CVE-2026-58704
A logic error in the Google Pixel cellular modem component allows for unauthenticated, adjacent privilege escalation without user interaction.
Critical vulnerabilities, curated daily for security professionals
Apache Software Foundation products and Google Chrome account for the highest-impact disclosures, with remote code execution and authentication bypass flaws in widely deployed middleware and browser components. The day brought 32 critical CVEs (up 113% from 15 the prior day) and 109 high-priority CVEs (up 51% from 72), for 141 total. Named critical entries include CVE-2026-94301 (CVSS 9.8) in Apache MINA, CVE-2026-86473 (CVSS 9.1) in Apache Airflow, CVE-2026-89422 (CVSS 9.3) in Erlang OTP, and two Google Chrome flaws at CVSS 9.6 (CVE-2026-91710 and CVE-2026-93372). WordPress plugin vulnerabilities again make up a large share of the high-priority set, alongside container and observability tooling such as Fluent Bit (CVE-2026-61674, CVSS 9.2) and remote access gateways like warpgate (CVE-2026-58491, CVSS 9.3); seven CVEs carry confirmed active exploitation, including Cisco Identity Services Engine and Acronis Backup. Prioritise internet-facing network access control, backup infrastructure, and browser fleets, verify fix status in each vendor advisory, and restrict management interfaces on Apache middleware and remote access gateways until updates are confirmed applied.
Immediate action: Patch Cisco Identity Services Engine, Acronis Backup, and Zyxel GS1900-48HPv2 devices first given confirmed exploitation, then move to Apache MINA and Apache Airflow deployments and Chrome browser fleets. Confirm the fixed version and fix status for each affected product in the vendor's own advisory before scheduling maintenance windows, and restrict network access to Airflow web interfaces and warpgate gateways until updates are in place.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
A logic error in the Google Pixel cellular modem component allows for unauthenticated, adjacent privilege escalation without user interaction.
An authentication bypass vulnerability in the Cisco Identity Services Engine API allows unauthenticated, remote attackers to gain unauthorized access to the management interface.
Acronis Backup plugins for cPanel and Plesk contain an insecure file permissions vulnerability that allows authenticated users to perform local privilege escalation.
A race condition in the Linux kernel crypto subsystem allows local users to cause state inconsistencies via concurrent writes to an af_alg socket.
A memory corruption vulnerability in the Linux kernel netfilter bridge component allows for out of bounds writes during ARP packet processing.
A vulnerability in the Linux kernel TLS implementation allows for improper handling of zero-length records during recvmsg processing, potentially leading to unauthorized system state manipulation.
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware allows potential remote command execution.
The Give Tributes WordPress plugin is vulnerable to PHP Object Injection via deserialization of untrusted input, potentially allowing unauthenticated remote code execution.
Mailu deployments with specific proxy configurations allow unauthenticated remote attackers to spoof trusted proxy identities and bypass authentication via the X-Forwarded-By header.
A deserialization vulnerability exists in Apache MINA due to an incomplete patch for CVE-2026-47065, allowing unauthenticated attackers to bypass filter allow-lists via java.lang.reflect.Proxy.
A session invalidation flaw in the Apache Airflow Core API allows intercepted bearer tokens to remain active after a user logs out.
The Web to Print Online Designer WordPress plugin fails to validate uploaded file types and exposes upload tokens, allowing unauthenticated attackers to execute arbitrary PHP code on the server.
A critical authentication bypass in Erlang/OTP ssl allows unauthenticated attackers to impersonate TLS 1.3 servers by injecting an unoffered pre_shared_key extension during the handshake.
A stack-based buffer overflow in Fluent Bit allows unauthenticated remote attackers to achieve remote code execution via a maliciously crafted PONG response during the Secure Forward handshake.
A stored cross-site scripting (XSS) and open redirect vulnerability exists in Warpgate prior to 0.25.5 due to improper sanitization of the next parameter in SSO endpoints.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 19, analysis completed Sep 19.
