CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Sep 19, 2026
Sep 17, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Ch...Show more
Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)Show less
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High...Show more
Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)Show less
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
8.1 HIGH· v3
N/A· v2
Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security s...Show more
Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)Show less
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Criti...Show more
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)Show less
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
-
-
Sep 19, 2026
Sep 18, 2026
N/A· v4
9.9 CRITICAL· v3
N/A· v2
Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
-
-
Sep 19, 2026
Sep 15, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allow...Show more
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).Show less
-
-
Sep 19, 2026
Sep 15, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability a...Show more
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).Show less
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
-
-
Sep 19, 2026
Sep 18, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
-
-
Sep 19, 2026
Sep 18, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
1Linux
1Linux Kernel
Sep 19, 2026
Jun 25, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(sk...Show more
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().Show less
-
-
Sep 19, 2026
Sep 17, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, wri...Show more
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS.Show less
-
-
Sep 19, 2026
Sep 18, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of message distribution list structures.
-
-
Sep 19, 2026
Sep 18, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in distribution list processing.