| CVE-2026-86188 | AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary J | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- Low
SISubsequent System Integrity- Low
SASubsequent System Availability- None
| — |
| CVE-2026-86187 | WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integer | — | 2026-09-05 | CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- High
ATAttack Requirements- Present
PRPrivileges Required- High
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86186 | AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operatio | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- Present
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86185 | Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration wit | — | 2026-09-05 | CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Adjacent
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- Passive
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86184 | Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attack | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86178 | Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated user | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86177 | Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedu | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86176 | NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bo | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86175 | NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with o | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86174 | Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attacke | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86173 | MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86169 | Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None in | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- Passive
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86150 | A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Su | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- High
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- Low
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86149 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This m | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- High
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- High
SISubsequent System Integrity- High
SASubsequent System Availability- High
| — |
| CVE-2026-86148 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- High
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- High
SISubsequent System Integrity- High
SASubsequent System Availability- High
| — |
| CVE-2026-86145 | PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching works | — | 2026-09-05 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
AVAttack Vector- Network
ACAttack Complexity- Low
PRPrivileges Required- None
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- High
AAvailability- Low
| — |
| CVE-2026-86144 | In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-86143 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- Low
| — |
| CVE-2026-86142 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-86141 | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- None
IIntegrity- None
AAvailability- Low
| — |
| CVE-2026-86140 | In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow. | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-86139 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-86138 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- High
AAvailability- High
| — |
| CVE-2026-86137 | In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp. | Xmlsoft | 2026-09-05 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
AVAttack Vector- Local
ACAttack Complexity- Low
PRPrivileges Required- Low
UIUser Interaction- None
SScope- Unchanged
CConfidentiality- High
IIntegrity- None
AAvailability- Low
| — |
| CVE-2026-86124 | AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attack | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86123 | SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL qu | — | 2026-09-05 | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
AVAttack Vector- Network
ACAttack Complexity- High
ATAttack Requirements- Present
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- High
SISubsequent System Integrity- High
SASubsequent System Availability- None
| — |
| CVE-2026-86122 | Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- Low
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86121 | Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfa | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86120 | APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level acc | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86119 | Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asse | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- High
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86118 | gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- None
VAVulnerable System Availability- Low
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86117 | Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts | — | 2026-09-05 | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- High
ATAttack Requirements- Present
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86116 | Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- High
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86115 | Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation a | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- Low
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86114 | Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delet | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- High
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86113 | BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to mo | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- None
VIVulnerable System Integrity- High
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86112 | BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86111 | BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read f | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- None
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| — |
| CVE-2026-86100 | Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. | — | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- None
PRPrivileges Required- Low
UIUser Interaction- None
VCVulnerable System Confidentiality- Low
VIVulnerable System Integrity- Low
VAVulnerable System Availability- None
SCSubsequent System Confidentiality- Low
SISubsequent System Integrity- Low
SASubsequent System Availability- None
| — |
| CVE-2026-86060 | MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability | Mikrotik | 2026-09-05 | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
AVAttack Vector- Network
ACAttack Complexity- Low
ATAttack Requirements- Present
PRPrivileges Required- None
UIUser Interaction- None
VCVulnerable System Confidentiality- High
VIVulnerable System Integrity- High
VAVulnerable System Availability- High
SCSubsequent System Confidentiality- None
SISubsequent System Integrity- None
SASubsequent System Availability- None
| 2026-09-10 |