A use after free vulnerability in Google Chrome WebAppInstalls allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A buffer overflow vulnerability in the WebGL component of Google Chrome on Android allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A use after free vulnerability in Google Chrome Extensions allows a remote attacker to execute arbitrary code outside the sandbox via a crafted extension.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A use after free vulnerability in the Dawn component of Google Chrome on Android allows a remote attacker to execute arbitrary code via a crafted HTML page.
An authorization flaw in Ajenti allows authenticated users to execute arbitrary commands as root via unvalidated plugin management tasks, leading to full system compromise.
MaxKB is vulnerable to OS command injection via improper neutralization of control characters in AWS credential fields, allowing authenticated users to execute arbitrary commands as root.
The Meta Box Frontend Submission plugin for WordPress contains an unauthenticated privilege escalation vulnerability via improper shortcode attribute validation, allowing attackers to gain administrator access.
An unauthenticated remote attacker can poison the Eclipse Open VSX metadata cache by injecting forged headers, leading users to install malicious extensions from attacker-controlled URLs.
Disclosed Sep 17 without a CVSS score; scored Sep 19, analysis completed Sep 19.
The wpShopGermany IT-RECHT KANZLEI plugin before 2.4 allows unauthenticated attackers to predict API tokens and perform remote code execution through improper authentication token generation.
OpenStack Octavia contains a code injection vulnerability allowing authenticated users to inject arbitrary HAProxy configuration directives via the tls_ciphers field.
Disclosed Sep 17 without a CVSS score; scored Sep 19, analysis completed Sep 19.
The Private Feed Key WordPress plugin fails to validate authentication keys, allowing unauthenticated attackers to impersonate any user, including administrators.
Disclosed Sep 17 without a CVSS score; scored Sep 19, analysis completed Sep 19.
The Pressengine WordPress plugin through version 1.0 contains an authentication flaw that allows unauthenticated attackers to bypass login protections and gain unauthorized administrative access.
Disclosed Sep 17 without a CVSS score; scored Sep 19, analysis completed Sep 19.
The Login with QR WordPress plugin fails to validate authentication tokens, allowing unauthenticated attackers to hijack user sessions, including those with administrative privileges.
VeloCloud Orchestrator (VCO) on-prem is vulnerable to improper input validation, allowing unauthenticated remote attackers to access privileged functionality and compromise the host.
An unauthenticated remote attacker can access the Gigatech PDV5701 WebSocket service to retrieve administrator credentials and sensitive device configuration data.
OpenStack Octavia fails to sanitize control characters in L7 policy fields, allowing authenticated project members to inject arbitrary HAProxy directives into the load balancer configuration.
Joplin Server prior to 3.7.2 lacks rate limiting on the SSO login endpoint, allowing unauthenticated attackers to brute-force authentication codes and gain unauthorized access to user accounts.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
The Linux kernel inetpeer subsystem uses deterministic Red-Black tree lookups, allowing unauthenticated remote attackers to predict tree topology and bypass ICMP rate limits via forced node eviction.
MaxKB contains an OS command injection vulnerability in SandboxShellBackend that allows unauthenticated attackers to achieve remote code execution via untrusted chat or ingested content.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A memory management flaw in the Linux kernel NFSv4.1 implementation allows uninitialized pointer usage, potentially leading to memory corruption during callback sequence decoding.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A use after free vulnerability exists in the Linux kernel NFSv4 implementation due to improper handling of callback IDR entries during failed client allocation.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A double-free vulnerability in the Linux kernel xfrm_dev_direct_output function allows for potential memory corruption or system instability.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 19, analysis completed Sep 19.
A remote code execution vulnerability in the biz_helper.exe component of Sogou Input Method allows unauthenticated attackers to execute arbitrary code.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 19, analysis completed Sep 19.
IBM Verify Identity Access containers fail to correctly apply management password updates, potentially leaving systems vulnerable to unauthorized access via improperly secured credentials.
A pre-authentication Remote Code Execution vulnerability in Ivanti EPMM allows unauthenticated attackers to execute arbitrary code via malicious HTTP requests handled by legacy bash scripts.
The Ninja Forms WordPress plugin contains a deserialization vulnerability that allows unauthenticated attackers to trigger PHP Object Injection during administrative CSV exports.
