Vulnerabilities

Tracking and analyzing security vulnerabilities across technologies and ecosystems. Focus on what matters most to reduce risk and speed response.

Recently Tracked Vulnerabilities

CVE IDProductSeverityExploitation StatusPublished
Research advisoryWarm-paper investigative illustration: a red path leaves a controlled exploit arena through a package-cache gateway and several server steps, crosses an organizational boundary, and reaches a data warehouse under blue-green detection lights.OpenAI ExploitGym and Hugging Face package cacheCriticalAn internal agent evaluation exploited a package-cache zero-day, crossed the research boundary, and reached Hugging Face production; isolate evaluation infrastructure, remove production reachability, repair the cache path, rotate exposed material, and verify containment end to end.July 23, 2026
Fastjson @JSONType RCEA warm hand-drawn investigation scene connects a JSON label, nested jar container, loopback resource parcel, and class-loading gate to show the conditional path formed by Fastjson @JSONType probing and Spring Boot fat-jar loading on Temurin 8u492.Fastjson 1.xCriticalOn the tested JDK 8 and Spring Boot loader path, Fastjson's @JSONType resource probe could trust externally retrieved class bytes before type-compatibility checks, allowing class initialization before a later ClassCastException; enable SafeMode where available, audit handlers and loader/TCCL exposure, restrict egress, and migrate to Fastjson2.Jul 20, 2026
CVE-2026-42533A warm hand-drawn comparison shows NGINX measuring a blue string into a wooden tray, then a later copy stretching beyond that tray after map state changes; a red mark identifies the crossed boundary.NGINX Open Source and NGINX PlusCriticalUnder specific configurations, either a regex map/capture relationship or a qualifying non-cacheable rewrite path can change bytes between NGINX's length and copy passes, allowing crafted unauthenticated requests to overrun a worker heap buffer. Upgrade OSS stable to 1.30.4, mainline to 1.31.3, or Plus and downstream products to their listed fixed releases.July 20, 2026
CVE-2026-63030 / CVE-2026-60137On beige paper, a sealed envelope splits into two mechanical lines: an upper line passes a key and a locked door with a cloud-shaped side tube, while a lower line passes a blue booklet, integer beads, a stone arch, and a cylinder before both lines end in gray fog.WordPress CoreCriticalWordPress says the two flaws combine to RCE on 6.9 and 7.0; Searchlight reports anonymous triggering on stock plugin-free core, while Cloudflare limits its described path to sites without persistent object caching. Install 6.9.5 or 7.0.2; 6.8 users need 6.8.6 for CVE-2026-60137.Jul 19, 2026
CVE-2026-56190Hand-drawn technical cover: a blue RDP cable enters a nighttime reception desk where a small front cabinet is neatly prepared, while a vast dark room behind it still carries dust and ghostly traces from prior occupants as an engineer inspects it by lamp.Windows Remote Desktop ServicesCriticalCVE-2026-56190 lets a reachable Windows RDP service with NLA disabled enter an incompletely initialized connection-object path before authentication; every affected system with an eligible servicing channel should receive Microsoft's currently mapped security update or a supported successor and restart, while NLA, ingress, historical exposure, and fault evidence remain separate acceptance fields.Jul 17, 2026
CVE-2026-24233A warm hand-drawn checkpoint where a sealed pickle crate reaches a TensorRT-LLM worker, allowed globals queue at the workshop, and a shadowed callable is stopped by the repaired deny gate.NVIDIA TensorRT-LLMHighThe RLHF weight-update worker admitted broad torch globals while unpickling CUDA IPC handles; TensorRT-LLM 1.3.0rc15 adds higher-priority exact denials for the confirmed execution path.July 15, 2026
CVE-2026-61520A warm hand-drawn view of the SMF 3.0 repair: DNS A and AAAA results converge into one address set, the global-range gate rejects private and NAT64-to-private destinations, and a 3xx response returns to the URL for another check.Simple Machines Forum image proxyModerateAuthenticated post content could reach the server-side image fetcher through an HMAC-signed proxy URL without a complete destination-safety boundary; apply the reviewed release-2.1 or release-3.0 fix and verify every redirect path.Jul 15, 2026
