| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-86464 | Cri | 0.57 | — | 0.00 | Sep 8, 2026 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak… | ||
| CVE-2026-84869 | Cri | 0.76 | 9.9 | 0.01 | KEV | Sep 8, 2026 | A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted. | |
| CVE-2026-84197 | Cri | 0.60 | — | 0.00 | Sep 8, 2026 | In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes… | ||
| CVE-2026-75746 | Cri | 0.59 | 9.1 | 0.01 | Sep 8, 2026 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to… | ||
| CVE-2026-48273 | Cri | 0.64 | 9.9 | 0.02 | Sep 8, 2026 | ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to… | ||
| CVE-2026-19232 | Cri | 0.64 | 9.9 | 0.01 | Sep 8, 2026 | Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could… | ||
| CVE-2026-82004 | Cri | 0.65 | 10.0 | 0.01 | Sep 8, 2026 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability… | ||
| CVE-2026-76201 | Cri | 0.60 | 9.3 | 0.00 | Sep 8, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the… | ||
| CVE-2026-76200 | Cri | 0.60 | 9.3 | 0.00 | Sep 8, 2026 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the… | ||
| CVE-2026-66302 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-58822 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2026-49921 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2026-28606 | Cri | 0.64 | 9.8 | 0.00 | Sep 8, 2026 | In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2026-83941 | Cri | 0.64 | 9.9 | 0.01 | Sep 8, 2026 | Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-81376 | Cri | 0.62 | 9.6 | 0.01 | Sep 8, 2026 | Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-78510 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-78509 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-78445 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-77493 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-73025 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-73010 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-73009 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-72983 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-72982 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-72979 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-70296 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69910 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69854 | Cri | 0.59 | 9.0 | 0.01 | Sep 8, 2026 | Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-69845 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69829 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69824 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69819 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69769 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69768 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69730 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69715 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69641 | Cri | 0.59 | 9.1 | 0.01 | Sep 8, 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-69595 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69590 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | ||
| CVE-2026-69586 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69579 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69525 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69496 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69493 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69491 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69463 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69431 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69408 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-69356 | Cri | 0.61 | 9.3 | 0.01 | Sep 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-69276 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2026 | Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network. |
- risk 0.57cvss —epss 0.00
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak…
- risk 0.76cvss 9.9epss 0.01
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
- risk 0.60cvss —epss 0.00
In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes…
- risk 0.59cvss 9.1epss 0.01
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to…
- risk 0.64cvss 9.9epss 0.02
ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to…
- risk 0.64cvss 9.9epss 0.01
Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. A low-privileged attacker could…
- risk 0.65cvss 10.0epss 0.01
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability…
- risk 0.60cvss 9.3epss 0.00
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the…
- risk 0.60cvss 9.3epss 0.00
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the…
- risk 0.64cvss 9.8epss 0.01
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.00
In multiple functions of ftsmooth.c, there is a possible memory safety issue due to improper casting. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
In multiple locations, there is a possible memory safety issue due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.00
In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with no additional execution privileges needed. User interaction is not needed for…
- risk 0.64cvss 9.9epss 0.01
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
- risk 0.62cvss 9.6epss 0.01
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Stack-based buffer overflow in Windows Hyper-V allows an unauthorized attacker to execute code over a network.
- risk 0.59cvss 9.0epss 0.01
Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.
- risk 0.59cvss 9.1epss 0.01
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- risk 0.64cvss 9.8epss 0.01
Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.01
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
- risk 0.61cvss 9.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.64cvss 9.8epss 0.01
Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.