The HUSKY – Products Filter for WooCommerce Professional plugin is vulnerable to unauthenticated Local File Inclusion via the shortcode parameter, allowing arbitrary PHP code execution.
A missing authorization check in Warpgate allows authenticated regular users to view sensitive real time session data, including credentials, from other users and administrators.
A resource exhaustion vulnerability in the nginx-ignition gin i18n middleware allows unauthenticated attackers to cause high CPU usage via malformed Accept-Language headers.
A path traversal vulnerability in Conda allows malicious packages to write files outside of the intended directory or overwrite existing entry points during installation.
The WP Travel Engine plugin for WordPress is vulnerable to Local File Inclusion via the wte_get_template function, allowing authenticated contributors to execute arbitrary PHP code.
Chartbrew versions prior to 5.2.3 are vulnerable to SQL injection via the ClickHouse protocol, allowing unauthenticated attackers to execute arbitrary SQL queries on connected databases.
A server-side request forgery vulnerability in drawio allows unauthenticated attackers to access internal IPv6 resources and disclose sensitive cloud metadata or internal service data.
A Go runtime panic in temporalio/sqlparser allows authenticated users to trigger a denial of service by submitting malformed MySQL version comments.
A failure to validate TChannel call fragments allows unauthenticated remote attackers to trigger a process crash via a malformed request, leading to a denial of service.
A flaw in pki-core causes incorrect authorization by misprioritizing wildcard ACL keys, allowing lower-privileged users to bypass intended permission requirements in the REST API.
vLLM contains a denial of service vulnerability in P2P KV offloading where attackers can supply arbitrary host and port values to trigger uncaught ZMQ errors that crash the inference engine.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 18, analysis completed Sep 22.
A missing permission check in the Android Setup Wizard allows for remote package installation and escalation of privilege without user interaction.
KubeEdge is vulnerable to path traversal in the DecompressTarGz function, allowing attackers to overwrite arbitrary files on Windows edge nodes during component installation or joining.
A Time-of-Check Time-of-Use (TOCTOU) race condition in BleachBit prior to 6.0.1 allows local unprivileged users to perform arbitrary file deletion and achieve local SYSTEM privilege escalation.
vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling, allowing unauthenticated attackers to crash the decode engine.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 18, analysis completed Sep 22.
A type confusion vulnerability in the Android kernel allows for local escalation of privilege without requiring user interaction or additional execution privileges.
An authorization bypass in ntopng allows authenticated non-admin users to download system backups, exposing sensitive credential data including password hashes, API tokens, and TOTP secrets.
Disclosed Sep 15 without a CVSS score; tracked by CVE Brief from Sep 16; scored Sep 18, analysis completed Sep 22.
A logic error in the Android Bootloader allows for a permission bypass, enabling local escalation of privilege to system execution levels without user interaction.
Tinyauth incorrectly handles hostname case sensitivity, allowing authenticated users to bypass per-app access controls by using differently cased hostnames that reverse proxies treat as equivalent.
An unauthenticated race condition in the nginx-ignition onboarding API allows remote attackers to create unauthorized administrator accounts.
The Ninja Forms WordPress plugin contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to execute malicious scripts in the browser of an administrator.
The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution due to improper input validation, allowing authenticated attackers to execute unauthorized shortcodes.
A vulnerability in CRI-O checkpoint restore allows authenticated users to bypass Kubernetes security contexts, potentially resulting in container processes retaining unauthorized elevated privileges.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Report Manager component of Oracle E-Business Suite allows low-privileged attackers to achieve a full system takeover via network-based HTTP requests.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Spares Management component of Oracle E-Business Suite allows a low privileged attacker to achieve full system takeover via HTTP.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Spares Management component of E-Business Suite allows a low privileged attacker to achieve a full system takeover via network access.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Siebel CRM Deployment server infrastructure allows a low privileged, network-based attacker to achieve a full system takeover.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A critical vulnerability in the Oracle Application Object Library allows a low privileged attacker to achieve a full system takeover via the Attachments and File Upload component.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Oracle Depot Repair component of Oracle E-Business Suite allows a low privileged, network-based attacker to achieve a full system takeover.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A vulnerability in the Personalization component of Oracle Applications Framework allows low privileged attackers to achieve full system takeover via network access.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A SQL injection vulnerability in the Oracle Siebel CRM Deployment Migration component allows a low privileged attacker to achieve full system takeover.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A high severity vulnerability in the Oracle Siebel CRM Workflow component allows an authenticated low privileged attacker to achieve full system takeover via network access.