CVE-2026-45579A warm hand-drawn scientific-computing operations room follows one report card through service desks toward an interpreter mechanism, while a repaired path ends at two orderly model cabinets.DIRAC RequestManagerCriticalAuthenticated report fields reached Python eval while DIRAC formed the affected ORM expression, before SQL generation or execution; upgrade to 8.0.79, 9.0.22, 9.1.10 or a later supported release.Jul 13, 2026
CVE-2026-45086 + 8A cutaway civic hall contains separate navy and teal organizations above a sequence of record, permission, query, publishing, and delivery desks, with nine sealed case files arranged below.DecidimHighNine coordinated disclosures converge on tenant scoping, authorization, private downloads, query construction, stored HTML and push-subscription destinations; fixed streams are 0.30.9, 0.31.5 and 0.32.0.Jul 13, 2026
CVE-2026-5426Three separately fenced institutions send sealed state toward one oversized shared key while an investigator traces that trust through a server and configuration evidence.KnowledgeDeliver and ASP.NET MachineKeyCriticalCVE-2026-5426 turned a deployment secret reused by independent KnowledgeDeliver customers into cross-instance signing authority: an unauthenticated holder could submit ViewState that another installation trusted, reach deserialization, and obtain operating-system-level code execution.Jul 13, 2026
CVE-2026-54174A warm-paper illustration of an APK receiving desk where the signed index and control member have passed inspection while the data member waits at the final digest comparison.apko and melangeHighThe APK getter authenticated control without comparing datahash to the delivered payload. Deploy apko 1.2.25 and melange 0.56.3 as reviewed, rechecking at deployment; 1.2.9 and 0.50.4 are the first-fixed boundary.July 11, 2026
CVE-2026-48939 / CVE-2026-56291A defender compares a calendar attachment intake and a public form attachment intake whose separate conveyor paths converge on an exposed server chamber, while guarded storage routes stand in the foreground.Joomla iCagenda and Balbooa FormsCriticalCISA KEV lists two actively exploited unauthenticated upload paths; deploy iCagenda 3.9.15 or 4.0.8 and Balbooa Forms 2.4.1, then review public upload directories.Jul 10, 2026
CVE-2026-53363A warm hand-drawn investigation bench where an engineer arranges packets into a uniform envelope before sending it into an encryption tunnel.Linux XFRM IP-TFSHighiptfs_consume_frags() moved page fragments without SKBFL_SHARED_FRAG, allowing ESP to treat externally shared pages as private writable packet storage.July 10, 2026
GHSA-g5r6-gv6m-f5jvAn editorial investigation scene follows one attachment request across a workspace fence, into a host file drawer, and onward to a remote collaboration page, joining local read authority with remote write authority.mcp-atlassianHighConfluence attachment uploads could read any local path visible to the MCP server account; 0.22.0 confines resolved paths to the runtime workspace.July 10, 2026
CVE-2026-15123Warm hand-drawn scene with DOM branches, pending node cards, an iframe lifecycle setting, a node transfer, and the final structural check position.Chromium Blink DOMHighChromium fix cb26b6a1eb79 moves Blink's live structural recheck ahead of the Document branch; assets should install the vendor's current Stable build and retire old renderers, derivatives must prove that equivalent source and the complete WPT reached their product, and LTS-144 still lacks a publicly merged backport as of July 26, 2026.July 8, 2026
CVE-2026-15132A hand-drawn three-slot tagged array whose third initialization store disappears just before the garbage collector arrives, while the later write of 42 is too late to repair what the collector observed.Chromium V8HighCVE-2026-15132 lets V8 Turboshaft remove a required FixedArray initialization store under a specific loop-unrolling and store-elimination sequence, allowing the garbage collector to read an uninitialized slot and compromise renderer memory safety.Jul 8, 2026
CVE-2026-15114Hand-drawn AV1 stream showing two equal-sized frames carrying different internal tool requirements, an undersized decoder context, and a reset gate leading to a fully provisioned hardware cabinet.Chromium AV1 hardware decoderHighCVE-2026-15114 lets a crafted AV1 sequence change allocation-sensitive coding tools while keeping its visible dimensions stable, so old Chromium builds reuse an undersized hardware context and can perform out-of-bounds reads or writes.Jul 8, 2026
