View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical

🚨 ACTIVE EXPLOITS & INCIDENTS

🕵️ THREAT RESEARCH & DEEP DIVES

📋 VENDOR BULLETINS & ADVISORIES

  • CVE-2026-46459: Missing Authorization in ICU Scandinavia Boomerang — Critical auth bypass allows unauthenticated remote attackers to read full facility configurations. Immediate mitigation recommended for affected device endpoints.

  • CVE-2026-46458: Credential Exposure in ICU Scandinavia Boomerang — Sensitive credential files exposed via static HTTP, enabling unauthenticated remote retrieval. Urgent patching or network controls required to prevent credential compromise.

  • CVE-2026-15779: Samba pam_winbind mkhomedir Chown Critical System Paths — Vulnerability allows privilege escalation by changing ownership of critical system directories due to lack of path validation. High risk for Linux environments using pam_winbind with mkhomedir enabled.

  • CVE-2026-15809: CRI-O /etc/passwd Injection Bypass — Fix for CVE-2022-4318 was bypassable, allowing attackers with container environment control to inject into /etc/passwd, risking container breakout. Patch CRI-O installations immediately.

  • Multiple permission control and out-of-bounds read vulnerabilities (CVE-2026-58549 through CVE-2026-58559) affecting vibration services, Bluetooth, file system, settings, card modules, and image codec components have been disclosed. These impact confidentiality and availability and require review of vendor patches and mitigations.

📰 LESSER-KNOWN / UNDER-REPORTED

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check