Overview of incoming advisories.
1553 results found
CVE-2026-61754 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker exploiting this flaw could achieve remote code execution, tamper with data, or disclose sensitive information. The vulnerability is currently undergoing analysis by NVD. NVIDIA has published a security advisory referencing this CVE. Deserialization vulnerabilities are particularly dangerous as they can lead to full system compromise without requiring authentication in some configurations. The issue is tracked under NVIDIA's product security repository for 2026. Users of NVIDIA Megatron Bridge should monitor for patches and apply mitigations as soon as they become available.
View original advisory →CVE-2026-61768 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, a well-known class of vulnerability that can be exploited by attackers to achieve remote code execution. A successful exploit could also lead to data tampering and information disclosure. NVIDIA has published a security advisory referencing this CVE. The vulnerability is tracked on NVD (nvd.nist.gov) and CVE.org. No specific exploit details or active exploitation indicators are mentioned in the article. The impact is rated as high, making it a priority for patching in environments running NVIDIA Megatron Bridge. Organizations using this product should apply vendor-provided mitigations or patches promptly.
View original advisory →appium-mcp-server versions through 0.1.61 contain a path traversal vulnerability in the write_file and write_files_batch tools. The server fails to validate or normalize file paths, allowing attackers to write files outside the intended PROJECT_ROOT directory. Attackers can exploit this by supplying absolute paths or relative paths containing parent directory segments (e.g., ../). This enables overwriting of arbitrary files with the privileges of the server user. Sensitive targets include shell profiles and configuration files located in the home directory. The vulnerability poses a significant risk as it can lead to privilege escalation or persistent backdoor installation. No authentication bypass is required beyond access to the MCP server tools.
View original advisory →LibreNMS versions through 26.4.0 are vulnerable to stored/persistent cross-site scripting (XSS) due to improper output encoding of JSON fields returned by the admin-configurable Oxidized integration URL. Specifically, fields such as name, ip, model, author, and commit message are rendered into the device showconfig page without applying htmlspecialchars(). An administrator who configures the Oxidized URL to point at an attacker-controlled server (leveraging SSRF) can cause malicious JSON to be returned and stored, affecting all users who view any device's showconfig tab. The vulnerability requires administrator-level access to configure the malicious URL, but its impact extends to all users of the platform. The issue has been patched in LibreNMS version 26.7.0. References are available via the NVD, GitHub Security Advisory, and VulnCheck advisory pages.
View original advisory →CVE-2026-84119 is a high-severity vulnerability affecting Mozilla Firefox that allows sandbox escape through a use-after-free condition in the DOM Navigation component. This class of vulnerability can allow attackers to execute arbitrary code outside the browser sandbox, potentially compromising the underlying system. The flaw has been patched across multiple Firefox release channels including Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Use-after-free vulnerabilities in browser DOM components are considered critical as they can be exploited remotely via malicious web content. Multiple Mozilla Security Advisories (mfsa2026-82 through mfsa2026-85) have been published in connection with this vulnerability. Users are strongly advised to update to the fixed versions immediately. The vulnerability is currently awaiting full NVD analysis.
View original advisory →CVE-2026-51766 describes an incorrect access control vulnerability in the setDevReboot function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Unauthenticated attackers can exploit this flaw by sending a crafted MQTT message to the cs_broker component to trigger a device reboot. On mesh network master devices, the attack can fan out reboot commands to all connected mesh slave devices, amplifying the impact. No authentication is required to exploit this vulnerability, making it trivially accessible to remote attackers. The vulnerability affects the MQTT-based communication layer of the device's management interface. Successful exploitation results in denial of service through forced reboots across the mesh network. The issue has been documented in vendor coordination repositories on GitHub. TOTOLINK has been notified and download resources are referenced on their official site. The vulnerability poses a significant risk to network availability in environments using TOTOLINK T6 mesh deployments.
View original advisory →CVE-2026-18550 affects the Nokri Job Board WordPress Theme in all versions up to and including 1.6.6. The vulnerability exists in the nokri_reset_password() function due to insufficient reset token validation. Attackers can supply an empty reset token that matches empty or unset sb_password_forget_token user meta values. This allows unauthenticated attackers to reset passwords for any user account, including administrators. Successful exploitation leads to full account takeover and privilege escalation. No authentication is required to exploit this vulnerability. The flaw is classified as a Privilege Escalation via Account Takeover. Users are advised to update beyond version 1.6.6 to remediate the issue.
View original advisory →Kyverno versions before 1.16.4 contain a critical vulnerability where the admission controller automatically attaches its ServiceAccount token to outbound HTTP requests when operating in apiCall service mode. This occurs without requiring explicit authorization headers, creating a significant security risk. Attackers can exploit this by directing apiCall requests to external or attacker-controlled endpoints to capture the token. Once obtained, the exfiltrated token grants full control over Kyverno policies and cluster resources. The vulnerability affects Kubernetes clusters using Kyverno as a policy engine. The fix is available in Kyverno version 1.16.4 and later. Users are advised to upgrade immediately to mitigate the risk of credential theft and cluster compromise.
View original advisory →A SQL injection vulnerability has been discovered in Chanjet CRM versions up to 20260707. The flaw exists in the file jxf_dump_table.php, where manipulation of the argument gblOrgID allows SQL injection attacks. The vulnerability can be exploited remotely, making it accessible to a wide range of attackers. A public exploit has already been published and is available for use. The vendor was notified early in the disclosure process but failed to respond, leaving users without an official patch or mitigation. This unpatched state combined with a public exploit significantly increases the risk of exploitation in the wild.
