Vulnerebility
H
ECV
KB
KEV
MICROSOFT PATCH
WINDOWS UPDATE
Top 50 in years
|
2026
2025
| CPU VULNEREBILITY
SOFTWARE PATCH REPORTS
DRIVE VULNEREBILITY
Vulnerebility Calendar Top Vulnerebility
List of Attack
CWE LIST
Anti-Debug
Tricks
2026 January February March April May June July August September October November December
|
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
10.10.26 |
CVE-2025-30241 | Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions. An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise. | ||
|
10.10.26 |
CVE-2025-30240 | The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link. Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem. | ||
|
10.10.26 |
CVE-2025-30239 | In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information. | ||
|
10.10.26 |
CVE-2025-30238 | In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations. An attacker may perform administrative actions such as creating privileged accounts or modifying critical configuration settings. | ||
|
10.10.26 |
CVE-2025-30237 | The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations. Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device. | ||
|
10.10.26 |
CVE-2026-47483 | NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. | ||
|
10.10.26 |
CVE-2026-47483 | NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. | ||
|
9.10.26 |
CVE-2026-105133 | (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" component. | VULNEREBILITY | VULNEREBILITY |
|
9.10.26 |
CVE-2026-105134 | (CVSS v4 score: 9.3) - An operating system command injection vulnerability in the Replication Receiver component. | VULNEREBILITY | VULNEREBILITY |
|
9.10.26 |
CVE-2015-3306 | (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. | VULNEREBILITY | VULNEREBILITY |
|
9.10.26 |
CVE-2021-3199 | (CVSS score: 9.8) - A path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used, via a "/.." sequence in an image upload parameter and could allow for remote code execution. | VULNEREBILITY | VULNEREBILITY |
|
9.10.26 |
CVE-2023-22894 | (CVSS score: 7.2) - A cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter. | VULNEREBILITY | VULNEREBILITY |
|
9.10.26 |
CVE-2016-3081 | (CVSS score: 8.1) - A command injection vulnerability in Apache Struts that could allow a remote attacker to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. | VULNEREBILITY | VULNEREBILITY |
|
9.10.26 |
CVE-2015-5477 | (CVSS score: 7.5) - A reachable assertion vulnerability in ISC BIND that could allow a remote attacker to cause a denial-of-service via TKEY queries. | VULNEREBILITY | VULNEREBILITY |
|
9.10.26 |
CVE-2026-107406 | Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-107406 | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco Meraki Security Hardening Release: October 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, engineering teams conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco License (Smart Software Manager) On-Prem Vulnerabilities | Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthorized access, access sensitive information, cause a denial of service (DoS) | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities | Multiple vulnerabilities in the Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as Next Generation OAM (NGOAM), could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco NX-OS Software NX-API Remote Code Execution Vulnerability | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability | A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco License (Smart Software Manager) On-Prem Security Hardening Release: October 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco NX-OS Software Security Hardening Release: October 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco Application Policy Infrastructure Controller Security Hardening Release: October 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco Finesse Server-Side Request Forgery Vulnerability | A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.This vulnerability is due to improper input validation for specific HTTP requests | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco NX-OS Software Control Plane Denial of Service Vulnerability | A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition.This vulnerability exists because rate limiting was improperly applied to some protocols. An attacker could exploit this | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco NX-OS Software Python Sandbox Escape Vulnerability | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affected device.This vulnerability is due to | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco Application Policy Infrastructure Controller Unauthorized File Access Vulnerability | A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to access sensitive files on an affected device. To exploit this vulnerability, the attacker must have valid | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco Application Policy Infrastructure Controller API Command Injection Vulnerability | A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
Cisco Nexus 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability | A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts.This vulnerability is | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
CVE-2026-102255 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations. | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
CVE-2026-105192 | LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. | VULNEREBILITY | VULNEREBILITY |
|
8.10.26 |
CVE-2026-105756 | Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service | VULNEREBILITY | VULNEREBILITY |
|
6.10.26 |
CVE-2026-71168 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. | VULNEREBILITY | VULNEREBILITY |
|
6.10.26 |
CVE-2026-63697 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | VULNEREBILITY | VULNEREBILITY |
|
6.10.26 |
CVE-2026-86362 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit thishttps://www.cve.org/CVERecord?id=CVE-2026-105192 vulnerability, leading to Elevation of privileges. | VULNEREBILITY | VULNEREBILITY |
|
6.10.26 |
CVE-2026-86361 | Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | VULNEREBILITY | VULNEREBILITY |
|
6.10.26 |
