- CVE-2026-69843 CRITICAL CVSS 10.0 -
NVD: Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review; CVSS 10.0 (CRITICAL); EPSS percentile 59; sources: NVD.
- CVE-2026-62874 CRITICAL CVSS 10.0 -
NVD: Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 10.0 (CRITICAL); EPSS percentile 34; sources: NVD.
- CVE-2026-85878 CRITICAL CVSS 9.9 -
NVD: Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for critical severity review; CVSS 9.9 (CRITICAL); EPSS percentile 55; sources: NVD.
- CVE-2026-93450 HIGH CVSS 8.7 -
NVD: go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. NVD: Remote unauthenticated attackers can submit deeply nested JSON documents to services accepting OpenAPI specifications, causing fatal stack overflow that terminates the process and all in-flight requests. OSV: go-openapi/swag jsonutils before 0.27.1 Uncontrolled Recursion in Ordered JSON Marshal and Unmarshal
The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure; CVSS 8.7 (HIGH); EPSS percentile 58; sources: NVD, OSV.
- CVE-2026-93452 HIGH CVSS 8.7 -
NVD: snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. NVD: Attackers can supply incompressible data that exceeds the destination buffer's remaining capacity, corrupting off-heap memory and causing JVM termination. OSV: snappy-java through 1.1.10.8 Buffer Overflow in Snappy.compress
The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure; CVSS 8.7 (HIGH); EPSS percentile 50; sources: NVD, OSV.
- CVE-2026-79954 HIGH CVSS 8.7 -
NVD: NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. NVD: The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but it does not verify that the selected SA is authorized for the frame's GVCID. OSV: NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 8.7 (HIGH); EPSS percentile 44; sources: NVD, OSV.
- CVE-2026-93453 HIGH CVSS 8.7 -
NVD: SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. NVD: Attackers can submit password recovery requests with a malicious Origin header to have valid password-reset tokens mailed to victim recovery addresses within links pointing to attacker infrastructure, enabling account takeover. OSV: SOGo before 5.12.11 Password Reset Token Interception via Origin Header
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 8.7 (HIGH); EPSS percentile 40; sources: NVD, OSV.
- CVE-2026-83946 HIGH CVSS 8.2 -
NVD: Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 8.2 (HIGH); EPSS percentile 44; sources: NVD.
- CVE-2026-85887 HIGH CVSS 7.7 -
NVD: Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for high severity review; CVSS 7.7 (HIGH); EPSS percentile 57; sources: NVD.
- CVE-2026-93451 MEDIUM CVSS 6.9 -
NVD: snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. NVD: Attackers controlling compressed input can cause misaligned length values to write past array bounds with attacker-controlled bytes, corrupting heap memory. OSV: snappy-java through 1.1.10.8 Buffer Overflow via typed uncompress methods
The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure; CVSS 6.9 (MEDIUM); EPSS percentile 40; sources: NVD, OSV.
- CVE-2026-2585 MEDIUM CVSS 6.4 -
NVD: The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output escaping. NVD: This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary; CVSS 6.4 (MEDIUM); EPSS percentile 16; sources: NVD.
- CVE-2026-77164 MEDIUM CVSS 6.2 -
NVD: Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF protections. NVD: The public, unauthenticated endpoints POST /apps/circles/event/ and POST /apps/circles/incoming/ reach this code path, allowing any unauthenticated user to force the server to issue a GET request to an internal address. NVD: The response body of the internal request is never returned to the requester, so this is blind SSRF: an attacker can determine whether an internal service is reachable, but cannot read its response contents through this endpoint alone.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authenticated boundary; CVSS 6.2 (MEDIUM); EPSS percentile 8; sources: NVD.
- CVE-2026-93310 MEDIUM CVSS 5.5 -
NVD: A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. NVD: This affects an unknown part of the component VES Collector. NVD: The manipulation leads to allocation of resources.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 51; sources: NVD.
- CVE-2026-93454 MEDIUM CVSS 5.1 -
NVD: Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. NVD: Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record. OSV: Aureus ERP through 1.6.0 Stored XSS via Payment Term Note
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk · authenticated boundary; CVSS 5.1 (MEDIUM); EPSS percentile 20; sources: NVD, OSV.
- CVE-2026-18441 MEDIUM CVSS 4.3 -
NVD: The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missing validation on a user... NVD: This makes it possible for unauthenticated attackers to enumerate arbitrary customer records and disclose personally identifiable information - including first name, last name, email address, and phone number - by iterating the customer[id] parameter. NVD: This issue is exploitable only when the site is configured with customer authentication disabled (guest checkout enabled).
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 4.3 (MEDIUM); EPSS percentile 14; sources: NVD.
- CVE-2026-68493 LOW CVSS 3.1 -
NVD: After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 3.1 (LOW); EPSS percentile 12; sources: NVD.
- CVE-2026-93312 LOW CVSS 2.1 -
NVD: A flaw has been found in Freedesktop Poppler 26.07.0. NVD: Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. NVD: This manipulation causes null pointer dereference.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.1 (LOW); EPSS percentile 46; sources: NVD, OSV.
- CVE-2026-93311 LOW CVSS 2.1 -
NVD: A vulnerability was detected in Freedesktop Poppler 26.07.0. NVD: This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. NVD: The manipulation of the argument BitsPerSample results in integer overflow.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.1 (LOW); EPSS percentile 44; sources: NVD.
- CVE-2026-93308 LOW CVSS 2.1 -
NVD: A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. NVD: Affected by this vulnerability is an unknown functionality of the component VES Collector. NVD: Performing a manipulation results in allocation of resources.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.1 (LOW); EPSS percentile 42; sources: NVD.
- CVE-2026-93309 LOW CVSS 2.1 -
NVD: A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. NVD: Affected by this issue is some unknown functionality of the component VES Collector. NVD: Executing a manipulation can lead to allocation of resources.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.1 (LOW); EPSS percentile 42; sources: NVD.