Overzicht van binnengekomen advisories.
1553 resultaten gevonden
CVE-2026-61755 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker exploiting this flaw could achieve remote code execution, tamper with data, or disclose sensitive information. The vulnerability is classified as high severity. NVIDIA has published an advisory via their product-security GitHub repository. The issue is tracked by both NVD and the CVE Program. No specific patch details are included in the article, but references point to NVIDIA's official security advisories. Users of NVIDIA Megatron Bridge should monitor NVIDIA's security channels for mitigations and updates.
Bekijk origineel advisory →CVE-2026-61765 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, a class of vulnerability commonly exploited by attackers to achieve arbitrary code execution. A successful exploit could lead to code execution, data tampering, and information disclosure. The vulnerability is currently undergoing analysis by NVD. NVIDIA has published a security advisory on their GitHub product-security repository. The CVE record is also tracked on cve.org. Users and administrators of NVIDIA Megatron Bridge should monitor for patches and mitigations from NVIDIA. This type of deserialization vulnerability poses significant risk to affected deployments, particularly in AI and machine learning infrastructure contexts.
Bekijk origineel advisory →CVE-2026-61756 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this flaw could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is tracked by NVD and NVIDIA's product security team. It has been assigned a high criticality rating. The issue stems from improper handling of serialized data inputs, a common but severe class of vulnerability. NVIDIA has published security advisory details via their GitHub product-security repository. Users and administrators of NVIDIA Megatron Bridge are advised to review the advisory and apply any available mitigations or patches promptly.
Bekijk origineel advisory →Kyverno versions before 1.16.2 contain a server-side request forgery (SSRF) vulnerability in its APICall feature. The URL field in a Policy's ServiceCall configuration lacks proper validation, allowing users with namespace-level Policy creation permissions to direct Kyverno to make HTTP requests to arbitrary internal resources. This includes cloud metadata endpoints such as 169.254.169.254 and other tenants' internal resources. Kyverno executes these requests using its cluster-wide high-privilege ServiceAccount, creating a Confused Deputy problem. The responses, which may contain sensitive data such as other tenants' secrets and cloud IAM credentials, are returned in the PolicyReport and accessible to the attacker. This effectively breaks multi-tenant isolation in Kubernetes clusters using Kyverno. Users are advised to upgrade to Kyverno 1.16.2 or later to remediate this vulnerability.
Bekijk origineel advisory →CVE-2026-61762 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published a security advisory referencing this CVE. The flaw represents a high-severity risk due to the potential for full code execution on affected systems. Organizations using NVIDIA Megatron Bridge should monitor for patches and apply mitigations as soon as they become available.
Bekijk origineel advisory →Wyoming before version 1.10.2 contains a server-side request forgery (SSRF) vulnerability identified as CVE-2026-8712. Unauthenticated attackers with network access can exploit this flaw by supplying a malicious `uri` query parameter to the HTTP API. The vulnerability allows attackers to force outbound connections to arbitrary targets using `tcp://` or `unix://` URI schemes. Affected endpoints include /api/info, /api/speech-to-text, and /api/text-to-speech. Exploitation enables attackers to override the server-configured backend and redirect connections to attacker-chosen hosts. No authentication is required, making this accessible to any network-adjacent attacker. The issue has been patched in Wyoming version 1.10.2. Users are advised to upgrade immediately to mitigate the risk of internal network probing or service abuse.
Bekijk origineel advisory →CVE-2026-61753 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, a class of vulnerability commonly exploitable by remote or local attackers to achieve arbitrary code execution. A successful exploit could lead to code execution, data tampering, and information disclosure. NVIDIA has published a security advisory referencing this CVE. The vulnerability is currently undergoing analysis by NVD. No patch or mitigation details are included in this article. The affected product, NVIDIA Megatron Bridge, is likely used in large-scale AI/ML training infrastructure, making the potential impact significant.
