Security

7,997 items RSS
C
CVE Project (cvelistV5) Security

CVE 2026-09-16_2000Z

1881 changes (714 new | 1167 updated): - 714 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2025-36591, CVE-2025-43936, CVE-2025-59953, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-14916, CVE-2026-14917, CVE-2026-16588, CVE-2026-16794, CVE-2026-17526, CVE-2026-18120, CVE-2026-18212, CVE-2026-18555, CVE-2026-18595, CVE-2026-19033, CVE-2026-19248, CVE-2026-…

A
AWS Security Bulletins Security

CVE-2026-86831: Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS

Bulletin ID: 2026-113-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/16/2026 12:30 PM PDT Description: Network Policy Agent is an EKS Policy management feature. We identified CVE-2026-86831, a cross-namespace NetworkPolicy bypass in Amazon EKS Network Policy Agent (aws-network-policy-agent) before v1.4.0. Pod identifiers are constructed by concatenating the pod na…

U
Ubuntu Security Notices Security

USN-8776-1: python-cryptography vulnerabilities

It was discovered that python-cryptography incorrectly accepted objects with immutable buffers when performing certain cipher operations. This would result in corrupted output, contrary to expectations. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-23931) It was discovered that python-cryptography reported the outcome of decrypting PKCS#7 enveloped data in distinguishable ways, and with obs…

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_1900Z

1800 changes (669 new | 1131 updated): - 669 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2025-36591, CVE-2025-43936, CVE-2025-59953, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-14916, CVE-2026-14917, CVE-2026-16588, CVE-2026-16794, CVE-2026-17526, CVE-2026-18120, CVE-2026-18212, CVE-2026-18555, CVE-2026-18595, CVE-2026-19033, CVE-2026-19248, CVE-2026-…

I
Infisical Security v0.165.12

v0.165.12

What's Changed feat(pam): restore Oracle Database account support by @carlosmonastyrski in #8035 fix(cert-management): fix dupe member issue by @lb-vn in #8147 fix: oracle cli version by @carlosmonastyrski in #8152 improvement(frontend): migrate server admins modal to v3 components by @claude[bot] in #8045 improvement(admin): migrate remaining server console UI to v3 by @andrewhuhh in #8149 docs(a…

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_1800Z

1734 changes (636 new | 1098 updated): - 636 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2025-36591, CVE-2025-43936, CVE-2025-59953, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-14916, CVE-2026-14917, CVE-2026-16588, CVE-2026-16794, CVE-2026-17526, CVE-2026-18120, CVE-2026-18212, CVE-2026-18555, CVE-2026-18595, CVE-2026-19033, CVE-2026-19248, CVE-2026-…

T
TruffleHog Security v3.97.5

v3.97.5

What's Changed Update module github.com/rabbitmq/amqp091-go to v1.13.0 [SECURITY] by @renovate[bot] in #5274 Update github-actions by @renovate[bot] in #5250 Update dependency golangci/golangci-lint to v2.13.2 by @renovate[bot] in #5251 Make GitHub App installationId optional when scanning all installations by @kashifkhan0771 in #5275 [INT-942] Add HumioAPIToken detector by @unsmith in #5258 Objec…

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_1700Z

1666 changes (619 new | 1047 updated): - 619 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2025-36591, CVE-2025-43936, CVE-2025-59953, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-14916, CVE-2026-14917, CVE-2026-16588, CVE-2026-16794, CVE-2026-17526, CVE-2026-18212, CVE-2026-18555, CVE-2026-18595, CVE-2026-19033, CVE-2026-19248, CVE-2026-19535, CVE-2026-…

U
Ubuntu Security Notices Security

USN-8774-1: libheif vulnerabilities

Ali Firas discovered that libheif incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-62291) Dmitrijs Trizna discovered that libheif incorrectly handled certain image sequences. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-62377)

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_1600Z

1042 changes (584 new | 458 updated): - 584 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2025-36591, CVE-2025-43936, CVE-2025-59953, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-14916, CVE-2026-14917, CVE-2026-16588, CVE-2026-16794, CVE-2026-17526, CVE-2026-18212, CVE-2026-18555, CVE-2026-18595, CVE-2026-19033, CVE-2026-19248, CVE-2026-19535, CVE-2026-1…

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_1500Z

949 changes (568 new | 381 updated): - 568 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2025-36591, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-14916, CVE-2026-14917, CVE-2026-16588, CVE-2026-16794, CVE-2026-18212, CVE-2026-18555, CVE-2026-18595, CVE-2026-19033, CVE-2026-19248, CVE-2026-19535, CVE-2026-19619, CVE-2026-19640, CVE-2026-19662, CVE-2026-19…

K
Keycloak Security v26.7.4

26.7.4

Upgrading Before upgrading refer to the migration guide for a complete list of changes. All resolved issues Security fixes #52834 [CVE-2026-90997] Default MySQL/MariaDB row counts make stateless replay gates accept reused artifacts #52835 [CVE-2026-79651] Keycloak Unauthenticated Denial of Service via Unbounded Locale Caching #52836 [CVE-2026-74909] Incomplete fix: percent-encoded semicolon bypass…

U
Ubuntu Security Notices Security

USN-8736-2: Perl vulnerabilities

USN-8736-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 24.04 LTS. Original advisory details: It was discovered that Perl incorrectly handled certain large inputs during regular expression matching. An attacker could possibly use this issue to trigger out-of-bounds heap reads or writes, resulting in a denial of service or arbitrary code execution. (C…

