CVE-2026-62800 — Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
Security intelligence for your infrastructure.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms
— track vulnerabilities, critical patches and release news on a single screen. Stay a step ahead with verified, prioritised and actionable intelligence.
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network.
Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines the ORG_ADMIN permission on the ROOT org. This issue results from the Velociraptor server allowing for the deletion of Orgs by incorrectly checking the ORG_ADMIN permission of callers within the calli
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal filename through entry.name. In tabby-ssh/src/session/sftp.ts, SFTPSession.readdir() and _makeFile() use POSIX path processing that preserves the backslashes as ordinary filename characters. In tabby-ssh/src/components/sftpPanel.component.ts, downloadFolderRecursive() propagates item.name into the local relative path. In tabby-electr
An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.
Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
A vulnerability allowing remote unauthenticated code execution on the agent host.
A vulnerability allowing local privilege escalation to the Reporter service context.
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.
Google patched a high-severity privilege escalation vulnerability in the Pixel Cellular Modem tracked as CVE-2026-58704. NIST records indicate the iss...
Leaked credentials or published vulnerability notices can be turned into attacks before defenders finish triage; attackers are shortening the time fro...
Acronis reported that CVE-2026-87886 (CVSS 7.8), a local privilege escalation rooted in insecure file permissions in the Acronis Backup plugin for cPa...
Vulnerabilities and release notes for the platforms you follow, in one email every morning. You choose which platforms to track, and you can leave at any time.
Already subscribed? Manage your preferences