Bekijk origineel advisory →CVE-2026-79687 affects Dell PowerStore SDNAS, which contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this flaw to gain unauthorized access to the filesystem. The vulnerability requires no authentication, making it particularly dangerous as it lowers the barrier for exploitation. Dell has issued a security advisory (DSA-2026-330) addressing this and multiple other vulnerabilities in Dell PowerStore T. The impact is rated high due to the potential for full filesystem access by remote unauthenticated attackers. Users are advised to apply the security updates provided by Dell to mitigate the risk.
Bekijk origineel advisory →CVE-2026-61756 is a high-severity vulnerability affecting NVIDIA Megatron Bridge, a component likely associated with NVIDIA's AI and large-scale model training infrastructure. The vulnerability involves deserialization of untrusted data, a well-known attack vector that can allow remote or local attackers to inject malicious payloads. Successful exploitation could lead to arbitrary code execution, data tampering, and unauthorized information disclosure. Deserialization vulnerabilities are particularly dangerous because they can be exploited without authentication in some configurations. The vulnerability is currently undergoing analysis by NVD. NVIDIA has published an advisory via their product-security GitHub repository. Users and administrators of NVIDIA Megatron Bridge are advised to monitor NVIDIA's official security advisories for patches and mitigations. The CVE has been registered with both NVD and the CVE program. Given the potential for code execution and data compromise, this is considered a high-impact vulnerability.
Bekijk origineel advisory →CVE-2026-61752 is a high-severity vulnerability in NVIDIA Megatron Bridge involving deserialization of untrusted data. An attacker exploiting this flaw could achieve remote code execution, tamper with sensitive data, and extract confidential information. The vulnerability is catalogued in the NVD and has an associated NVIDIA product security advisory. NVIDIA has published details via their official product-security GitHub repository. The impact scope includes code execution, data integrity compromise, and information disclosure, making it a critical concern for organizations using NVIDIA Megatron Bridge. No additional exploit details or patch specifics are provided in the current article state, which is marked as 'Received' in NVD status.
Bekijk origineel advisory →CVE-2026-61761 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published security advisory details in their product-security GitHub repository. The flaw is classified as high criticality given its potential impact on code execution and data integrity. No patch or mitigation details are explicitly mentioned in the article content. Users of NVIDIA Megatron Bridge should monitor NVIDIA's security advisories for updates and remediation guidance.
Bekijk origineel advisory →CVE-2026-61778 is a high-severity vulnerability identified in NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability was published via the NVD and NVIDIA's product security advisory. No authentication bypass or exploit code details are provided in the article, but the potential impact is significant given the three major consequence categories: code execution, data tampering, and information disclosure. NVIDIA has published a security advisory on GitHub under their product-security repository. Users and administrators of NVIDIA Megatron Bridge are advised to review the advisory and apply any available patches or mitigations promptly.
Bekijk origineel advisory →CVE-2026-61757 is a high-severity vulnerability identified in NVIDIA Megatron Bridge involving deserialization of untrusted data. An attacker who successfully exploits this vulnerability could achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability is currently undergoing analysis on the NVD. NVIDIA has published security advisory details via their product-security GitHub repository. The flaw poses significant risk to systems running NVIDIA Megatron Bridge, particularly in AI and large-scale distributed computing environments. Organizations using this product should monitor NVIDIA's security advisories for patches and mitigations. The combination of code execution and data tampering potential classifies this as a critical finding requiring prompt attention.
Bekijk origineel advisory →CVE-2026-61772 is a high-severity vulnerability identified in NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve arbitrary code execution, data tampering, and information disclosure. The vulnerability was published via the NVD and is referenced in NVIDIA's official product security repository. No specific CVSS score or patch details are provided in the article, but the Current Kans Value is rated High. The affected product, NVIDIA Megatron Bridge, is likely used in AI and high-performance computing environments. Exploitation could have serious consequences for confidentiality, integrity, and availability of affected systems. Organizations using NVIDIA Megatron Bridge are advised to monitor NVIDIA's security advisories for patches and mitigations.
