LIVE FEED
1601 events · 13 sources · newest first
Events in view
1601
all sources
Critical
0
severity
Active sources
13
collectors
Last sync
2026-08-28 12:00
UTC
All sources
NVD CVE · 1794CISA KEV · 1686News · 424CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-08-13
NVD CVE
CVE-2026-16815: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-based buffer overflow.
cve-2026-16815denialibm-iibm-i-7-3ibm-i-7-4ibm-i-7-5ibm-i-7-6nvd-cve
2026-08-13
NVD CVE
CVE-2026-16867: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server reso
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper authentication during NTLM session negotiation.
authenticate-userauthenticationcve-2026-16867ibm-iimproper-authenticationntlm-session-negotiationnvd-cveremote-attackers
2026-08-12
NVD CVE
CVE-2026-16627: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2
HIGH
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate...
2026-08-12
NVD CVE
CVE-2026-10543: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privil
HIGH
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.
2026-08-12
NVD CVE
CVE-2026-10534: IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer
HIGH
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.
buffer-overflowcve-2026-10534databasedb2ibmixf-import-parsernvd-cvesecurity
2026-08-12
NVD CVE
CVE-2026-17111: IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker co
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.
cve-2026-17111data-deletiondata-modificationdatabaseibmibm-iibm-i-7-3ibm-i-7-4
2026-08-12
NVD CVE
CVE-2026-18847: IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to ha
HIGH
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.
credential-harvestingcve-2026-18847iibmibm-inavigatornvd-cveremote-attacks
2026-08-12
NVD CVE
CVE-2026-13433: IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to do
HIGH
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised...
2026-08-11
NVD CVE
CVE-2026-57104: Improper neutralization of input during web page generation ('cross-site scripti
HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
2026-08-11
CISA KEV
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance....
administrators-accessapplications-securitycisa-kevcredentials-theftcve-2026-72898data-theftdatabase-securitydatum-exfiltration
2026-08-11
NVD CVE
CVE-2026-65768: Improper limitation of a pathname to a restricted directory ('path traversal') i
HIGH
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
androidandroid-appscode-executioncve-2026-65768exploitmicrosoftmicrosoft-teamnetwork-security
2026-08-11
CISA KEV
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
ancillary-functions-driversauthorize-attackerscisa-kevcve-2026-68820freeincident-responselocal-attackmicrosoft
2026-08-11
CISA KEV
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to...
cisa-kevciscocisco-asacisco-ftdcve-2026-20349denialdevice-reloaddo-s
2026-08-10
NVD CVE
CVE-2026-59090: A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsign
HIGH
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to...
2026-08-07
NVD CVE
CVE-2026-62836: Improper restriction of communication channel to intended endpoints in Azure SQL
HIGH
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
azure-sqlimproper-restrictions-communicationsnetworks-vulnerabilitiesnvd-cveprivileges-elevationunauthorized-attacks
2026-08-07
NVD CVE
CVE-2026-56793: Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Im
HIGH
Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability,...
cve-2026-56793cybersecuritydelldfar-252-204-7012improper-authenticationincident-responsenist-800-171nvd-cve
2026-08-07
CISA KEV
Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.
appliance-executioncisa-kevcommand-injectionprogress-loadmastersprogress-loadmasters-vulnerabilitiesunauthenticated-attacksunsanitized-inputs
2026-08-05
CISA KEV
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.
agents-pollingcisa-kevdeserializationjetbrainremote-code-executionteamcityuntrusted-datavulnerability
2026-08-05
NVD CVE
CVE-2026-8470: IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.
