24h | 7d | 30d

Overview

  • Amazon Ion
  • Amazon Ion Java

18 Aug 2026
Published
19 Aug 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.44%

KEV

Description

Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted Ion binary document containing a declared-length field that causes excessive heap preallocation. To remediate this issue, users should upgrade to version 1.12.0.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
CVE-2026-75935 & CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service #patchmanagement
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Amazon Ion
  • Amazon Ion Java

18 Aug 2026
Published
19 Aug 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.44%

KEV

Description

Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of service via a crafted compressed Ion document that expands to an arbitrarily large size upon decompression. To remediate this issue, users should upgrade to version 1.12.0 and configure withGzipDecompressionEnabled(false) and/or set an explicit withMaximumBufferSize() when parsing untrusted input.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
CVE-2026-75935 & CVE-2026-75936 - Issue with Amazon ion-java - Memory-amplification denial of service #patchmanagement
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • ivanti
  • Sentry

09 Jun 2026
Published
12 Jun 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
99.90%

Description

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Statistics

  • 1 Post

Last activity: 7 hours ago

Bluesky

Profile picture fallback
🛡️ Manual Técnico de Mitigación: Vulnerabilidades CVE-2026-10520 y CVE-2026-10523 en Ivanti Sentry www.newstecnicas.com/2026/06/manu...
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • ivanti
  • Sentry

09 Jun 2026
Published
10 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
51.87%

KEV

Description

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access

Statistics

  • 1 Post

Last activity: 7 hours ago

Bluesky

Profile picture fallback
🛡️ Manual Técnico de Mitigación: Vulnerabilidades CVE-2026-10520 y CVE-2026-10523 en Ivanti Sentry www.newstecnicas.com/2026/06/manu...
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Red Hat
  • Red Hat Advanced Cluster Management for Kubernetes 2
  • rhacm2/acm-search-v2-rhel9

19 Aug 2026
Published
19 Aug 2026
Updated

CVSS
Pending
EPSS
0.26%

KEV

Description

A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Requests (CSRs), and manage ManifestWork. This grants excessive privileges beyond what is necessary for the operator's intended function, potentially leading to privilege escalation within the cluster.

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture fallback
Red Hat ACMに最大CVSS 9.9の深刻な権限昇格の脆弱性(CVE-2026-70496等)が発覚 CVE-2026-70496 & CVE-2026-66794: Privilege Escalation in Red Hat ACM Hits CVSS 9.9 #DailyCyberSecurity (Aug 20) securityonline.info/red-hat-acm-...
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Cisco
  • Cisco Secure Workload

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.32%

KEV

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20315 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

「Ciscoのバグの深刻度警告は、オリンピック体操競技の得点のように、10、10、9.9、9.6、7.5と表示されます。
/Secure Workload Softwareには5つの重大な欠陥があり、SaaSユーザーでさえアップデートをインストールする必要がある。 」: #TheRegister

「シスコは、ネットワーク内での攻撃者の横方向への移動を阻止することを目的としたマイクロセグメンテーションツールであるセキュアワークロードソフトウェア(旧称Tetration)に、4つの重大な欠陥と、さらに1つの深刻なバグが存在することを明らかにした。

CVE-2026-20315とCVE-2026-20317は、最高評価の10点満点バグです。どちらも不適切なアクセス制御に関連しています。 」

theregister.com/security/2026/

#prattohome

  • 0
  • 0
  • 0
  • 10h ago
Showing 61 to 66 of 66 CVEs