24h | 7d | 30d

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 8 hours ago

Fediverse

Profile picture fallback

(CISA TS+SOC) CVE-2026-86950 – Apple CoreGraphics Out-of-Bounds Write Briefing

Active exploitation of CVE-2026-88650 [CVE-2026-86950] in Apple CoreGraphics requires immediate patch deployment and forensic triage. Review integrated TSUITE + SOC intelligence assets....

thecybermind.co/2qk4

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.40%

KEV

Description

Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
Critical Citrix NetScaler ADC and Gateway Vulnerabilities CVE-2026-88771 through CVE-2026-88778 #patchmanagement
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Hewlett Packard Enterprise (HPE)
  • Instant ON

29 Sep 2026
Published
29 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.56%

KEV

Description

Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

HPE fixed 18 HPE Instant ON vulnerabilities in its access points, including CVSS 9.8 RCE flaws CVE-2026-76721 and CVE-2026-76722. Update to 3.4.2.0.

securityonline.info/hpe-instan

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • TeamViewer
  • Full Client

29 Sep 2026
Published
29 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.14%

KEV

Description

TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Update to 15.82 now. Five high-severity TeamViewer vulnerabilities include CVE-2026-92370, CVE-2026-19743 and CVE-2026-92368 in Full Client and Host.

securityonline.info/teamviewer

  • 1
  • 0
  • 0
  • 10h ago

Overview

  • OpenSSL
  • OpenSSL

29 Sep 2026
Published
29 Sep 2026
Updated

CVSS
Pending
EPSS
0.23%

KEV

Description

Issue summary: The first concurrent use of the same X.509 certificate by several threads may cause its cached extension data to be freed while another thread is still using it. Impact summary: A remote, unauthenticated peer could crash a multi-threaded TLS client, or a multi-threaded TLS server that requests client certificates, if the first certificate chains built to the same trusted CA certificate are built by several connections at the same time. This is a use-after-free read, which is likely to crash the process, resulting in a Denial of Service. CWE: CWE-416: Use After Free Description: OpenSSL caches the decoded values of a certificate's X.509v3 extensions inside the X509 object the first time they are needed. In OpenSSL 4.0 this cache is built in two phases: the extension values are computed while holding a read lock on the certificate, and the results are then installed into the certificate under a write lock. Because a read lock does not exclude other readers, several threads can compute the cache for the same certificate at the same time. Each thread that subsequently acquires the write lock installs its own results and frees the values installed by the thread before it, even though that earlier thread has already marked the cache as complete and may have returned pointers into it to its caller. A caller still using those pointers then reads freed memory. Any certificate shared between threads is exposed the first time its extensions are decoded. In TLS the certificates at risk are the trusted CA certificates supplied for chain verification, by whatever means, since these are shared by every connection and their extensions are decoded and cached the first time a chain is built to them. Certificates sent by the peer are decoded separately for each connection and are not shared, so they are not affected. In a TLS client verifying server certificates, or a TLS server that requests and verifies client certificates, the use-after-free could only occur if the first chains built to the same trusted CA are built by several connections at the same time. FIPS impact: no The FIPS module is not affected as X.509 certificate handling is outside of the OpenSSL FIPS module boundary. OpenSSL 4.0 is vulnerable to this issue. OpenSSL 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are not affected by this issue. OpenSSL 4.0 users should upgrade to OpenSSL 4.0.3. This issue was reported on 27 August 2026 by Tim Becker (Xint.io) and independently in a public report on 31 August 2026 by aydinmercan. The fix has been developed by Bob Beck. -- cut (non-publishing metadata for internal use) -- Reported by: Tim Becker (Xint.io), aydinmercan Fixed by: Bob Beck

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 8 hours ago

Bluesky

Profile picture fallback
OpenSSLの脆弱性(High: CVE-2026-84782, Moderate: CVE-2026-84783, Low: CVE-2026-35189複数)と4.0.3, 3.6.5, 3.5.9, 3.4.8, 3.0.23, 1.1.1zj, 1.0.2zsリリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #ssh #openssl #ssl security.sios.jp/vulnerabilit...
  • 1
  • 0
  • 0
  • 8h ago

Overview

  • TeamViewer
  • Full Client

29 Sep 2026
Published
29 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.13%

KEV

Description

Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Update to 15.82 now. Five high-severity TeamViewer vulnerabilities include CVE-2026-92370, CVE-2026-19743 and CVE-2026-92368 in Full Client and Host.

securityonline.info/teamviewer

  • 1
  • 0
  • 0
  • 10h ago

Overview

  • OpenSSL
  • OpenSSL

29 Sep 2026
Published
29 Sep 2026
Updated

CVSS
Pending
EPSS
0.12%

KEV

Description

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions. Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates. CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations. The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received. FIPS impact: no The affected code is outside the FIPS module boundary.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 8 hours ago

Bluesky

Profile picture fallback
OpenSSLの脆弱性(High: CVE-2026-84782, Moderate: CVE-2026-84783, Low: CVE-2026-35189複数)と4.0.3, 3.6.5, 3.5.9, 3.4.8, 3.0.23, 1.1.1zj, 1.0.2zsリリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #ssh #openssl #ssl security.sios.jp/vulnerabilit...
  • 1
  • 0
  • 0
  • 8h ago

Overview

  • electron
  • electron

29 Sep 2026
Published
29 Sep 2026
Updated

CVSS v3.1
HIGH (8.2)
EPSS
0.15%

KEV

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Five high-severity Electron vulnerabilities, including CVE-2026-102676, CVE-2026-102673 and CVE-2026-102674, weaken sandbox isolation. Update Electron now.

securityonline.info/electron-v

  • 0
  • 1
  • 0
  • 11h ago

Overview

  • electron
  • electron

29 Sep 2026
Published
29 Sep 2026
Updated

CVSS v3.1
HIGH (8.3)
EPSS
0.45%

KEV

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron <webview> guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than the embedder granted. Applications that do not enable the <webview> tag or that keep the embedder sandboxed are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Five high-severity Electron vulnerabilities, including CVE-2026-102676, CVE-2026-102673 and CVE-2026-102674, weaken sandbox isolation. Update Electron now.

securityonline.info/electron-v

  • 0
  • 1
  • 0
  • 11h ago

Overview

  • electron
  • electron

29 Sep 2026
Published
29 Sep 2026
Updated

CVSS v3.1
HIGH (8.2)
EPSS
0.27%

KEV

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a sandboxed top-level document that was permitted to open popups could therefore create a window with the Electron application's full origin instead of the restricted origin intended by the sandbox. Applications that deny such popups with setWindowOpenHandler are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Five high-severity Electron vulnerabilities, including CVE-2026-102676, CVE-2026-102673 and CVE-2026-102674, weaken sandbox isolation. Update Electron now.

securityonline.info/electron-v

  • 0
  • 1
  • 0
  • 11h ago
Showing 71 to 80 of 83 CVEs