Common Vulnerabilities and Exposures (CVE)

CVE-2026-15554

Sep 17, 2026 23:27:08 UTC

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authenticatio...

CVE-2026-10579

Sep 17, 2026 23:26:48 UTC

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead...

CVE-2026-93454

Sep 17, 2026 23:25:13 UTC

Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoi...

CVE-2026-93453

Sep 17, 2026 23:25:12 UTC

SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password recov...

CVE-2026-93452

Sep 17, 2026 23:25:12 UTC

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination buffe...

CVE-2026-93451

Sep 17, 2026 23:25:11 UTC

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Attacke...

CVE-2026-93450

Sep 17, 2026 23:25:10 UTC

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON documen...

CVE-2026-93308

Sep 17, 2026 23:15:13 UTC

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiated r...

CVE-2026-87886

Sep 17, 2026 23:09:27 UTC

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638, Ac...

CVE-2026-85887

Sep 17, 2026 23:04:48 UTC

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

CVE-2026-83946

Sep 17, 2026 23:04:47 UTC

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-69843

Sep 17, 2026 23:04:47 UTC

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-85878

Sep 17, 2026 23:04:46 UTC

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

CVE-2026-62874

Sep 17, 2026 23:04:46 UTC

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-83711

Sep 17, 2026 23:04:45 UTC

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.