Overzicht van binnengekomen advisories.
1553 resultaten gevonden
CVE-2026-61769 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve remote code execution, data tampering, and information disclosure. The vulnerability is catalogued in the National Vulnerability Database and referenced by NVIDIA's own product security advisories. Successful exploitation could have significant impact on confidentiality, integrity, and availability of affected systems. Organizations using NVIDIA Megatron Bridge should review NVIDIA's security advisory and apply any available patches or mitigations promptly.
Bekijk origineel advisory →A critical command injection vulnerability has been identified in the Cobham SATCOM VSAT7090 Maritime Satellite Router affecting versions up to 20260704. The vulnerability exists in the function c_set_reports_decode within the mail-report.sh file, specifically in the JSON Parsing component. Attackers can manipulate the sender/recipients arguments to achieve remote command injection. The attack can be launched remotely without physical access to the device. A public exploit is available and actively usable. The vendor was notified prior to disclosure but failed to respond. This vulnerability poses a significant risk to maritime satellite communication infrastructure. No patch or mitigation has been provided by the vendor.
Bekijk origineel advisory →CVE-2026-61750 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is documented on the NVD and referenced in NVIDIA's product security advisories. Successful exploitation could have serious consequences for systems running NVIDIA Megatron Bridge. No specific workaround or patch details are provided in this article, but the issue is tracked under NVIDIA's security bulletin repository on GitHub. The vulnerability is classified as high impact based on the potential outcomes of exploitation.
Bekijk origineel advisory →The WPLP Cookie Consent plugin for WordPress (versions up to and including 4.4.1) contains a critical vulnerability allowing unauthenticated arbitrary file uploads. The flaw stems from missing file type validation in the saas_upload_logo() function combined with an authorization bypass on the WPLP connector REST endpoints. Unauthenticated attackers can exploit this to upload arbitrary files to the server, potentially leading to remote code execution (RCE). The vulnerability affects all versions up to and including 4.4.1. A patch has been made available via the WordPress plugin repository changeset 3674117. The issue is tracked as CVE-2026-75865 and documented by both NVD and Wordfence. Site administrators running affected versions should update immediately to mitigate the risk of full server compromise.
Bekijk origineel advisory →CVE-2026-51743 describes an incorrect access control vulnerability in the guest_wifi_sync function of TOTOLINK T6 firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to disable guest virtual AP interfaces by sending a specially crafted MQTT message to the cs_broker component. No authentication is required to exploit this vulnerability, making it accessible to any attacker with network access to the device. The impact includes disruption of guest wireless network services. The vulnerability was reported via GitHub-based CVE vendor coordination repositories. TOTOLINK's official website and firmware download pages are referenced as part of the disclosure. This affects a consumer/SOHO IoT networking device, raising concerns about wide exposure in home and small business environments.
Bekijk origineel advisory →CVE-2026-61764 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and exfiltrate sensitive information. The vulnerability is currently undergoing analysis by NVD. NVIDIA has published security guidance via their product-security GitHub repository. Deserialization vulnerabilities are commonly rated high or critical due to the potential for full system compromise. The affected product, Megatron Bridge, is part of NVIDIA's AI and large-scale model training ecosystem. Users of NVIDIA Megatron Bridge should monitor NVIDIA's security advisories for patches and mitigations. The vulnerability is listed on both NVD and CVE.org, indicating it is officially tracked and recognized.
Bekijk origineel advisory →CVE-2026-61758 is a high-severity vulnerability affecting NVIDIA Megatron Bridge, a component likely related to NVIDIA's AI/ML infrastructure tooling. The vulnerability involves deserialization of untrusted data, a class of flaw that can allow attackers to inject malicious serialized objects. Successful exploitation could lead to remote code execution, data tampering, and information disclosure. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published a security advisory referencing this CVE in their product-security GitHub repository. No patch or mitigation details are included in the current article content. The deserialization attack vector is particularly dangerous in AI/ML pipeline environments where data flows between distributed components. Organizations using NVIDIA Megatron Bridge should monitor for patches and apply mitigations promptly given the potential for code execution.
Bekijk origineel advisory →CVE-2026-61753 affects NVIDIA Megatron Bridge, a component likely used in AI/ML infrastructure. The vulnerability involves deserialization of untrusted data, a well-known class of security flaw that can be highly dangerous. A successful exploit could lead to remote code execution, data tampering, and information disclosure. The vulnerability is rated high severity. NVIDIA has published a security advisory via their product-security GitHub repository. The flaw poses significant risk to environments running NVIDIA Megatron Bridge, particularly in AI training or large-scale distributed computing contexts. Organizations using this product should apply patches or mitigations as soon as they become available. The CVE is tracked on both NVD and CVE.org.
Bekijk origineel advisory →A critical command injection vulnerability has been identified in ICP DAS UA-2200 and UA-5200 devices up to firmware version 20260704. The flaw resides in the function ArmAngstromInstructionSet within the /CGI?RestApi=SetHostname endpoint. An attacker can manipulate the ParameterArray argument to inject arbitrary commands remotely. The exploit has been publicly disclosed and is available for use. The vendor was contacted prior to disclosure but did not respond. No patch or mitigation from the vendor has been communicated. This vulnerability poses a significant risk to industrial and OT environments where these devices are deployed.
Bekijk origineel advisory →A critical vulnerability has been identified in the API of HPE Networking Fabric Composer that allows unauthenticated remote attackers to bypass existing authentication controls. Successful exploitation can grant an attacker administrative privileges, leading to complete compromise of the HPE Networking Fabric Composer host. The vulnerability requires no authentication, making it particularly dangerous as it can be exploited remotely without credentials. The impact is severe, potentially allowing full administrative control over affected systems. HPE has published a security bulletin with remediation guidance. Organizations using HPE Networking Fabric Composer should apply patches immediately given the critical nature of the authentication bypass.
