CVE Index
43 identifiers across 39 articles. Search by number — the box below matches identifiers only. For a subject rather than a number, search the writing.
cve — index
43 identifiers covered — type a number to filter
2026 — 42 identifiers
- CVE-2026-422712026-10-08The command server's address is four words in a poem, and moving the botnet means editing the poem
- CVE-2026-1024062026-10-08Kibana let one tenant claim another's data stream, and removing the package does not give it back
- CVE-2026-165162026-10-08The host key check ran, and passed, on a curve the attacker chose for it
- CVE-2026-215892026-10-08 — 2 ARTICLESTwo hours passed between the proof of concept going public and the first attempt landing in a honeypot
- CVE-2026-1064462026-10-07Handlebars checked the parts of the template it expected to see, and compiled everything else into JavaScript
- CVE-2026-1064452026-10-07Handlebars checked the parts of the template it expected to see, and compiled everything else into JavaScript
- CVE-2026-969402026-10-06One working mailbox password let an Exchange user read everyone else's mail, and the cloud was fixed before anyone was told
- CVE-2026-615002026-10-06A model found the weak random number generator and, in the same pass, the unauthenticated path that leaks its output
- CVE-2026-887792026-10-06The NetScaler appliances restarting after the patch were not a patch bug — they were a third zero-day, and the sixth crash is the trigger
- CVE-2026-869502026-10-05Apple's font bug was used against a handful of people, and the proof of concept now crashes any unpatched iPhone
- CVE-2026-933482026-10-05Choosing a model in Unsloth Studio ran that model's code, and because the product was in beta there is no CVE to tell anyone
- CVE-2026-909702026-10-03GitLab's AI gateway let a prompt template run commands on the server, which is server-side template injection with a new place to live
- CVE-2026-887712026-10-03The NetScaler build that stopped the exploitation is restarting the gateway, and the bulletin that told you to install it says nothing about it
- CVE-2026-887722026-10-03 — 2 ARTICLESThe NetScaler build that stopped the exploitation is restarting the gateway, and the bulletin that told you to install it says nothing about it
- CVE-2026-1024892026-10-02The attacker left comments explaining why what it was doing was fine, and that is how DIVD decided it was not a person
- CVE-2026-1024902026-10-02The attacker left comments explaining why what it was doing was fine, and that is how DIVD decided it was not a person
- CVE-2026-1042862026-10-02FortiMail's path check and its file write disagree about where a filename ends, and attackers are already there
- CVE-2026-735702026-10-01The Zimbra flaw arrives as an email, and what it takes is the pair of keys that make passwords beside the point
- CVE-2026-765042026-10-01One hex-encoded letter walks past Cisco SD-WAN Manager's login, and it is already being used
- CVE-2026-645072026-10-01The CPU forgets the code and remembers where it jumped. That is enough to read the root hash
- CVE-2026-519902026-09-15Tencent patched the link into Sogou's hidden browser. The six-year-old engine, still unsandboxed, is still there
- CVE-2026-857062026-09-12One unauthenticated request reads any file on the GitLab server, and the patch taught attackers how
- CVE-2026-200792026-09-12The ransomware crew skipped Cisco's 10.0. It logged in with the 5.3 that CISA listed back in July
- CVE-2026-203162026-09-12The ransomware crew skipped Cisco's 10.0. It logged in with the 5.3 that CISA listed back in July
- CVE-2026-851022026-09-11Check Point's two 9.8s are in the code that reads the certificate before deciding whether to trust it
- CVE-2026-851032026-09-11Check Point's two 9.8s are in the code that reads the certificate before deciding whether to trust it
- CVE-2026-815782026-09-11 — 2 ARTICLESThe attacker told the agents which 28 countries to leave alone. They hit six of them
- CVE-2026-820782026-09-11 — 2 ARTICLESThe attacker told the agents which 28 countries to leave alone. They hit six of them
- CVE-2026-825332026-09-09The fence around the sandbox was a request header, and the agent inside sent one
- CVE-2026-674012026-09-09The cPanel advisory says almost nothing, and on shared hosting the precondition is a paid plan
- CVE-2026-694142026-09-09The researcher says Microsoft's Defender patch missed a spot, and published the proof
- CVE-2026-447562026-09-09The SAP flaw runs before authentication, so Segregation of Duties does not apply
- CVE-2026-858802026-09-09974 flaws, and the two that matter are both privilege escalation
- CVE-2026-765782026-09-09The anonymous client passes the ownership check by being nobody
- CVE-2026-593462026-09-08Two guest-to-host escapes in Workstation and Fusion, and guest admin is the whole precondition
- CVE-2026-593472026-09-08Two guest-to-host escapes in Workstation and Fusion, and guest admin is the whole precondition
- CVE-2026-131812026-09-07The Telerik exploit chain needs the hardening step Telerik recommends
- CVE-2026-862182026-09-07N-able's two documents disagreed about exploitation. CISA has settled it
- CVE-2026-630772026-09-07The flaw entered CISA's catalogue on 5 August. JetBrains' own server was breached through it on the 8th
- CVE-2026-850462026-09-07A Chrome V8 zero-day paid $1,000. The lowest published tier is $7,000
- CVE-2026-64712026-09-07REPLICATION was never a read-only privilege. For twelve years it was a shell
- CVE-2026-660662026-09-01Patching Rails against KindaRails2Shell only works if the libvips underneath it is new enough