Overzicht van binnengekomen advisories.
1553 resultaten gevonden
CVE-2026-19766 is an authentication bypass vulnerability in the underlying operating system of HPE Networking Fabric Composer (AFC). An unauthenticated attacker with adjacent network access can exploit this flaw to execute arbitrary code as a privileged user on the underlying OS. Successful exploitation leads to complete compromise of the AFC host. No authentication is required, lowering the bar for exploitation significantly. The vulnerability is currently awaiting full analysis by NVD. HPE has published a security bulletin with further details and remediation guidance. The severity is rated High due to the potential for full system takeover. Organizations using HPE Networking Fabric Composer should review the HPE advisory immediately and apply any available patches or mitigations.
Bekijk origineel advisory →CVE-2026-61767 is a high-severity vulnerability identified in NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, a class of vulnerability that can be particularly dangerous when exploited. A successful attack could lead to arbitrary code execution, data tampering, and unauthorized information disclosure. The vulnerability is currently undergoing analysis by NVD (National Vulnerability Database). NVIDIA has published security advisories related to this issue in their product-security repository. The vulnerability poses significant risk to environments running NVIDIA Megatron Bridge, potentially allowing attackers to fully compromise affected systems. Users and administrators are advised to monitor NVIDIA and NVD advisories for patches and mitigations.
Bekijk origineel advisory →CVE-2026-52130 affects llama.cpp versions up to and including build b5693. The vulnerability exists in the file common/json-schema-to-grammar.cpp and is classified as Uncontrolled Recursion. Exploitation of this vulnerability can result in a denial of service condition. The issue is tracked in the NVD and has been documented with a blog post and the official llama.cpp GitHub repository. llama.cpp is a widely used open-source library for running large language models locally. The vulnerability could be triggered by crafted input that causes unbounded recursive function calls, exhausting stack resources. Users are advised to update to a version beyond b5693 to mitigate the risk.
Bekijk origineel advisory →CVE-2026-61777 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published a security advisory via their product-security GitHub repository. The flaw is rated as high criticality given the potential impact of code execution and data compromise. No additional technical details or proof-of-concept exploits are referenced in the current advisory. Users of NVIDIA Megatron Bridge should monitor NVIDIA's security advisories for patches and mitigations.
Bekijk origineel advisory →A Use of Hard-coded Credentials vulnerability has been identified in TMT Machine Industry and Trade Ltd. Co.'s Talassoft Industrial Management Software. The vulnerability allows attackers to retrieve embedded sensitive data through the hard-coded credentials present in the software. Affected versions span from V.4 up to but not including V.16. The vulnerability is classified under CWE for hard-coded credentials and enables the 'Retrieve Embedded Sensitive Data' attack pattern. This is an industrial management software product, making the exposure of sensitive credentials particularly impactful for industrial environments. The issue has been assigned CVE-2026-18931 and is tracked by the Turkish cybersecurity authority (siberguvenlik.gov.tr). Users are advised to upgrade to V.16 or later to mitigate the risk.
Bekijk origineel advisory →The Nokri Job Board WordPress Theme is vulnerable to Privilege Escalation via Account Takeover in all versions up to and including 1.6.6. The vulnerability exists in the nokri_reset_password() function due to insufficient reset token validation. Attackers can supply an empty reset token that matches empty or unset sb_password_forget_token user meta values. This allows unauthenticated attackers to reset the password of any user, including administrators. Successful exploitation grants full account access without any prior authentication. The vulnerability is classified as critical given that it enables complete administrative account takeover. Users of the Nokri theme should update to a patched version immediately to mitigate the risk.
Bekijk origineel advisory →A denial-of-service vulnerability exists in the js-yaml JavaScript YAML parser affecting versions 3.0.0 through 3.15.1 and 4.0.0 through 4.3.1. The flaw lies in the maxTotalMergeKeys limit implementation in loader.js, which fails to count empty mapping sources when processing the YAML merge key '<<'. An attacker can craft a small malicious YAML document that aliases large sequences of empty mappings into many merge targets, triggering O(N * K) CPU processing while the configured resource limit counter remains unchanged. This allows prolonged CPU consumption in applications parsing untrusted YAML input, effectively causing a denial-of-service condition. Merge processing is enabled by default on affected release lines, broadening the attack surface. The vulnerability has been patched in versions 3.15.2 and 4.3.2. Users are strongly advised to upgrade to the fixed versions immediately.
