Common Vulnerabilities and Exposures (CVE)

CVE-2026-86139

Sep 5, 2026 04:23:14 UTC

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

CVE-2026-86138

Sep 5, 2026 04:21:53 UTC

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

CVE-2026-86137

Sep 5, 2026 04:19:30 UTC

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

CVE-2026-70178

Sep 5, 2026 03:55:34 UTC

Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

CVE-2026-70352

Sep 5, 2026 03:55:33 UTC

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-80098

Sep 5, 2026 03:55:32 UTC

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-83711

Sep 5, 2026 03:55:31 UTC

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-65818

Sep 5, 2026 03:55:30 UTC

Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

CVE-2026-62916

Sep 5, 2026 03:55:29 UTC

Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-85046

Sep 5, 2026 03:55:27 UTC

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-62196

Sep 5, 2026 03:55:26 UTC

OpenClaw versions 2026.3.22 before 2026.6.6 contain an authorization bypass vulnerability where WhatsApp group IDs can satisfy elevated sender allowlists. Attackers with lower-trust access can perform actions requiring stronger authorizatio...

CVE-2026-85444

Sep 5, 2026 02:28:34 UTC

MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length. Attackers can send NODE_REPORT messages with leading ...

CVE-2026-85439

Sep 5, 2026 02:26:42 UTC

MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can embed shell syntax in log...

CVE-2026-85434

Sep 5, 2026 02:25:21 UTC

MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-co...

CVE-2026-85429

Sep 5, 2026 02:23:47 UTC

MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other n...