View original advisory →A critical command injection vulnerability has been discovered in ICP DAS UA-2200 and UA-5200 devices up to firmware version 20260704. The flaw exists in the ArmAngstromInstructionSet function within the /CGI?RestApi=SetHostname endpoint, where manipulation of the ParameterArray argument enables command injection. The vulnerability is remotely exploitable without physical access to the affected device. A public exploit has been published, increasing the risk of active exploitation. The vendor was notified early in the disclosure process but did not respond, leaving users without an official patch or mitigation guidance. This affects industrial IoT/OT devices commonly used in automation and control environments. The unpatched status and public exploit availability make this a high-priority concern for organizations using these devices.
View original advisory →CVE-2026-51766 describes an incorrect access control vulnerability in the setDevReboot function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. Unauthenticated attackers can exploit this flaw by sending a crafted MQTT message to the cs_broker component to force a device reboot. In mesh network configurations, a compromised master device can propagate reboot commands to all slave nodes, amplifying the impact. The vulnerability requires no authentication, making it trivially exploitable remotely. This can result in denial of service across an entire mesh network. The issue has been documented via GitHub-based CVE vendor coordination repositories. TOTOLINK's official website and firmware download pages are referenced as part of the disclosure. No patch status is confirmed in the article content.
View original advisory →A SQL injection vulnerability has been identified in Chanjet CRM versions up to 20260707. The flaw exists in the file jxf_dump_table.php, where manipulation of the gblOrgID argument allows for SQL injection attacks. Remote exploitation is possible, making this a significant risk for affected deployments. A public exploit has been published and is available for use by threat actors. The vendor was notified prior to disclosure but did not respond, leaving users without an official patch or mitigation. This unpatched status, combined with public exploit availability, raises the severity of the issue considerably. Organizations using Chanjet CRM should take immediate precautionary measures to limit exposure.
View original advisory →CVE-2026-61776 is a high-severity vulnerability in NVIDIA Megatron Bridge involving deserialization of untrusted data. An attacker exploiting this flaw could achieve remote code execution, data tampering, and information disclosure. The vulnerability is catalogued by NVD and NVIDIA's product security team. No patch or workaround details are provided in the article. The issue highlights risks associated with unsafe deserialization in AI/ML infrastructure components. NVIDIA has published a security advisory on their GitHub repository. The vulnerability is classified as high impact given the potential consequences of successful exploitation.
View original advisory →CVE-2026-61778 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, data tampering, and information disclosure. The vulnerability is currently undergoing analysis by NVD. The issue is documented in NVIDIA's product security advisories on GitHub. Deserialization vulnerabilities are considered high severity due to their potential for arbitrary code execution. No patch or mitigation details are provided in the current article content.
View original advisory →CVE-2026-84121 is a high-severity vulnerability in Mozilla Firefox involving a use-after-free condition in the DOM Security component that allows a sandbox escape. The flaw enables attackers to potentially break out of the browser's security sandbox, which is a critical containment boundary. It affects multiple Firefox release lines including the standard and ESR (Extended Support Release) branches. Mozilla has addressed the issue in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Multiple Mozilla Security Advisories (mfsa2026-82 through mfsa2026-85) were published in conjunction with the fix. The vulnerability is tracked in Mozilla's Bugzilla under bug ID 2059018. Use-after-free vulnerabilities in browser engines are commonly leveraged in sophisticated attacks, including drive-by exploits and targeted campaigns. Users and organizations are strongly advised to update to the patched versions immediately.
View original advisory →CVE-2026-73701 is a critical unauthenticated remote code execution vulnerability affecting HPE Networking Fabric Composer. The flaw resides in the underlying operating system of the product and can be exploited if certain preconditions outside the attacker's control are met. Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code with elevated privileges on the host operating system. This could lead to complete compromise of the HPE Networking Fabric Composer host. The vulnerability is currently awaiting full analysis on NVD. HPE has published a security bulletin addressing this issue. No active exploitation details are currently disclosed. The severity is considered high due to the unauthenticated nature and potential for full system compromise.
View original advisory →AVideo contains a cross-site request forgery (CSRF) vulnerability in the plugin/API/set.json.php endpoint. The flaw allows attackers to craft malicious GET requests that bypass CSRF protections and perform unauthorized state-changing actions. By navigating a victim's browser to a specially crafted URL, attackers can delete videos, deactivate user accounts, or modify playlists without any user interaction. The vulnerability stems from the API accepting GET requests for operations that should require authenticated POST requests with CSRF tokens. This represents a significant risk to AVideo deployments as exploitation requires only that a logged-in user visit a malicious URL. The vulnerability is tracked as CVE-2026-83595 and has been documented in both the GitHub security advisories and VulnCheck advisories.
View original advisory →CVE-2026-61768 is a high-severity vulnerability in NVIDIA Megatron Bridge involving deserialization of untrusted data. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is currently undergoing analysis by NVD. NVIDIA has published a security advisory referencing this CVE. The flaw resides in the Megatron Bridge component, which is part of NVIDIA's AI and large-scale model training infrastructure. No patch or workaround details are included in the current article, but the issue is tracked via NVIDIA's product security repository. The impact is considered high given the potential for full code execution and data compromise.
View original advisory →CVE-2026-61757 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is catalogued by NVD at NIST and also tracked by the CVE program. NVIDIA has published security advisories referencing this CVE in their product-security GitHub repository. The current criticality is rated High, reflecting the severe potential impact of successful exploitation. No additional technical details or proof-of-concept code are mentioned in the article.
View original advisory →CVE-2026-61763 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is currently undergoing analysis by NVD. NVIDIA has published a security advisory referencing this CVE in their product-security repository. The flaw represents a high-severity risk given the potential for full code execution on affected systems. Organizations using NVIDIA Megatron Bridge should monitor for patches and apply mitigations as soon as they become available.
View original advisory →