Bekijk origineel advisory →CVE-2026-61751 describes a critical vulnerability in NVIDIA Megatron Bridge involving deserialization of untrusted data. An attacker who successfully exploits this vulnerability could achieve arbitrary code execution, tamper with data, and cause information disclosure. The vulnerability is tracked by NVD at NIST and has been acknowledged by NVIDIA's product security team. No additional technical details or CVSS score are currently published, though the potential impact is severe given the combination of code execution and data compromise outcomes. The advisory is referenced in NVIDIA's official product security GitHub repository. Users of NVIDIA Megatron Bridge should monitor for patches and apply mitigations promptly.
Bekijk origineel advisory →SVGO (SVG Optimizer), a Node.js library for optimizing SVG files, contains a vulnerability in its opt-in removeScripts plugin (called removeScriptElement in versions 2 and 3). Affected versions range from 1.0.0 up to but not including 2.8.4, 3.3.5, and 4.1.0. The plugin incompletely filters executable links by failing to recognize namespace-prefixed SVG anchor elements such as svg:a with href or namespaced *:href attributes. Additionally, it does not strip ASCII tab, line-feed, or carriage-return characters before checking URL schemes, which browsers silently remove before parsing, allowing malicious links to bypass the filter. When attacker-controlled SVG input is processed and served in an active browser context, a victim clicking the surviving link can trigger script execution within the SVG's origin. This could lead to data exposure, content modification, or unauthorized actions performed as the victim. Fixes are available in versions 2.8.4, 3.3.5, and 4.1.0.
Bekijk origineel advisory →A Code Injection vulnerability (CVE-2026-18808) has been identified in Klemsan Electrical Electronics Inc.'s KIO (Klemsan Internet Objects) product. The vulnerability is classified as Improper Control of Generation of Code, allowing attackers to perform code injection attacks. All versions of KIO prior to v1.9 are affected. The issue has been reported via the Turkish cybersecurity authority (siberguvenlik.gov.tr) and published on NVD. Users are advised to upgrade to v1.9 or later to remediate the vulnerability. The KIO product is an industrial IoT-oriented device, making this vulnerability particularly significant for operational technology environments. No additional exploitation details or proof-of-concept references are currently noted in the advisory.
Bekijk origineel advisory →CVE-2026-61763 is a critical vulnerability identified in NVIDIA Megatron Bridge involving deserialization of untrusted data. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is documented in the NVD and tracked by NVIDIA's product security team. NVIDIA has published an advisory in their product-security repository on GitHub. The impact is considered high given the potential for code execution and data compromise. No additional technical details or CVSS scores are provided in the current article state, which is marked as 'Received'. Users and administrators of NVIDIA Megatron Bridge are advised to monitor for patches and apply them promptly.
Bekijk origineel advisory →A stored cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of HPE Networking Fabric Composer. The vulnerability allows an authenticated low-privilege operator user to inject malicious scripts that target administrative users of the interface. A successful exploit enables the attacker to execute arbitrary script code within the victim's browser in the context of the affected interface. The attack requires authentication as a low-privilege user, lowering the barrier for exploitation in environments with multiple user roles. This type of privilege escalation via XSS can lead to session hijacking, credential theft, or further compromise of the administrative account. HPE has published a security bulletin addressing this issue. The vulnerability is currently awaiting full analysis by NVD.
Bekijk origineel advisory →CVE-2026-84119 is a high-severity vulnerability in Mozilla Firefox involving a use-after-free condition in the DOM Navigation component that allows for a sandbox escape. The flaw could potentially allow an attacker to break out of the browser sandbox, leading to arbitrary code execution or privilege escalation. Mozilla has addressed the issue in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Multiple security advisories were published by Mozilla (mfsa2026-82 through mfsa2026-85) covering this vulnerability. The bug was tracked internally via Bugzilla bug ID 2057817. Users and administrators are strongly advised to update to the patched versions immediately. The vulnerability is classified as critical due to the sandbox escape nature of the exploit, which bypasses a key browser security boundary.
Bekijk origineel advisory →A critical vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer (AFC). The flaw allows an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts without any credentials. Successful exploitation enables execution of arbitrary commands as a privileged user on the underlying operating system. This can lead to complete system compromise of affected HPE AFC hosts. The vulnerability is tracked as CVE-2026-76658 and has been assigned a high criticality rating. HPE has published a security bulletin providing remediation guidance. The attack vector is remote and requires no authentication, significantly raising its risk profile. Organizations using HPE Networking Fabric Composer are urged to apply patches immediately.