Disclosed Sep 16; published with a limited analysis after repeated re-checks found no further public detail.
A SQL injection vulnerability in the Oracle Siebel CRM Deployment server infrastructure allows low-privileged attackers to achieve a full system takeover.
An inefficient algorithmic complexity flaw in the Erlang/OTP ASN.1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to trigger a denial of service via a crafted OID in a TLS handshake.
Dell Command | Monitor (DCM) contains an incorrect permission assignment vulnerability that allows a low privileged local attacker to achieve elevation of privileges.
A missing authorization check in ntopng allows authenticated users to manipulate threat intelligence blocklists and download sources via the edit_blacklist.lua script.
A path traversal vulnerability in CRI-O container checkpoint and restore features allows privileged users to perform unintended host filesystem operations.
Dell Inventory Collector Client versions prior to 15.0.0 are vulnerable to an unquoted search path flaw, which may allow low privileged local attackers to achieve code execution and privilege escalation.
Dell Command Powershell Provider (DCPP) versions prior to 2.10.2 contain an insertion of sensitive information into log files, allowing local attackers to potentially access sensitive data.
A stored cross-site scripting vulnerability in GoCD allows authenticated attackers with commit access to execute malicious scripts via unescaped tracking-tool links in commit comments.
Apache Neethi is susceptible to a denial of service vulnerability where deeply nested WS-Policy documents can exhaust the thread stack and crash the parser.
A heap exhaustion vulnerability in Apache Neethi allows unauthenticated remote attackers to cause a denial of service by sending specially crafted WS-Policy documents.
Apache Neethi is vulnerable to a denial of service attack where malicious WS-Policy documents trigger exponential resource consumption during normalization.
Apache Neethi is vulnerable to a denial of service attack where crafted WS-Policy documents trigger exponential CPU consumption during policy intersection.
FalkorDB contains a buffer overflow in the _Decode_GrB_Matrix function, which can be triggered by a crafted input to cause a Denial of Service.
Disclosed Sep 16 without a CVSS score; scored Sep 18, analysis completed Sep 22.
LearnPress WordPress plugin fails to escape user input in HTML attributes, enabling unauthenticated reflected XSS attacks on sites using classic themes.
Envoy is vulnerable to a memory exhaustion attack where unauthenticated users can bypass header limits via HTTP/2 HPACK, causing the process to crash due to out of memory errors.
OpenBao templated policies fail to sanitize identity data, allowing attackers with high privileges to manipulate ACL, PKI, and SSH policy outcomes through injected syntax characters.
Temporal Server contains an OS command injection vulnerability in the Worker Service, allowing authenticated users with write access to execute arbitrary commands on the host machine.
A stack-based buffer overflow in fetchmail's NTLM authentication allows a malicious mail server to potentially trigger remote code execution via a crafted Type 2 challenge.
A command injection vulnerability in mcp-for-stata allows unauthenticated attackers to execute arbitrary OS commands via the ado_package_install tool.
A command injection vulnerability in the OpenWrt LuCI advanced reboot application allows authenticated users to execute arbitrary commands as root via improper ACL configuration.
MISP contains a privilege management flaw where a read-only API key can be escalated to full account permissions, allowing unauthorized write, delete, or administrative actions.
An improper array index validation in Temporal tchannel-go allows unauthenticated remote attackers to cause a process-terminating panic, resulting in a denial of service.
The MISP blocklist workflow module fails to validate file extensions, allowing an authenticated administrator to upload files with dangerous extensions that may lead to arbitrary code execution.
Sync-in Server before 2.4.0 allows authenticated users to bypass TOTP two-factor authentication via the /api/auth/token endpoint, granting unauthorized access to JWTs.