CVE-2026-15107Warm hand-drawn investigation room with two clocks over blue and red stains, a cart holding three geometric objects, and gloved hands examining a clear glass sphere in a black tray while a lone researcher stands in the adjoining archive.Chromium IndexedDB DevToolsMediumCVE-2026-15107 lived in the gap between two clocks: a DevTools request began while its V8 inspector session was alive, yet IndexedDB returned the last row only after navigation had disposed that session, leaving the callback able to reach its agent, copy a stale native pointer, and ask freed inspector state to wrap the row.Jul 8, 2026
CVE-2026-15133Hand-drawn auction reporting room after a red timeout bell has rung; native helpers are leaving while a blue browserSignals envelope and a Promise claim ticket remain connected to a brass property drawer.Chromium Protected AudienceHighCVE-2026-15133 began after a Protected Audience winner was chosen: a report left browserSignals on globalThis , queued a Promise to read renderUrl , and timed out; native helpers left with the stack, then cleanup ran it through a stale handle into an expired object, so the fix kept the filler through scope cleanup, limited logger use to script execution, and reset native links before delayed JavaScript resumed.July 8, 2026
CVE-2026-13122Source-oriented cover for OpenVPN CVE-2026-13122, tracing a short credential through prefix classification, failed token verification, external authentication, storage in auth_token_initial, fixed-offset memory access, and the two-part repair.OpenVPN external authenticationMediumCVE-2026-13122 affects OpenVPN 2.6.0–2.6.20 and 2.7 alpha1–2.7.4 servers using external-auth : a short credential beginning with SESS_ID_AT_ can fail cryptographic verification, still be retained as the initial session token, and then drive fixed-offset reads and writes beyond its allocation before a fatal assertion terminates the daemon.Jul 8, 2026
CVE-2026-12996A warm hand-drawn before-and-after view of OpenVPN session promotion: above, two tunnels leave an ACK envelope tied to a collapsing borrowed holder; below, the repaired transition clears the borrowed path before the retired tunnel disappears.OpenVPN TLS control channelHighCVE-2026-12996 occurs during one OpenVPN server TLS multi-session pass: the active session lends a shallow view of a dedicated ACK to the outer send slot, a candidate session reaches the TLS promotion threshold and frees the old owner, and the event loop later reads the stale ack_write_buf , producing a remotely influenceable heap use-after-free.Jul 8, 2026
CVE-2026-53359Hand-drawn nested machine rooms frame a suspended split memory panel; an inspector holds two brass tokens while a brick-red reverse-map thread runs from the panel across the room toward a filing cabinet.Linux KVM/x86 shadow MMUHighSame-GFN shadow-page reuse across a role change could leave rmap state alive after teardown; direct kernel.org deployments should run 7.1.5, 6.18.40, 6.12.98, 6.6.145, or 6.1.178, while vendor kernels require an equivalent supported fix.Jul 6, 2026
CVE-2026-53362Hand-drawn technical cover comparing a vulnerable IPv6 packet build that omits linear carry capacity and writes into skb_shared_info with a fixed build that reserves the carried range.Linux IPv6 UDP fragmentationHighThe paged IPv6 append path omitted fraggap from linear allocation and could copy local splice-supplied bytes into skb_shared_info; fixed floors include 6.1.177 and 6.6.144.Jul 4, 2026
CVE-2026-53361Hand-drawn technical cover: the first AF_UNIX garbage-collection shift leaves and switches off a work lamp while a second queued shift enters the same two-socket cleanup room; a MSG_PEEK clerk duplicates a brass file handle while the original envelope remains on the cycle.Linux AF_UNIXMediumA queued unix_gc() rerun could execute while gc_in_progress was false, hiding an overlapping SCM_RIGHTS MSG_PEEK from the socket graph collector's sequence check.July 4, 2026
CVE-2026-53360Hand-drawn technical cover: a sealed confidential guest passes a short three-compartment tray through a one-page shared service hatch; the KVM host has a long allocator shelf, and a ghosted compartment extends beyond the tray toward neighboring host objects.Linux KVM AMD SEV-SNPHighGHCB v2 accepted an outside-page scratch allocation whose PSC index was checked against a page-wide limit, enabling a malicious protected guest to cross the host heap object boundary.July 4, 2026
CVE-2026-55956A warm hand-drawn slash gate receives two distinct request tokens on separate left-to-right rails; the upper public rail reaches an open tray, while the lower protected rail passes through a three-role shield checkpoint.Apache TomcatModerateDefault-servlet security constraints skipped HTTP method selection; upgrade to Tomcat 9.0.119, 10.1.56, 11.0.23, or a later supported release.Jun 29, 2026
