Common Vulnerabilities and Exposures (CVE)

CVE-2026-67397

Sep 3, 2026 23:57:15 UTC

Path traversal in Plesk 18.0.79.9 and earlier and 18.0.80 through 18.0.80.5 allows local users to execute arbitrary code as root.

CVE-2026-67402

Sep 3, 2026 23:57:15 UTC

An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and r...

CVE-2026-67398

Sep 3, 2026 23:57:15 UTC

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHM...

CVE-2026-17252

Sep 3, 2026 23:30:17 UTC

A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability by se...

CVE-2026-49509

Sep 3, 2026 23:11:38 UTC

Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overread Buffers. This issue affects Escargot: 25648aef19187b3f87f4d9420b8d761453ad4630.

CVE-2026-16493

Sep 3, 2026 23:01:45 UTC

A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing c...

CVE-2026-11332

Sep 3, 2026 23:01:40 UTC

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can injec...

CVE-2026-85378

Sep 3, 2026 23:00:10 UTC

A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterCo...

CVE-2026-62916

Sep 3, 2026 22:59:17 UTC

Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-65818

Sep 3, 2026 22:59:17 UTC

Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

CVE-2026-69857

Sep 3, 2026 22:59:16 UTC

Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.

CVE-2026-83711

Sep 3, 2026 22:59:15 UTC

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-80098

Sep 3, 2026 22:59:13 UTC

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-70352

Sep 3, 2026 22:59:12 UTC

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-70178

Sep 3, 2026 22:59:11 UTC

Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.