with elevated privileges. No authentication is required, making this particularly dangerous for exposed network devices. The vulnerabilities affect HPE AOS-CX, which runs on Aruba/HPE switching hardware. An official advisory has been published by HPE via their support portal. Organizations running AOS-CX should apply patches or mitigations as soon as they become available. The severity is high due to the unauthenticated RCE potential with privilege escalation.
View original advisory →A critical flaw was identified in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows attackers to bypass the denylist originally introduced to mitigate CVE-2018-1000130. The proxy accepts a target.url parameter from POST requests and passes it directly to JMXServiceURL and JMXConnectorFactory without adequate filtering. The existing denylist only blocks URLs matching 'service:jmx:rmi:///jndi/ldap:.*', which can be bypassed using alternative JMX service URL forms such as ldaps:// schemes or LDAP URLs with non-empty JMX host components. These bypass URLs are accepted as valid JMXServiceURL objects, causing the Jolokia agent JVM to perform JNDI lookups against attacker-controlled LDAP endpoints. The vulnerability can result in server-side request forgery (SSRF), credential forwarding to remote endpoints, and potentially remote code execution depending on the target JVM configuration and available classes.
View original advisory →CVE-2026-19766 describes a critical authentication bypass vulnerability in the underlying operating system of HPE Networking Fabric Composer (AFC). An unauthenticated attacker with adjacent network access can exploit this flaw to execute arbitrary code as a privileged user on the underlying OS. Successful exploitation leads to complete compromise of the AFC host. No authentication is required, lowering the barrier for exploitation significantly. The vulnerability is classified as high severity given the potential for full system takeover. HPE has published a security bulletin with remediation guidance. The attack vector is adjacent network, meaning the attacker must be on the same network segment. This represents a significant risk for organizations using HPE networking management infrastructure.
View original advisory →CVE-2026-61761 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve code execution, data tampering, and information disclosure. The vulnerability was published by NVD and is also tracked on the CVE.org record. NVIDIA has published a security advisory referencing this issue in their product-security GitHub repository. No specific exploit code or active exploitation details are currently provided in the article. The vulnerability poses significant risks to environments running NVIDIA Megatron Bridge, particularly in AI/ML infrastructure contexts. Users and administrators are advised to review the NVIDIA advisory and apply any available patches or mitigations promptly.
View original advisory →Kyverno versions before 1.18.0 contain a server-side request forgery (SSRF) vulnerability in the apiCall.service.url parameter. Authenticated users can inject user-controlled input through variable substitution to send arbitrary HTTP requests. Attackers can leverage this to target internal services, cloud metadata endpoints (e.g., AWS/GCP/Azure IMDS), and loopback addresses. The vulnerability is particularly dangerous because response data is reflected back in admission error messages, enabling non-blind data exfiltration. This means attackers can read the responses from internal requests, making it a high-impact SSRF. The flaw affects Kubernetes policy engine Kyverno and could be exploited by any authenticated cluster user. Users are advised to upgrade to Kyverno 1.18.0 or later to remediate the issue.
View original advisory →An unauthenticated remote code execution vulnerability has been identified in the underlying operating system of HPE Networking Fabric Composer. The vulnerability can be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code as a privileged user. This could lead to complete compromise of the HPE Networking Fabric Composer host. The vulnerability is classified as high severity given its potential for full system takeover without authentication. HPE has published a security bulletin with further details and remediation guidance. No authentication is required to exploit this vulnerability, significantly increasing its risk profile.
View original advisory →