Bekijk origineel advisory →CVE-2026-61760 is a high-severity vulnerability identified in NVIDIA Megatron Bridge, a component associated with NVIDIA's large-scale AI training infrastructure. The vulnerability involves deserialization of untrusted data, a well-known class of security flaw that can be exploited by attackers to achieve arbitrary code execution. Successful exploitation could also lead to data tampering and information disclosure, making it a multi-impact threat. The vulnerability is currently undergoing analysis by the NVD (National Vulnerability Database). NVIDIA has published security guidance referencing the issue in their product-security repository on GitHub. Organizations using NVIDIA Megatron Bridge in AI/ML pipelines should monitor for patches and apply mitigations promptly. The deserialization attack vector typically requires network access or the ability to supply malicious input to the affected service. Given the potential for code execution, this vulnerability poses significant risk to confidentiality, integrity, and availability of affected systems.
Bekijk origineel advisory →AVideo contains a missing authentication vulnerability in the file plugin/Live/on_publish.php. Unauthenticated attackers can send crafted POST requests to an unguarded RTMP callback endpoint to mark arbitrary scheduled broadcasts as failed. The attack works by supplying fabricated stream keys matching the pattern -ps-<N>, which allows manipulation of scheduled broadcast status fields. This effectively allows any attacker to silently cancel any scheduled live broadcast without requiring credentials or authorization. The vulnerability poses a significant risk to AVideo deployments that use the Live plugin for scheduled broadcast management. No authentication or special privileges are required to exploit this flaw, making it trivially exploitable by remote unauthenticated attackers.
Bekijk origineel advisory →CVE-2023-54391 is a critical authentication bypass vulnerability affecting Proxmox Virtual Environment (VE) versions 7.0 through 8.0, specifically in libpve-access-control before version 8.0.4. Unauthenticated attackers can exploit this flaw by sending a POST request to the access ticket API endpoint with an arbitrary value in the tfa-challenge parameter, completely bypassing password verification. This allows attackers to authenticate as any existing enabled user that does not have a second factor configured, including the highly privileged root@pam account. The vulnerability requires no credentials and provides full unauthorized access to the hypervisor management interface. A fix was introduced in libpve-access-control 8.0.4. All affected releases (7.0β8.0) are end of life and no longer receive official support patches. Organizations still running these versions are at significant risk and should upgrade immediately or implement network-level controls.
Bekijk origineel advisory →LibreNMS versions prior to 26.3.1 are affected by a stored cross-site scripting (XSS) vulnerability in legacy PHP templates. The vulnerability arises because SNMP-sourced and syslog-sourced data are output without proper escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript payloads through SNMP interface descriptions or syslog program fields. These payloads execute in the browser context of authenticated users who view the affected pages. The attack vector requires the attacker to control a device being monitored by the LibreNMS instance. Exploitation could lead to session hijacking, credential theft, or further lateral movement within the network management environment. Users are strongly advised to upgrade to LibreNMS 26.3.1 or later to remediate the vulnerability. The issue has been disclosed via GitHub Security Advisories and tracked by VulnCheck.
Bekijk origineel advisory →CVE-2026-61775 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is classified as high severity. NVIDIA has published a security advisory with details available through their product security GitHub repository. The flaw is catalogued in both the NVD and CVE databases. No additional technical details or proof-of-concept are currently disclosed in the article. Users of NVIDIA Megatron Bridge should monitor for patches and apply mitigations as soon as available.
Bekijk origineel advisory →CVE-2026-61755 is a high-severity vulnerability affecting NVIDIA Megatron Bridge, a component likely related to NVIDIA's AI/ML infrastructure tooling. The flaw involves deserialization of untrusted data, a class of vulnerability that can be particularly dangerous in distributed computing environments. A successful exploit could allow an attacker to achieve remote code execution, tamper with data, or disclose sensitive information. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published a security advisory via their product-security GitHub repository. No patch details or CVSS score are yet publicly confirmed, but the potential impact is rated High. Organizations using NVIDIA Megatron Bridge in AI training or inference pipelines should monitor for updates and apply mitigations promptly.
Bekijk origineel advisory →