LIVE FEED
228 events · 13 sources · newest first
Events in view
228
all sources
Critical
0
severity
Active sources
13
collectors
Last sync
2026-08-28 12:00
UTC
All sources
NVD CVE · 1794CISA KEV · 1686News · 424CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 1
2026-07-30
NVD CVE
CVE-2026-14522: IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.
HIGH
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.
arbitrary-commandscrlf-character-neutralizationscve-2026-14522ibm-apps-connect-enterprisenvd-cveremote-attacksvulnerability
2026-07-29
NVD CVE
CVE-2026-13697: undici's cache interceptor mishandles malformed Cache-Control private directives
HIGH
undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such...
cache-controlcaches-interceptorscve-2026-13697errors-handlinghttps-headersinformation-disclosuremalformed-headersnvd-cve
2026-07-29
NVD CVE
CVE-2026-58163: Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corr
HIGH
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apacheapache-traffic-serverscache-corruptioncve-2026-58163data-integritydata-lossesincident-responsenvd-cve
2026-07-29
NVD CVE
CVE-2026-58177: The Apache Traffic Server Cripts framework has out-of-bounds writes, path traver
HIGH
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade...
apache-traffic-serversbound-writecmmccritical-patchescve-2026-58177defense-industrial-basefedrampfree
2026-07-29
NVD CVE
CVE-2026-58179: The Apache Traffic Server regex_remap plugin overflows the stack and integers fr
HIGH
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0...
apache-traffic-serverscve-2026-58179cve-disclosuresinteger-overflownvd-cveregex-remap-pluginssecurity-patchsoftware
2026-07-28
NVD CVE
CVE-2026-16184: IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to b
HIGH
IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.
applications-securityauthentication-bypasscve-2026-16184cybersecuritydata-protectiondefense-industrial-baseibmnist-800-171
2026-07-28
NVD CVE
CVE-2026-14974: IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote a
HIGH
IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of untrusted data.
2026-07-28
NVD CVE
CVE-2026-14976: IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected
HIGH
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature enabled.
2026-07-27
NVD CVE
CVE-2026-45623: PostCSS takes a CSS file and provides an API to analyze and modify its rules by
HIGH
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.11 and prior, the PreviousMap parses the /*# sourceMappingURL=PATH...
2026-07-27
NVD CVE
CVE-2026-66014: JFrog Artifactory contains an authentication handling weakness in internal reque
HIGH
JFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific conditions, may allow an attacker to escalate privileges beyond the intended access level.
access-controlauthentication-weaknessescompliance-riskcve-2026-66014internal-requests-processingjfrog-artifactorynvd-cveprivileges-escalation
2026-07-23
NVD CVE
CVE-2026-65906: In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL s
HIGH
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
2026-07-23
NVD CVE
CVE-2026-64815: In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible v
HIGH
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
arbitrary-code-injectioncode-injectioncve-2026-64815cybersecuritydevelopers-toolsform-fileintellij-ideajetbrain
2026-07-23
NVD CVE
CVE-2026-15966: Permissive cross-domain security policy with untrusted domains vulnerability in
HIGH
Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
nvd-cve
2026-07-23
NVD CVE
CVE-2026-15967: Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This
HIGH
Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
cisacmmc-level-2compliancecve-2026-15967defense-industrial-basedodfedramp-authorizationincident-response
2026-07-23
NVD CVE
CVE-2026-10697: Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue a
HIGH
Improper Authentication vulnerability in Progress MOVEit Transfer.
This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.
authentication-bypasscisacmmc-level-2cve-2026-10697datum-exfiltrationdodfedramp-authorizationimproper-authentication
2026-07-21
NVD CVE
CVE-2026-56820: Netty is a network application framework for development of protocol servers and
HIGH
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the...
2026-07-20
NVD CVE
CVE-2026-12341: This vulnerability
impacts all versions of IdentityIQ and allows an unauthentica
HIGH
This vulnerability
impacts all versions of IdentityIQ and allows an unauthenticated attacker
unauthorized access to protected APIs and data due to improper validation of
OAuth bearer tokens.
2026-07-20
NVD CVE
CVE-2026-28220: Wazuh is a free and open source platform used for threat prevention, detection,
HIGH
Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to...
2026-07-20
NVD CVE
CVE-2026-41521: xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer
HIGH
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send...
2026-07-18
NVD CVE
CVE-2026-15631: Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail
HIGH
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
2026-07-18
NVD CVE
CVE-2026-16158: Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 b
HIGH
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source...
2026-07-17
NVD CVE
CVE-2026-13473: IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 throu
HIGH
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker...
2026-07-17
NVD CVE
CVE-2026-13448: IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated re
HIGH
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems...
agent-componentapi-v1code-act-agentcsv-agentcve-2026-13448denialflow-idibm
2026-07-15
NVD CVE
CVE-2026-56400: open-webui before 0.3.14 contains a cross-origin resource sharing misconfigurati
HIGH
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functions endpoint. Attackers can execute...
admins-usersapi-endpointarbitrary-code-executionattackers-controlled-websitesauthenticate-requestscross-origin-resources-sharingcross-site-requestcve-2026-56400
2026-07-15
NVD CVE
CVE-2026-20156: As part of Cisco's ongoing commitment to proactive security and product quality,
HIGH
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-15
NVD CVE
CVE-2026-56398: Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in
HIGH
Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type is inferred from file extension rather than Content-Type header,...
accounts-takeoverauthentication-token-theftcontent-typescross-site-scriptingcve-2026-56398datum-urifile-extensioninline-disposition
2026-07-15
NVD CVE
CVE-2026-20157: As part of Cisco's ongoing commitment to proactive security and product quality,
HIGH
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...
2026-07-14
NVD CVE
CVE-2026-47988: Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul
HIGH
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized...
adobe-commercecve-2026-47988exploitincorrect-authorizationno-user-interactionnvd-cvereads-accessessecurity-bypass
2026-07-14
NVD CVE
CVE-2026-50487: Use after free in Microsoft Windows DNS allows an unauthorized attacker to eleva
HIGH
Use after free in Microsoft Windows DNS allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-54995: Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unautho
HIGH
Use after free in Reliable Multicast Transport Driver (RMCAST) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-58594: Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to
HIGH
Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-10672: subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI
HIGH
subsys/net/lib/lwm2m/lwm2m_pull_context.c copied the firmware-update Package URI into a fixed static buffer (context.uri, size CONFIG_LWM2M_SWMGMT_PACKAGE_URI_LEN, default 128) with memcpy(context.uri, uri,...
2026-07-14
NVD CVE
CVE-2026-57090: Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unaut
HIGH
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-54433: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's...
2026-07-14
NVD CVE
CVE-2026-50694: Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unau
HIGH
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-50330: Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attac
HIGH
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to elevate privileges over a network.
2026-07-14
NVD CVE
CVE-2026-57089: Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allow
HIGH
Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-62643: In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascadin
HIGH
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure, e.g., if stylesheet links point to...
2026-07-14
NVD CVE
CVE-2026-49164: Heap-based buffer overflow in Active Directory Domain Services allows an unautho
HIGH
Heap-based buffer overflow in Active Directory Domain Services allows an unauthorized attacker to execute code over a network.
2026-07-14
NVD CVE
CVE-2026-58617: Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized
HIGH
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.