Common Vulnerabilities and Exposures (CVE)

CVE-2026-20212

Sep 3, 2026 03:56:34 UTC

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 ar...

CVE-2026-20274

Sep 3, 2026 03:56:33 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that a...

CVE-2026-20275

Sep 3, 2026 03:56:31 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that a...

CVE-2026-20279

Sep 3, 2026 03:56:30 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that a...

CVE-2026-66842

Sep 3, 2026 03:56:29 UTC

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an a...

CVE-2026-20280

Sep 3, 2026 03:56:28 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases t...

CVE-2026-84645

Sep 3, 2026 03:56:27 UTC

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field val...

CVE-2026-20278

Sep 3, 2026 03:56:26 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that a...

CVE-2026-78604

Sep 3, 2026 03:56:25 UTC

Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources us...

CVE-2026-75604

Sep 3, 2026 03:56:23 UTC

Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape...

CVE-2026-73778

Sep 3, 2026 03:56:22 UTC

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state befor...

CVE-2026-73771

Sep 3, 2026 03:56:20 UTC

An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass aut...

CVE-2026-73763

Sep 3, 2026 03:56:19 UTC

A vulnerability exists in a management component that could allow an unauthenticated adjacent attacker to execute arbitrary commands. Successful exploitation could result in remote execution of arbitrary commands in the context of the affec...

CVE-2026-73758

Sep 3, 2026 03:56:17 UTC

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low privilege operator user to change the state of certain settings of a vulnerable system.

CVE-2026-73755

Sep 3, 2026 03:56:16 UTC

A privilege escalation vulnerability exists in the API endpoint of AOS-CX. Successful exploitation could allow an authenticated low-privilege operator user, after a required user action, to access sensitive information from the vulnerable s...