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_1400Z

766 changes (518 new | 248 updated): - 518 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-14916, CVE-2026-14917, CVE-2026-16588, CVE-2026-16794, CVE-2026-18555, CVE-2026-18595, CVE-2026-19248, CVE-2026-19535, CVE-2026-19619, CVE-2026-19640, CVE-2026-19662, CVE-2026-19667, CVE-2026-19857, CVE-2026-19941, CVE-2026-11…

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_1300Z

693 changes (474 new | 219 updated): - 474 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-14916, CVE-2026-14917, CVE-2026-16588, CVE-2026-16794, CVE-2026-18555, CVE-2026-18595, CVE-2026-19248, CVE-2026-19535, CVE-2026-19619, CVE-2026-19640, CVE-2026-19857, CVE-2026-1168, CVE-2026-27546, CVE-2026-27547, CVE-2026-275…

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_1200Z

623 changes (456 new | 167 updated): - 456 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-14916, CVE-2026-14917, CVE-2026-16588, CVE-2026-16794, CVE-2026-18555, CVE-2026-18595, CVE-2026-19248, CVE-2026-19619, CVE-2026-19640, CVE-2026-19857, CVE-2026-1168, CVE-2026-27546, CVE-2026-27547, CVE-2026-27548, CVE-2026-275…

C

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose si…

C

Using Cyber Decoys to Strengthen Detection and Response

CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber dec…

C

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security…

U
Ubuntu Security Notices Security

USN-8773-1: GNU Guix vulnerability

It was discovered that GNU Guix incorrectly made build outputs accessible to local users before their file metadata was finalized. A local attacker could possibly use this issue to gain elevated privileges.

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_1100Z

602 changes (440 new | 162 updated): - 440 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-14916, CVE-2026-14917, CVE-2026-16588, CVE-2026-16794, CVE-2026-18555, CVE-2026-18595, CVE-2026-19248, CVE-2026-19619, CVE-2026-19640, CVE-2026-19857, CVE-2026-1168, CVE-2026-27546, CVE-2026-27547, CVE-2026-27548, CVE-2026-275…

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_1000Z

319 changes (173 new | 146 updated): - 173 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-16588, CVE-2026-16794, CVE-2026-18555, CVE-2026-18595, CVE-2026-19248, CVE-2026-19619, CVE-2026-19640, CVE-2026-19857, CVE-2026-1168, CVE-2026-27546, CVE-2026-27547, CVE-2026-27548, CVE-2026-27549, CVE-2026-27550, CVE-2026-275…

U
Ubuntu Security Notices Security

USN-8772-1: AOM vulnerabilities

It was discovered that AOM incorrectly handled the first-pass statistics buffer in Look-Ahead Processing (LAP) mode. An attacker could possibly use this issue to cause a heap buffer overflow, leading to a denial of service or possibly execute arbitrary code. (CVE-2026-56208) It was discovered that AOM incorrectly validated spatial and temporal layer IDs in the SVC (Scalable Video Coding) encoder c…

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_0900Z

296 changes (151 new | 145 updated): - 151 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-16588, CVE-2026-16794, CVE-2026-18555, CVE-2026-18595, CVE-2026-19248, CVE-2026-19619, CVE-2026-19857, CVE-2026-1168, CVE-2026-27546, CVE-2026-27547, CVE-2026-27548, CVE-2026-27549, CVE-2026-27550, CVE-2026-27551, CVE-2026-275…

U
Ubuntu Security Notices Security

USN-8514-2: OpenSSH vulnerability

USN-8514-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could use this to install setuid or setgid files…

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_0800Z

253 changes (109 new | 144 updated): - 109 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-16588, CVE-2026-16794, CVE-2026-18555, CVE-2026-18595, CVE-2026-19248, CVE-2026-19619, CVE-2026-19857, CVE-2026-1168, CVE-2026-27546, CVE-2026-27547, CVE-2026-27548, CVE-2026-27549, CVE-2026-27550, CVE-2026-27551, CVE-2026-275…

E
Ente (Photos & Auth) Security v4.4.26-beta

auth-v4.4.26-beta: [mobile] Wait for progress dialog frame (#12942)

The lifecycle fix in #12939 removed the fixed dismissal delay, but show() could consequently resolve before Flutter painted the newly pushed route. Callers that begin synchronous import decryption immediately afterward could freeze the UI before the progress dialog became visible. Wait for the end of the first frame after pushing and recording the dialog route. This preserves safe immediate dismis…

C
CVE Project (cvelistV5) Security

CVE 2026-09-16_0700Z

225 changes (82 new | 143 updated): - 82 new CVEs: CVE-2024-11222, CVE-2025-14871, CVE-2026-11984, CVE-2026-11996, CVE-2026-12793, CVE-2026-13407, CVE-2026-14349, CVE-2026-16588, CVE-2026-16794, CVE-2026-18555, CVE-2026-18595, CVE-2026-19248, CVE-2026-19619, CVE-2026-19857, CVE-2026-1168, CVE-2026-3855, CVE-2026-5920, CVE-2026-61396, CVE-2026-73447, CVE-2026-73450, CVE-2026-74926, CVE-2026-76550,…