Common Vulnerabilities and Exposures (CVE)

CVE-2026-97177

Sep 24, 2026 05:47:57 UTC

A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. This a...

CVE-2026-97176

Sep 24, 2026 05:47:52 UTC

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an active...

CVE-2026-14780

Sep 24, 2026 05:17:40 UTC

A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization and access restrictions within the embedded execution engine. An authenticated user with administrative access to the ma...

CVE-2026-71465

Sep 24, 2026 03:57:17 UTC

RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.extend(['-l', limit]) like RunJob. A limit beginning with - is parsed as an ansible CLI optio...

CVE-2026-71464

Sep 24, 2026 03:57:11 UTC

LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/JobTemplate/JobLaunch serializers. Schedule and WFJT Node accept --upload-pack=/bin/id as...

CVE-2026-71463

Sep 24, 2026 03:57:09 UTC

Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job'+'_env']) and {% if job.id > 100 %} conditional gating bypass both the AST check and the te...

CVE-2026-84691

Sep 24, 2026 03:55:46 UTC

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live ...

CVE-2026-87899

Sep 24, 2026 03:55:45 UTC

Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.

CVE-2026-88832

Sep 24, 2026 03:55:44 UTC

BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

CVE-2026-96804

Sep 24, 2026 03:55:42 UTC

MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

CVE-2026-73589

Sep 24, 2026 03:55:34 UTC

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerab...

CVE-2026-73588

Sep 24, 2026 03:55:34 UTC

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerabili...

CVE-2026-61413

Sep 24, 2026 03:55:33 UTC

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to U...

CVE-2026-86678

Sep 24, 2026 03:55:32 UTC

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.

CVE-2026-86683

Sep 24, 2026 03:55:31 UTC

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.