- CVE-2026-86304 CRITICAL CVSS 9.8 -
NVD: MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. NVD: parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert, cert_text or anchors argument, then passes the returned XML to Net::SAML2::Protocol::Assertion->new_from_xml with the IdP signing certificate as cacert. NVD: In Net::SAML2 before 0.86 that certificate guards only encrypted assertions, so the signature on an unencrypted assertion is checked against the certificate the response itself carries.
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review; CVSS 9.8 (CRITICAL); EPSS percentile 13; sources: NVD.
- CVE-2026-16876 CRITICAL CVSS 9.3 -
NVD: An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. NVD: A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
This critical severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for authentication boundary review; CVSS 9.3 (CRITICAL); EPSS percentile 26; sources: NVD.
- CVE-2026-20501 HIGH CVSS 8.4 mediatek / mt2718_firmware
NVD: In vdec, there is a possible out of bounds write due to a heap buffer overflow. NVD: This could lead to local escalation of privilege with no additional execution privileges needed. NVD: User interaction is not needed for exploitation.
The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure; CVSS 8.4 (HIGH); EPSS percentile 3; affected product context: mediatek / mt2718_firmware; sources: NVD, Vendor Advisory.
- CVE-2026-20502 HIGH CVSS 8.4 mediatek / mt2718_firmware
NVD: In vdec, there is a possible out of bounds write due to a missing bounds check. NVD: This could lead to local escalation of privilege with no additional execution privileges needed. NVD: User interaction is not needed for exploitation.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for user interaction required; CVSS 8.4 (HIGH); EPSS percentile 3; affected product context: mediatek / mt2718_firmware; sources: NVD, Vendor Advisory.
- CVE-2026-20506 MEDIUM CVSS 6.7 -
NVD: In Audio HAL, there is a possible escalation of privilege due to use after free. NVD: This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. NVD: User interaction is not needed for exploitation.
The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure; CVSS 6.7 (MEDIUM); EPSS percentile 2; sources: NVD.
- CVE-2026-20508 MEDIUM CVSS 6.7 -
NVD: In Power HAL, there is a possible escalation of privilege due to type confusion. NVD: This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. NVD: User interaction is not needed for exploitation.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for user interaction required; CVSS 6.7 (MEDIUM); EPSS percentile 2; sources: NVD.
- CVE-2026-20507 MEDIUM CVSS 6.7 -
NVD: In Audio HAL, there is a possible escalation of privilege due to use after free. NVD: This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. NVD: User interaction is not needed for exploitation.
The affected component has memory-safety risk that may lead to crash, privilege, or code-execution impact depending on exposure; CVSS 6.7 (MEDIUM); EPSS percentile 2; sources: NVD.
- CVE-2026-86237 MEDIUM CVSS 5.5 -
NVD: A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. NVD: Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. NVD: Performing a manipulation of the argument base_url results in server-side request forgery.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.5 (MEDIUM); EPSS percentile 42; sources: NVD, OSV.
- CVE-2026-20500 MEDIUM CVSS 5.5 mediatek / mt2716_firmware
NVD: In Modem, there is a possible system crash due to improper input validation. NVD: This could lead to local denial of service with User execution privileges needed. NVD: User interaction is needed for exploitation.
The affected service may become unavailable or unreliable; CVSS 5.5 (MEDIUM); EPSS percentile 1; affected product context: mediatek / mt2716_firmware; sources: NVD, Vendor Advisory.
- CVE-2026-20503 MEDIUM CVSS 5.3 mediatek / mt2716_firmware
NVD: In Modem, there is a possible system crash due to a missing bounds check. NVD: This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. NVD: User interaction is not needed for exploitation.
The affected service may become unavailable or unreliable; CVSS 5.3 (MEDIUM); EPSS percentile 9; affected product context: mediatek / mt2716_firmware; sources: NVD, Vendor Advisory.
- CVE-2026-20504 MEDIUM CVSS 5.3 mediatek / mt2735_firmware
NVD: In Modem, there is a possible system crash due to a missing bounds check. NVD: This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. NVD: User interaction is not needed for exploitation.
The affected service may become unavailable or unreliable; CVSS 5.3 (MEDIUM); EPSS percentile 9; affected product context: mediatek / mt2735_firmware; sources: NVD, Vendor Advisory.
- CVE-2026-86231 LOW CVSS 2.9 -
NVD: A security flaw has been discovered in mwiede jsch up to 2.28.5. NVD: Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. NVD: Performing a manipulation of the argument known_hosts results in improper check for certificate revocation.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.9 (LOW); EPSS percentile 20; sources: NVD, OSV.
- CVE-2026-86238 LOW CVSS 2.1 -
NVD: A vulnerability was determined in projectworlds Online Examination System 1.0. NVD: The affected element is an unknown function of the file feedback.php of the component Feedback Form. NVD: Executing a manipulation of the argument Name/Subject can lead to cross site scripting.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 2.1 (LOW); EPSS percentile 36; sources: NVD.
- CVE-2026-86228 LOW CVSS 2.1 -
NVD: A security vulnerability has been detected in JeecgBoot up to 3.9.3. NVD: This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelController.java. NVD: Such manipulation of the argument credential leads to improper access controls.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 2.1 (LOW); EPSS percentile 13; sources: NVD, OSV.
- CVE-2026-86233 LOW CVSS 2.1 -
NVD: A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. NVD: Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. NVD: The manipulation of the argument ID leads to sql injection.
An attacker may be able to read or change database-backed application data; CVSS 2.1 (LOW); EPSS percentile 11; sources: NVD.
- CVE-2026-86234 LOW CVSS 2.1 -
NVD: A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. NVD: This affects an unknown part of the file /pages/cust_transac.php?action=add. NVD: The manipulation of the argument firstname results in sql injection.
An attacker may be able to read or change database-backed application data; CVSS 2.1 (LOW); EPSS percentile 11; sources: NVD.
- CVE-2026-86235 LOW CVSS 2.1 -
NVD: A flaw has been found in itsourcecode Sales and Inventory System 1.0. NVD: This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. NVD: This manipulation of the argument Customer causes sql injection.
An attacker may be able to read or change database-backed application data; CVSS 2.1 (LOW); EPSS percentile 11; sources: NVD.
- CVE-2026-86236 LOW CVSS 2.1 -
NVD: A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. NVD: This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. NVD: Such manipulation of the argument Name leads to sql injection.
An attacker may be able to read or change database-backed application data; CVSS 2.1 (LOW); EPSS percentile 10; sources: NVD.
- CVE-2026-86232 LOW CVSS 2.1 -
NVD: A weakness has been identified in itsourcecode Sales and Inventory System 1.0. NVD: Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. NVD: Executing a manipulation of the argument ID can lead to sql injection.
An attacker may be able to read or change database-backed application data; CVSS 2.1 (LOW); EPSS percentile 10; sources: NVD.
- CVE-2026-86227 LOW CVSS 1.3 -
NVD: A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. NVD: This affects the function kvstoreGetHashtable of the file src/kvstore.c. NVD: This manipulation of the argument didx causes out-of-bounds read.
The affected service may become unavailable or unreliable; CVSS 1.3 (LOW); EPSS percentile 25; sources: NVD, OSV.