HIGH
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under...
api-keyauthentication-tokencve-2026-8470deterministic-rngencryption-keysfernet-encryptionsibm-langflownvd-cve
2026-08-05
NVD CVE
CVE-2026-17617: IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side
HIGH
IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.
applications-gateways-operatorscustom-resourcecve-2026-17617ibmnvd-cvesecurityservers-sides-requests-forgeryssrf
2026-08-05
NVD CVE
CVE-2026-16443: A flaw was found in the SAML metadata import functionality of the keycloak-servi
HIGH
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata...
authenticationcve-2026-16443forgeryidentity-brokeridentity-providerkeycloakmetadata-importnvd-cve
2026-08-05
NVD CVE
CVE-2026-9205: IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in t
HIGH
IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
cryptographiccve-2026-9205ibmkey-derivationlangflownvd-cvevulnerabilityweak-key
2026-08-05
NVD CVE
CVE-2026-10025: IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 00
HIGH
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event...
authenticationcve-2026-10025event-processingibminjectioninterim-fixesnvd-cveport-514
2026-08-05
NVD CVE
CVE-2026-16442: A flaw was found in the SAML broker component of Keycloak, which is used to mana
HIGH
A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a...
access-controlaccounts-linkingauthenticationcve-2026-16442identity-federationidentity-managementkeycloaklogins-restrictions
2026-08-05
NVD CVE
CVE-2026-8400: IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Serv
HIGH
IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server...
application-serverarbitrary-code-executionclass-loadingcve-2026-8400ibmibm-sdkiiopjava
2026-08-04
CISA KEV
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
alternate-channelalternate-pathsauthentication-bypasscisa-kevcve-2026-18556cybersecurityinformation-securitymanaged-services-providers
2026-08-04
CISA KEV
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.
apache-tomcatbypasscisa-kevcve-2026-34486cybersecuritydata-protectiondfar-252-204-7012encrypt-interceptor
2026-08-04
CISA KEV
Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.
api-vulnerabilitiescode-executioncve-2026-9198default-deploymentibmlangflownvd-cveopen-source
2026-08-04
NVD CVE
CVE-2026-66321: Access of resource using incompatible type ('type confusion') in Microsoft Edge
HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
chromiumcve-2026-66321cybersecuritydefense-industrial-basedfar-252-204-7012information-securitymicrosoftmicrosoft-edge
2026-08-03
CISA KEV
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for...
accounts-takeoveralternate-pathsauthentication-bypasschannelcisa-kevcve-2026-18556cve-2026-18577cybersecurity
2026-07-30
NVD CVE
CVE-2026-14522: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
HIGH
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
arbitrary-commandscrlf-character-neutralizationscve-2026-14522ibm-apps-connect-enterprisenvd-cveremote-attacksvulnerability
2026-07-29
NVD CVE
CVE-2026-58179: The Apache Traffic Server regex_remap plugin overflows the stack and integers fr
HIGH
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apache-traffic-serverscve-2026-58179cve-disclosuresinteger-overflownvd-cveregex-remap-pluginssecurity-patchsoftware
2026-07-29
NVD CVE
CVE-2026-58163: Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corr
HIGH
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apacheapache-traffic-serverscache-corruptioncve-2026-58163data-integritydata-lossesincident-responsenvd-cve
2026-07-29
CISA KEV
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an...
cisa-kevciscocmmccompliance-riskcve-2026-20316defense-industrial-basefirepower-management-centerfirewall
2026-07-29
NVD CVE
CVE-2026-13697: undici's cache interceptor mishandles malformed Cache-Control private directives
HIGH
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such...
cache-controlcaches-interceptorscve-2026-13697errors-handlinghttps-headersinformation-disclosuremalformed-headersnvd-cve
2026-07-29
NVD CVE
CVE-2026-58177: The Apache Traffic Server Cripts framework has out-of-bounds writes, path traver
HIGH
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade...
apache-traffic-serversbound-writecmmccritical-patchescve-2026-58177defense-industrial-basefedrampfree
2026-07-28
NVD CVE
CVE-2026-14974: IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a
HIGH
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
2026-07-28
NVD CVE
CVE-2026-16184: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b
HIGH
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
applications-securityauthentication-bypasscve-2026-16184cybersecuritydata-protectiondefense-industrial-baseibmnist-800-171
2026-07-28
NVD CVE
CVE-2026-14976: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected
HIGH
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
2026-07-27
NVD CVE
CVE-2026-45623: PostCSS takes a CSS file and provides an API to analyze and modify its rules by
HIGH
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH...