CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.5
WIEDZA Z SIECI
Podatności
CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.5
CVE-2026-88771 · Citrix NetScaler Improper Input Validation Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 6.9
CVE-2026-67279 · Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.8
CVE-2026-65660 · Microsoft SharePoint Code Injection Vulnerability
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 8.1
CVE-2026-87902 · WordPress Core Remote File Inclusion Vulnerability
WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 10.0
CVE-2026-5430 · WSO2 Multiple Products Path Traversal Vulnerability
WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.1
CVE-2026-71362 · Adobe Commerce and Magento Incorrect Authorization Vulnerability
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.5
CVE-2026-93952 · Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.3
CVE-2026-94127 · F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.8
CVE-2026-93616 · Check Point Multiple Products Path Traversal Vulnerability
Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.Czytaj całość ↵Źródło — otwiera w nowej karcieCISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 9.8
CVE-2026-85102 · Check Point Multiple Products Improper Certificate Validation Vulnerability
Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 5.1
CVE-2026-93339 · Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitra…
Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicious wrapper attribute values in layout tags. The ditty_layout_render_tag_wrapper() function inserts caller-supplied wrapper attribute values directly as HTML element names without allowlist validation, bypassing wp_kses_post() sanitization because KSES runs at save time before layout tag attributes are resolved at render time, causing the payload to execute in the browser of any visitor viewing posts or pages embedding the affected Ditty item.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 9.1
CVE-2026-86473 · Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie.
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout response but revokes nothing, so the token remains valid until it expires. An attacker who already holds a copy of that token keeps the victim's access after the victim has logged out and believes the session ended; the default token lifetime is 24 hours and is configurable. Affects API clients that authenticate with a bearer token rather than the browser session cookie. The attacker must already possess a copy of a valid token; obtaining one is outside the scope of this issue, and no privileges beyond the victim's own are gained. Users of apache-airflow are recommended to upgrade to apache-airflow version 3.3.2 or later, which fixes the issue.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 4.2
CVE-2026-82355 · When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting …
When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer over cookie. The request then executes -- and is recorded in the audit log -- as the cookie's principal rather than the identity the client explicitly presented. Only Apache Airflow 3.3.0 and 3.3.1 are affected. Earlier releases do not contain the code path that caches the cookie-derived user, and are not vulnerable. Exploiting this requires an attacker to first place a valid session cookie of their own into the victim's browser or client: for example by cookie tossing from a sibling subdomain, through cross-site scripting in a separate application sharing a parent domain, or via a shared workstation. Deployments that host the Airflow UI on a domain shared with other applications are therefore the most exposed; a deployment on a dedicated domain with no co-hosted applications is not reachable this way. The consequence is principal confusion and misattributed audit records rather than a direct privilege escalation. Users of 3.3.0 or 3.3.1 should upgrade to Apache Airflow 3.3.2 or later, which resolves the caller from the explicitly supplied credential whenever one is present.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 8.1
CVE-2026-80110 · A flaw was found in pki-core.
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's profile-management REST API this allows a request to POST /v2/profiles/raw -- intended to require Administrator-level profiles.create permission -- to instead be authorized under the lower-privileged profiles.approve permission held by the default Certificate Manager Agents group. The highest threat from this vulnerability is to confidentiality and integrity of the certificate authority's issuance policy.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 7.4
CVE-2026-75939 · A flaw was found in openshift/oc-mirror.
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid Red Hat release key ID but a forged signature. This enables the `oc-mirror` tool to accept and mirror a malicious release payload into a disconnected registry, potentially compromising the integrity of software deployments.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 4.3
CVE-2026-75158 · Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read.
Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore enumerate asset events — including the source Dag ID, task ID, run ID and event timestamps — for Dags they have no permission to see. Because the filter was also absent from the count query, `total_entries` and pagination disclosed the existence of hidden Dags even without inspecting individual rows. Deployments are affected whenever per-Dag access control is used to separate teams or tenants; no special configuration is required. Upgrade to apache-airflow 3.3.2 or later.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 7.5
CVE-2026-71543 · OpenBao is an open source identity-based secrets management system.
OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated policies, asterisks, plus signs, and slashes could alter path matching. In PKI allowed_uri_sans_template and allowed_domains policies, an asterisk could broaden certificate issuance to unauthorized domains. In SSH allowed_users and allowed_domains policies, a comma could add unauthorized principals. Exploitation requires a deployment to use templated policy data that users can freely modify; templates based on the randomly generated identity.entity.id value are not affected. This could allow privilege escalation, unauthorized access, and unauthorized certificate issuance. This issue is fixed in version 2.6.0.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 7.0
CVE-2026-68919 · GoCD is a continuous deliver server.
GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage Detail, Job/Build Detail, Value Stream Map, and Pipeline History views. A user with write access to a material tracked by GoCD can store arbitrary HTML or JavaScript in a forged package material comment, which executes in the browser session of a user who later views an affected page. Exploitation requires a victim to view a page that renders the malicious modification, and GoCD does not render every material comment in every view. Successful exploitation can expose a privileged user session or allow changes using the victim's credentials and privileges. This issue is fixed in version 26.1.0.Czytaj całość ↵Źródło — otwiera w nowej karcieNVD · CVSS 4.2