CVE-2026-12413A warm hand-drawn IKEv2 reassembly bench where sealed fragment parcels fill every digest slot, the former end stop rejects the last valid parcel, and the repaired rack accepts the complete protected set.LibreSwan IKEv2 fragmentationHighCVE-2026-12413 lets an IKEv2 initiator that has not completed identity authentication fill all 30 payload descriptors in a protected fragmented message, after which Libreswan 4.6 through 5.3 mistakes the valid count for a broken invariant and terminates pluto; a remote actor can repeat the exchange to disrupt the VPN control plane, and version 5.3.1 corrects the boundary.June 24, 2026
CVE-2026-20245A hand-drawn table with one red row enters an SD-WAN control appliance; a red path crosses the appliance to two keys while a fabric of edge nodes branches below it.Cisco Catalyst SD-WAN control planeHighAuthenticated CLI file handling can execute commands as root; affected release trains have explicit fixed versions and no workaround.Jun 24, 2026
CVE-2026-35273A hand-drawn PeopleSoft web-tier cabinet opens into a remote-management room, branching application systems, and a sealed archive route.Oracle PeopleSoft PeopleToolsCriticalUnauthenticated remote code execution in Environment Management; PeopleTools 8.61 and 8.62 require Oracle's June 2026 fixes and exposure review.Jun 12, 2026
CVE-2026-47895A warm hand-drawn before-and-after ownership map: two cloned EAP identities share one red-tied empty buffer and tear it during teardown on the left, while the repaired clone gives each identity its own blue-tied buffer on the right.strongSwan IKE identity handlingCriticalCVE-2026-47895 lets an unauthenticated IKE peer use the two-byte EAP identity @# to create a zero-length but freeable allocation; strongSwan's old identity clone gave the same address to two owners, so failed-authentication teardown double-frees it, reliably threatening gateway availability while the project assesses potential remote code execution.Jun 8, 2026
CVE-2026-44706A hand-drawn investigation desk follows three tenant folders through a filter service toward a database cabinet, where a rust-red query fragment slips beyond the intended drawer.ChatwootHighAuthenticated filter values and custom-attribute keys reached PostgreSQL syntax across tenant boundaries; Chatwoot 4.11.2 uses typed binds and key validation.May 22, 2026
CVE-2026-48095A warm hand-drawn forensic bench where an NTFS disk ruler and a compression token feed a shift mechanism above a tiny cup and a broad data stream.7-Zip NTFS parserHighCross-field NTFS geometry can produce an undersized input buffer before decompression; 7-Zip 26.01 restores the parser invariant.May 22, 2026
CVE-2026-45350A hand-drawn chat desk where a typed tool identifier slips behind a private cabinet before a guard checks the requesting account.Open WebUIHighUser-supplied tool identifiers could resolve restricted local tools and MCP connections before authorization; upgrade to 0.8.6 or later.May 15, 2026
TS-2026-002A hand-drawn investigation scene in which a blank request card passes four checkpoints toward a routing desk, where an exit path and advertised subnet paths fade; a repaired guard stops a second blank card before it reaches the desk.Tailscale device web interfaceMediumTS-2026-002 allowed an authenticated tailnet peer that could reach an explicitly exposed device web interface on TCP 5252 to send a route request selecting no operation; the old handler asked for neither route capability, preserved neither existing route group, and then gave two empty values explicit write authority, clearing the target's active exit node and advertised subnet routes.May 13, 2026
CVE-2026-39852A hand-drawn investigation shows one stone path decorated with semicolon-shaped markers, an open security gate testing the wrong silhouette, and a routing bench cleaning the same path before it reaches a protected archive.Quarkus HTTP securityHighMatrix parameters gave the security matcher and REST router different path identities; fixed platform streams normalize each path segment consistently.May 4, 2026
CVE-2026-28514A hand-drawn enterprise chat operations room where the password-check hourglass is still running while a login request has already crossed the gate and collected a session key.Rocket.Chat DDP authenticationCriticalCVE-2026-28514 affected Rocket.Chat's Enterprise microservice password flow: an unresolved bcrypt Promise was treated as truthy before its false result arrived, after which the service issued a session token and attached the impersonated identity to the DDP connection.Mar 12, 2026