FalkorDB versions 4.20.1 through 4.20.4 contain a stack overflow vulnerability in the _ValidateUnion_Clauses function that allows remote, unauthenticated attackers to cause a Denial of Service.
A vulnerability in the FalkorDB Redis module allows unauthenticated attackers to trigger a denial of service through an out-of-bounds read error.
Improper error handling in the GRAPH.EFFECT component of FalkorDB v4.20.1 allows unauthenticated attackers to trigger a Denial of Service.
A heap-based buffer overflow exists in the mtdispkm64.sys library of the Moore Threads MTT S80 driver, potentially allowing local code execution.
jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint, allowing authenticated users to grant themselves unauthorized roles.
Envoy contains an interpretation conflict vulnerability where inconsistent path canonicalization allows unauthenticated clients to bypass RBAC path-based authorization rules.
Envoy contains a use-after-free vulnerability in the HttpDatagramHandler when Capsule Protocol is enabled, potentially leading to a process crash via HTTP/3 datagrams.
An unauthenticated null pointer dereference vulnerability in Envoy's ext_authz filter allows remote attackers to crash the proxy process via specifically crafted path-less CONNECT requests.
A use-after-free vulnerability in the Envoy oghttp2 codec allows unauthenticated remote attackers to trigger a process crash by sending malformed HTTP/2 response trailer headers.
Envoy HTTP RBAC policies may fail to correctly enforce access controls due to improper regex evaluation of RFC-valid header bytes, potentially allowing unauthorized access to restricted routes.
A CRLF injection vulnerability in OpenWrt luci-app-adblock-fast allows authenticated users to achieve persistent command execution as root via the setCronEntry RPC method.
The Zapros Python HTTP client is vulnerable to a denial of service attack via memory exhaustion when processing compressed responses due to inadequate chunk size enforcement.
A local privilege escalation flaw in the CUPS serial backend allows authenticated users with lpadmin privileges to gain root code execution by manipulating arbitrary files via malicious device URIs.
HomeBox version 0.26.0 addresses an authorization bypass vulnerability allowing authenticated users to read or modify another tenant's notifier credentials and notification webhooks.
A heap-based buffer overflow in libX11 before 1.8.14 allows a malicious X server to trigger memory corruption via the XkbGetMap function.
A heap-based buffer overflow in libXrender allows malicious X servers to execute arbitrary code within the context of attached X clients.
An improper privilege management vulnerability exists in the mtdispkm64.sys library of the Moore Threads MTT S80 driver, requiring local access to exploit.
ColorFul iGameCenter version 1.0.3.4 contains an untrusted pointer dereference vulnerability in the ene.sys library IOCTL handler, potentially allowing local code execution.
jshERP versions 3.6 and earlier contain an authorization bypass vulnerability in the user password reset endpoint, allowing authenticated users to reset the passwords of other users.
jshERP contains an authorization bypass vulnerability in userBusiness CRUD endpoints, allowing authenticated users to modify or delete authorization relations without proper privilege validation.
KubeEdge contains an OS command injection vulnerability in ConfigUpdateJob, allowing an authenticated user to execute arbitrary commands on edge nodes with elevated privileges.
A missing authorization flaw in deepstream.io allows authenticated users to perform unauthorized record modifications via the PATCH_MULTI operation.
A command injection vulnerability in ntopng allows authenticated users or unauthenticated attackers via CSRF to execute arbitrary OS commands by manipulating the scan_ports parameter.
Tuleap Enterprise Edition is vulnerable to OS Command Injection in versions 17.3 through 17.5, potentially allowing authenticated attackers to execute arbitrary system commands.
A recursion depth vulnerability in the sqlparser library allows attackers to trigger a process-terminating stack overflow via deeply nested SQL expressions in Temporal Server.
Temporal ringpop-go fails to enforce label limits on SWIM membership changes, allowing unauthenticated remote attackers to trigger resource exhaustion and cause service unavailability.
jshERP fails to perform authorization checks on role management endpoints, allowing authenticated users to modify data scopes or delete roles.
jshERP versions 3.6 and earlier suffer from an insecure direct object reference vulnerability, allowing authenticated users to access and modify business objects belonging to other users.