Bekijk origineel advisory →CVE-2026-61770 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve remote code execution, data tampering, and information disclosure. The vulnerability is documented in the National Vulnerability Database (NVD) and referenced in NVIDIA's official product security repository. No authentication or user interaction details are specified in the available content. The potential impact is significant given the combination of code execution and data exposure risks. NVIDIA has published a security advisory linked from their GitHub product-security repository. Organizations using NVIDIA Megatron Bridge should monitor for patches and apply mitigations promptly.
Bekijk origineel advisory →Cypht versions before 2.12.2 are affected by a PHP object injection vulnerability tracked as CVE-2026-71981. Authenticated attackers can exploit the back_query GET parameter in the logout handler by supplying a base64-encoded serialized PHP object payload. The parameter is decoded and passed directly to unserialize() without any allow-list, signature verification, or type restriction. This insecure deserialization enables gadget-chain exploitation, allowing attackers to execute arbitrary operating system commands as the web server process, effectively achieving remote code execution (RCE). The vulnerability requires authentication but poses critical risk due to full RCE potential. A fix was released in Cypht version 2.12.2. Relevant patches and advisories are available via the official GitHub repository and VulnCheck.
Bekijk origineel advisory →CVE-2026-61764 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve remote code execution, data tampering, and information disclosure. The vulnerability is documented in the NVD and CVE databases. NVIDIA has published a security advisory on their GitHub product-security repository. No additional exploitation details or patches are described in the article, but the potential impact is significant given the range of consequences. Organizations using NVIDIA Megatron Bridge should monitor for patches and apply mitigations promptly.
Bekijk origineel advisory →CVE-2026-61779 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability was published on NVD and referenced in NVIDIA's product security advisories. Successful exploitation could have significant impact on confidentiality, integrity, and availability of affected systems. Organizations using NVIDIA Megatron Bridge are advised to review the advisory and apply mitigations as provided by NVIDIA.
Bekijk origineel advisory →CVE-2026-61775 affects NVIDIA Megatron Bridge, a component likely related to NVIDIA's AI/ML infrastructure. The vulnerability involves deserialization of untrusted data, a well-known class of security flaw that can be exploited remotely. A successful exploit could lead to arbitrary code execution, data tampering, and information disclosure. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published a security advisory referencing this CVE in their product-security GitHub repository. The potential for code execution makes this a high-severity issue. Organizations using NVIDIA Megatron Bridge should monitor for patches and apply mitigations as soon as they become available.
Bekijk origineel advisory →A SQL injection vulnerability has been identified in Teracity Software Technologies Inc. E-OSB product. The vulnerability is classified as an improper neutralization of special elements used in SQL commands. It allows attackers to perform SQL injection attacks against affected installations. All versions of E-OSB prior to V02.26.07.08.01 are affected. The issue has been assigned CVE-2026-18765 and reported via the Turkish cybersecurity authority. Users are advised to update to version V02.26.07.08.01 or later to mitigate the risk. The vulnerability poses a high risk due to the potential for unauthorized database access and data manipulation.
Bekijk origineel advisory →CVE-2026-61773 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published a security advisory referencing this CVE in their product-security GitHub repository. The severity has been assessed as High. No patch or mitigation details are currently described in the available content, but users of NVIDIA Megatron Bridge should monitor NVIDIA's security advisories for updates. Deserialization vulnerabilities of this nature are commonly exploited in AI and ML infrastructure components, making this particularly relevant given Megatron's use in large-scale model training environments.
Bekijk origineel advisory →CVE-2026-61776 is a high-severity vulnerability affecting NVIDIA Megatron Bridge, a component likely related to NVIDIA's AI/ML infrastructure. The vulnerability involves deserialization of untrusted data, a well-known attack vector that can allow remote or local attackers to supply malicious serialized objects. Successful exploitation could lead to arbitrary code execution, data tampering, and information disclosure. NVIDIA has published a security advisory on their GitHub product-security repository. The vulnerability is currently undergoing analysis on the NVD. No CVSS score or patch details are explicitly provided in the article, but the high Kans value suggests significant risk. Organizations using NVIDIA Megatron Bridge should monitor NVIDIA's security advisories for patches and mitigations.
Bekijk origineel advisory →The WPLP Cookie Consent plugin for WordPress is vulnerable to arbitrary file upload in all versions up to and including 4.4.1. The vulnerability stems from missing file type validation in the saas_upload_logo() function combined with an authorization bypass on WPLP connector REST endpoints. Unauthenticated attackers can exploit this flaw to upload arbitrary files to the affected server. Successful exploitation may lead to remote code execution. No authentication is required, making this a critical risk for any WordPress site running the affected plugin versions. The vulnerability affects the plugin used for GDPR, CCPA, and Google Consent Mode cookie banner management. A patch is available via the WordPress plugin repository changeset 3674117. The issue is tracked as CVE-2026-75865 and documented by both NVD and Wordfence.
Bekijk origineel advisory →CVE-2026-79687 affects Dell PowerStore SDNAS, which contains a Missing Authentication for Critical Function vulnerability. An unauthenticated remote attacker can potentially exploit this flaw to gain unauthorized access to the filesystem. The vulnerability requires no prior authentication, making it especially dangerous for exposed systems. Dell has issued a security advisory (DSA-2026-330) addressing this and multiple other vulnerabilities in PowerStore T. The issue highlights risks associated with missing access controls on critical storage management functions. Remote exploitation could lead to sensitive data exposure or manipulation at the filesystem level. Organizations using Dell PowerStore should apply the recommended security updates immediately.
Bekijk origineel advisory →