CVE-2026-86360 | Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | VULNEREBILITY | VULNEREBILITY |
|
6.10.26 |
CVE-2021-26086 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1. | VULNEREBILITY | VULNEREBILITY |
|
6.10.26 |
CVE-2026-21589 | CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products | VULNEREBILITY | VULNEREBILITY |
|
6.10.26 |
CVE-2026-96940 | Microsoft Exchange Server Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
5.10.26 |
Horizon3’s Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS | Anthropic started Project Glasswing with the mission of securing the world’s most critical software. Since joining the project in July of 2026, Horizon3 has used Anthropic’s Mythos model in its vulnerability research pipelines to discover many critical vulnerabilities. Horizon3’s participation in the project came with our own internal mission to find vulnerabilities likely to be found and exploited in the wild by threat actors at scale. | VULNEREBILITY | VULNEREBILITY |
|
5.10.26 |
CVE-2026-61500 | Rejetto HFS 3.0.0 through 3.2.0 derives its session... | VULNEREBILITY | VULNEREBILITY |
|
5.10.26 |
CVE-2026-88779 | Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779 | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-104286 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-92371 | TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-92369 | TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-19743 | Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation. | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-92368 | TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user | VULNEREBILITY | VULNEREBILITY |
|
4.10.26 |
CVE-2026-92370 | An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability | A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.This vulnerability is due to improper handling of URI encoding | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
Cisco IOS XE Software Security Hardening Release: August 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-90970 | GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-67273 | (CVSS score: 9.6) - An improper neutralization of special elements used in a template engine vulnerability that a low-privilege attacker with remote access could exploit to escalate privileges, access sensitive information, and carry out unauthorized RBAC tampering. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-61421 | (CVSS score: 9.8) - A use of hard-coded cryptographic key vulnerability in the JWT authentication component of karavi-authorization that a remote unauthenticated attacker with knowledge of this publicly available signing secret could exploit to forge authentication tokens and gain administrative privileges. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-54472 | (CVSS score: 9.8) - A use of hard-coded credentials vulnerability in the CSM Authorization module that a remote unauthenticated attacker could exploit to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM Authorization proxy. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-67269 | (CVSS score: 9.9) - An improper privilege management vulnerability in the ContainerStorageModule Custom Resource reconciler that a low-privilege remote attacker could exploit to escalate privileges and gain root-level access on cluster nodes. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-63692 | (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the authorization proxy and tenant service that an unauthenticated network attacker could exploit to bypass authentication controls and gain administrative-level privileges. | VULNEREBILITY | VULNEREBILITY |
|
3.10.26 |
CVE-2026-63688 | (CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an unauthenticated remote attacker could exploit to obtain unauthorized access to storage backend administrator credentials for all registered storage arrays. | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86950 | CVE-2026-86950: The Great Glyph Grift | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86134 Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86104 Fireware OS Resource Exhaustion in Login Process Allows Denial of Service | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-18145 Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-13046 Fireware OS Deserialization of Untrusted Data in samld Allows Remote Code Execution | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86101 Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86133 Fireware OS Pre-Authentication Integer Underflow in iked Allows Remote Denial of Service | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-13224 Fireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File Read | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86132 Fireware OS Pre-Authentication Integer Underflow in iked Allows Denial of Service | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86105 Fireware OS Improper Authorization in Access Portal Reverse Proxy | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-90441 Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant B | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86131 Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86136 Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant A | Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-81433 Fireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code Execution | Fireware OS>= 2026.3, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86128 Fireware OS NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allows Remote Denial of Service | Default>= 2026.3, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-18105 Fireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of Service | Default>= 2026.3, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-101891 WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access | WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-86102 WatchGuard AP Command Injection in Internal Management API Allows Command Execution | WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8 | VULNEREBILITY | VULNEREBILITY |
|
1.10.26 |
CVE-2026-87969 WatchGuard AP Authenticated Command Injection in Diagnostic CLI | WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8 | VULNEREBILITY | VULNEREBILITY |