MISP contains a file-handling vulnerability where authenticated users with modify permissions can perform Server-Side Request Forgery or read arbitrary local server files via malicious XML imports.
MISP is vulnerable to an insecure direct object reference in the Event model, allowing authenticated users to read or modify arbitrary event reports by manipulating the report ID field.
A stored cross-site scripting (XSS) vulnerability in the Telegram Desktop HTML exporter allows attackers to execute arbitrary JavaScript when a victim opens a maliciously crafted exported chat file.
A memory safety vulnerability in the Zephyr RTOS Time-aware GPIO syscall handler allows an authenticated local user to perform arbitrary kernel memory writes, potentially leading to privilege escalation.
DesktopSMS Lite for Android contains a local pairing authorization bypass that allows unprivileged applications to send SMS and access sensitive message content without user interaction.
Joplin fails to sanitize HTML generated by the Fountain renderer, allowing an attacker to execute arbitrary scripts in the context of the note viewer or published server pages.
HomeBox prior to 0.26.0 contains an authorization bypass vulnerability allowing authenticated users to delete the inventory of other groups by manipulating the X-Tenant header.
Joplin Server is vulnerable to Stored Cross-site Scripting (XSS) due to improper handling of MIME types and missing Content-Disposition headers for shared resources with empty titles.
A denial of service vulnerability in the vLLM NIXL connector allows remote attackers to crash decode workers by submitting multi-prompt requests that trigger an assertion failure in prefix caching.
vLLM versions 0.29.0 and earlier fail to validate the tp_size parameter in kv_transfer_params, allowing unauthenticated attackers to cause memory exhaustion and crash the decode worker process.
The vLLM Mooncake connector fails to manage GPU KV cache block ownership, allowing attackers to trigger GPU memory exhaustion and prevent legitimate request execution.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A missing return value check in the Linux kernel GIC-v5 driver allows for out of bounds memory access during MADT IAFFID parsing, potentially leading to system instability or compromise.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A vulnerability in the Linux kernel AppArmor subsystem allows a local user to bypass namespace restrictions, potentially leading to a sandbox escape through improper transition handling.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A flaw in the Linux kernel arm64 ptrace implementation allows a tracer to bypass seccomp or audit checks by failing to synchronize the orig_x0 register when the first syscall argument is modified.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A flaw in the Linux kernel IOMMU driver allows a use-after-free condition during PCI device probe failures, potentially leading to memory corruption or system instability.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A race condition in the Linux kernel PCI subsystem allows potential data misrouting or loss due to improper flushing of cached MSI writes before unmapping the iATU.
Disclosed Sep 17 without a CVSS score; tracked by CVE Brief from Sep 18; scored Sep 19, analysis completed Sep 19.
A flaw in the Linux kernel RDMA/rxe component causes a packet processing loop when a queue pair enters an error state, potentially leading to denial of service or data integrity issues.
Envoy Proxy is susceptible to an HTTP request smuggling vulnerability where an unauthenticated client can cause the proxy to misroute responses between different downstream clients.
An authorization flaw in Feast CI workflows allows attackers to execute arbitrary code and steal cloud credentials by manipulating pull request labels and triggering privileged make targets.
KubeEdge contains an OS command injection vulnerability in the NodeUpgradeJob handler, allowing authenticated users to execute arbitrary commands on edge nodes with elevated privileges.
The ansible_jailexec connection plugin for FreeBSD Jails fails to properly resolve symbolic links, allowing an attacker to escape the jail and achieve arbitrary root-privileged writes on the host.
HomeBox allows authenticated low-privileged users to overwrite or delete maintenance entries belonging to other tenants due to a missing authorization check on object UUIDs.
Disclosed Sep 16 without a CVSS score; tracked by CVE Brief from Sep 17; scored Sep 19, analysis completed Sep 19.
Howyar Technologies Inc SysReturn versions prior to 11.3.034 contain a vulnerability allowing local attackers to execute arbitrary code via a crafted cloak32.dat file on the EFI System Partition.