CVE-2026-42016
HIGH
CVSS: 8.1
EPSS: 8.6%
VulnCheck KEV
PoC Available
CISA KEV
CWE-863
T1078
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
Published: 2026-07-27
Mentioned in 2 article(s):
CVE-2026-85103
CRITICAL
CVSS: 9.8
EPSS: 3.7%
CWE-122
T1203
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
Published: 2026-09-09
Mentioned in 2 article(s):
CVE-2026-76023
HIGH
CVSS: 8.8
EPSS: 0.5%
CWE-913
Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-20
Mentioned in 1 article(s):
CVE-2026-76022
HIGH
CVSS: 8.8
EPSS: 0.5%
CWE-122
T1203
Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-20
Mentioned in 1 article(s):
CVE-2026-76021
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-416
T1203
Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-20
Mentioned in 1 article(s):
CVE-2026-76019
HIGH
CVSS: 8.1
EPSS: 0.3%
CWE-863
T1078
Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-20
Mentioned in 1 article(s):
CVE-2026-76018
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-250
T1068
Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)
Published: 2026-08-20
Mentioned in 1 article(s):
CVE-2026-76017
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-416
T1203
Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)
Published: 2026-08-20
Mentioned in 1 article(s):
CVE-2026-76039
MEDIUM
CVSS: 6.5
EPSS: 0.3%
CWE-706
Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-18
Mentioned in 1 article(s):
CVE-2026-76036
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-122
T1203
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-08-18
Mentioned in 1 article(s):
CVE-2026-85053
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-668
Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-03
Mentioned in 1 article(s):
CVE-2026-85052
LOW
CVSS: 3.1
EPSS: 0.2%
CWE-125
T1005
Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-03
Mentioned in 1 article(s):
CVE-2026-85051
HIGH
CVSS: 8.8
EPSS: 0.5%
CWE-843
Type confusion in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-03
Mentioned in 1 article(s):
CVE-2026-85049
HIGH
CVSS: 8.8
EPSS: 0.3%
CWE-416
T1203
Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-03
Mentioned in 1 article(s):
CVE-2026-85048
HIGH
CVSS: 8.3
EPSS: 0.4%
CWE-416
T1203
Use after free in Compositing in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-03
Mentioned in 1 article(s):
CVE-2026-85045
HIGH
CVSS: 7.5
EPSS: 0.3%
CWE-367
Race condition in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-03
Mentioned in 1 article(s):
CVE-2026-85043
CRITICAL
CVSS: 9.1
EPSS: 0.4%
CWE-459
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)
Published: 2026-09-03
Mentioned in 1 article(s):
CVE-2026-85042
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-416
T1203
Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-03
Mentioned in 1 article(s):
CVE-2026-84333
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-416
T1203
Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-02
Mentioned in 1 article(s):
CVE-2026-84330
MEDIUM
CVSS: 5.4
EPSS: 0.3%
CWE-451
UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-02
Mentioned in 1 article(s):
CVE-2026-84352
CRITICAL
CVSS: 9.6
EPSS: 0.5%
CWE-416
T1203
Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-02
Mentioned in 1 article(s):
CVE-2026-85892
HIGH
CVSS: 7.8
EPSS: 0.2%
CWE-362
T1068
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
Published: 2026-09-14
Mentioned in 1 article(s):
CVE-2026-77490
MEDIUM
CVSS: 6.1
EPSS: 0.4%
CWE-79
T1189
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-11
Mentioned in 1 article(s):
CVE-2025-2137
HIGH
CVSS: 8.8
EPSS: 0.4%
CWE-125
CWE-125
T1005
Out of bounds read in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Published: 2025-03-10
Mentioned in 1 article(s):
CVE-2025-1920
HIGH
CVSS: 8.8
EPSS: 0.3%
CWE-843
CWE-843
Type Confusion in V8 in Google Chrome prior to 134.0.6998.88 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2025-03-10
Mentioned in 1 article(s):
CVE-2026-20079
CRITICAL
CVSS: 10.0
EPSS: 88.2%
VulnCheck KEV
Weaponized
Metasploit
CWE-288
T1078
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.
Published: 2026-03-04
Mentioned in 5 article(s):
CVE-2026-84869
CRITICAL
CVSS: 9.9
EPSS: 0.9%
VulnCheck KEV
Weaponized
CWE-269
CWE-862
T1068
T1078
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-42018
HIGH
CVSS: 7.5
EPSS: 9.8%
VulnCheck KEV
PoC Available
CWE-287
T1078
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
Published: 2026-08-12
Mentioned in 1 article(s):
CVE-2026-19490
CRITICAL
CVSS: 9.8
EPSS: 23.2%
VulnCheck KEV
Weaponized
CWE-288
T1078
Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
Published: 2026-08-19
Mentioned in 2 article(s):
CVE-2025-25249
HIGH
CVSS: 8.1
EPSS: 3.9%
VulnCheck KEV
Weaponized
CWE-122
CWE-787
T1203
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized code or commands via specially crafted packets
Published: 2026-01-13
Mentioned in 2 article(s):
CVE-2026-67277
HIGH
CVSS: 8.2
EPSS: 1.6%
VulnCheck KEV
Weaponized
CWE-306
T1078
RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel.
This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Published: 2026-09-05
Mentioned in 1 article(s):
CVE-2026-69414
HIGH
CVSS: 7.8
EPSS: 0.3%
CWE-284
CWE-269
T1068
T1078
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
Published: 2026-08-14
Mentioned in 1 article(s):
CVE-2026-44756
CRITICAL
CVSS: 10.0
EPSS: 0.7%
CWE-120
T1203
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-86218
CRITICAL
CVSS: 9.8
EPSS: 12.9%
VulnCheck KEV
Weaponized
CWE-96
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Published: 2026-09-06
Mentioned in 2 article(s):
CVE-2026-75650
CRITICAL
CVSS: 10.0
EPSS: 3.9%
VulnCheck KEV
PoC Available
CWE-1336
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Published: 2026-09-07
Mentioned in 4 article(s):
CVE-2026-83941
CRITICAL
CVSS: 9.9
EPSS: 0.8%
CWE-862
T1078
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-66302
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-73
T1083
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67631
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-67643
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-68839
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-20
CWE-122
T1190
T1203
Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69276
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
CWE-191
T1203
Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69408
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
CWE-190
T1203
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69431
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69463
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69491
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69493
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
CWE-125
T1005
T1203
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69496
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
T1203
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69525
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-416
T1203
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69579
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-416
T1203
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):
CVE-2026-69586
CRITICAL
CVSS: 9.8
EPSS: 1.0%
CWE-122
CWE-190
T1203
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
Published: 2026-09-08
Mentioned in 1 article(s):