Bekijk origineel advisory →CVE-2026-61772 is a high-severity vulnerability identified in NVIDIA Megatron Bridge, a component associated with NVIDIA's AI and machine learning infrastructure. The vulnerability involves deserialization of untrusted data, a class of flaw that can be exploited by remote or local attackers to manipulate the deserialization process. Successful exploitation could lead to arbitrary code execution, allowing an attacker to run malicious code in the context of the affected application. Additional impacts include data tampering, where the integrity of processed data could be compromised, and information disclosure, potentially exposing sensitive data. The vulnerability has been assigned a High criticality rating, reflecting its significant potential impact. It is catalogued in the National Vulnerability Database (NVD) and is currently undergoing analysis. NVIDIA has published a security advisory through their product-security GitHub repository. Users and administrators of NVIDIA Megatron Bridge are advised to monitor NVIDIA's official channels for patches and mitigations.
Bekijk origineel advisory →CVE-2026-61758 is a deserialization of untrusted data vulnerability affecting NVIDIA Megatron Bridge. An attacker exploiting this flaw could achieve remote code execution, tamper with data, and cause information disclosure. The vulnerability was published via NVD and has a high criticality rating. NVIDIA has issued a security advisory linked through their product-security GitHub repository. Deserialization vulnerabilities are commonly exploited in enterprise and AI/ML infrastructure components. The impact scope includes confidentiality, integrity, and availability. Users of NVIDIA Megatron Bridge are advised to review the advisory and apply mitigations or patches promptly.
Bekijk origineel advisory →A critical command injection vulnerability has been identified in the Cobham SATCOM VSAT7090 Maritime Satellite Router up to version 20260704. The vulnerability exists in the c_set_reports_decode function within the mail-report.sh file, specifically in the JSON Parsing component. Attackers can manipulate the sender/recipients arguments to inject arbitrary commands. The vulnerability is remotely exploitable, significantly increasing its risk profile. A public exploit is already available, making active exploitation a realistic threat. The vendor was notified prior to public disclosure but did not respond. This affects maritime satellite communication infrastructure, which is considered critical for naval and shipping operations. The lack of vendor response and availability of a public exploit elevate the urgency for mitigation.
Bekijk origineel advisory →A Use of Hard-coded Credentials vulnerability has been identified in TMT Machine Industry and Trade Ltd. Co.'s Talassoft Industrial Management Software. The vulnerability allows attackers to retrieve embedded sensitive data through hardcoded credentials present in the software. Affected versions range from V.4 through versions prior to V.16. The issue is tracked as CVE-2026-18931 and was disclosed via the Turkish cybersecurity authority siberguvenlik.gov.tr. Hard-coded credentials represent a significant security risk as they cannot be changed by end users and can be exploited by anyone who discovers them. Organizations using affected versions of Talassoft should upgrade to V.16 or later to mitigate this risk.
Bekijk origineel advisory →A critical vulnerability was identified in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows attackers to bypass the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a target.url parameter from POST requests and passes it to JMXServiceURL and JMXConnectorFactory without adequate filtering. The existing denylist only blocks URLs matching 'service:jmx:rmi:///jndi/ldap:.*', which can be circumvented using alternative JMX URL forms such as ldaps:// schemes or LDAP URLs with non-empty JMX host components. Exploitation causes the Jolokia agent JVM to perform a JNDI lookup against an attacker-controlled LDAP endpoint. Potential impacts include server-side request forgery (SSRF), credential forwarding to attacker-controlled endpoints, and remote code execution depending on the target JVM configuration and available classes.
Bekijk origineel advisory →CVE-2026-61766 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, a class of vulnerability commonly exploited to achieve arbitrary code execution. A successful exploit could lead to code execution, data tampering, and information disclosure. The vulnerability is currently undergoing analysis by NVD. NVIDIA has published a product security advisory on GitHub. This type of deserialization vulnerability can be critical in AI and machine learning infrastructure components like Megatron Bridge, as they may run with elevated privileges and handle sensitive data. Organizations using NVIDIA Megatron Bridge should monitor for patches and apply mitigations as soon as they become available.
Bekijk origineel advisory →