π VULNERABILITIES & CVEs
-
Quicly Connection State Corruption β CVE-2026-44436
Multiple denial-of-service vulnerabilities identified in Quicly (IETF QUIC protocol implementation used in H2O HTTP server). Prior to commit 8b178e6, attackers can cause connection state corruption leading to service disruption. -
Quicly Remote DoS via Assertion Failure β CVE-2026-44435
Assertion failure triggered by malformed CRYPTO stream handshake frames in Quicly versions before commit 937d0e9 causes remote denial of service. -
Quicly Stateless Reset Injection β CVE-2026-44434
Stateless reset injection vulnerability due to lack of packet validation in Quicly prior to commit dccf5d4 allows attackers to disrupt connections. -
Quicly Memory Exhaustion β CVE-2026-44433
Memory exhaustion denial of service possible by sending minimal STREAM frames in Quicly versions before commit 8b178e6. -
Bouncy Castle ARM SHA3/SHAKE Out-of-Bounds Write β CVE-2026-15997
Out-of-bounds write in Legion of the Bouncy Castle bcprov-lts8on on ARM platforms due torestoreFullStateunderflow detection failure. -
wger IDOR Allows Access to Private Workout Data β CVE-2026-43977
Authenticated users in wger fitness manager (pre-2.6) can read other usersβ private workout notes and history. -
wger Privilege Escalation via Session Chaining β CVE-2026-43978
Gym trainers can escalate privileges to manager roles by chaining trainer-login sessions in wger versions before 2.6. -
Jupyter Enterprise Gateway Kubernetes Manifest Injection β CVE-2026-44182
Pre-3.3.0 versions interpolate untrusted input in Jinja2 templates, enabling Kubernetes manifest injection and potential remote code execution. -
Jupyter Enterprise Gateway SSTI via Jinja2 Templates β CVE-2026-44181
Server-side template injection vulnerability in Jupyter Enterprise Gateway (2.0.0rc2 to pre-3.3.0) allows remote code execution. -
Jupyter Enterprise Gateway ContainerProcessProxy Privilege Bypass β CVE-2026-44180
Improper enforcement of prohibited user IDs in Jupyter Enterprise Gateway versions before 3.3.0 can lead to privilege bypass. -
Microsoft SharePoint Server Spoofing (XSS) β CVE-2026-62826
Authorized attackers can exploit input neutralization flaws during web page generation to perform spoofing attacks over the network. -
Windows Backup Service Privilege Escalation (Race Condition) β CVE-2026-58598
Local privilege escalation via race condition in Windows Backup Engine due to improper synchronization of shared resources. -
Windows Admin Center Cross-Site Scripting (XSS) β CVE-2026-58643
Unauthenticated attackers can perform network spoofing via input neutralization flaws in Windows Admin Center web pages. -
Windows Terminal Remote Code Execution β CVE-2026-59117
Integer overflow vulnerability in Windows Terminal allows remote code execution by unauthenticated attackers. -
Kirby CMS XSS via KirbyTags and Image Blocks β CVE-2026-45368
Versions prior to 4.9.1 and 5.4.1 fail to sanitize URLs in KirbyTags and image blocks, enabling stored cross-site scripting attacks. -
Kirby CMS Content Lock Info Disclosure β CVE-2026-45334
Content-locking feature leaks IDs and emails of inaccessible users due to missing access checks in Kirby CMS before 4.9.1 and 5.4.1. -
Kirby CMS XSS via List Field Content β CVE-2026-44175
Unsanitized list field content in Kirby CMS allows stored cross-site scripting in versions before 4.9.1 and 5.4.1. -
YAML::Syck Perl Out-of-Bounds Read β CVE-2026-57077
Versions before 1.47 allow out-of-bounds read via unbounded newline scan in bundled libsyck, risking memory disclosure. -
YAML::Syck Perl Heap Use-After-Free β CVE-2026-57076
Heap use-after-free triggered by anchor name reuse in YAML::Syck versions prior to 1.47, leading to potential memory corruption. -
YAML::Syck Perl Out-of-Bounds Read via Base64 Decoder β CVE-2026-57075
Signed-char lookup table index flaw in base64 decoder causes out-of-bounds read in YAML::Syck before 1.47.
π΅οΈ THREAT RESEARCH & DEEP DIVES
- Agentic AI Is Untamable: Ask the Right Security Questions
Emerging agentic AI systems introduce novel security risks that go beyond traditional attacker models, requiring a fundamental rethinking of organizational security strategies to address autonomous AI-driven threats.