Common Vulnerabilities and Exposures (CVE)

CVE-2026-88032

Sep 10, 2026 23:36:07 UTC

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to c...

CVE-2026-84941

Sep 10, 2026 23:35:53 UTC

An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of use...

CVE-2026-19820

Sep 10, 2026 23:32:25 UTC

A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level syste...

CVE-2026-77807

Sep 10, 2026 23:27:03 UTC

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes...

CVE-2026-81906

Sep 10, 2026 23:20:47 UTC

Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete auth...

CVE-2026-81905

Sep 10, 2026 23:16:31 UTC

Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alone ...

CVE-2026-17176

Sep 10, 2026 23:14:33 UTC

An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete...

CVE-2026-83711

Sep 10, 2026 23:12:16 UTC

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-80098

Sep 10, 2026 23:12:15 UTC

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-70352

Sep 10, 2026 23:12:15 UTC

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-62906

Sep 10, 2026 23:12:14 UTC

Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

CVE-2026-62804

Sep 10, 2026 23:12:13 UTC

External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2026-66307

Sep 10, 2026 23:12:13 UTC

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

CVE-2026-66303

Sep 10, 2026 23:12:12 UTC

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

CVE-2026-84003

Sep 10, 2026 23:12:12 UTC

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.