THREAT OPS › Threat News
Threat Intelligence News
11626 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-82552 (MEDIUM 4.3) — A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the component gNB Termination Handler. The manipulation leads to denial of service. The attack is possible tnvd · 2026-08-30
- [NVD] CVE-2026-82551 (MEDIUM 5.3) — A weakness has been identified in Linux Foundation Magma 1.9.0. Affected is an unknown function of the file ngap_amf_handlers.c of the component NGSetup Handler. Executing a manipulation can lead to state issue. The attack can be executed remotely. The exploit has been made availnvd · 2026-08-30
- [NVD] CVE-2026-82550 (MEDIUM 5.3) — A security flaw has been discovered in Linux Foundation Magma 1.9.0. This impacts an unknown function of the component NGSetupRequest Handler. Performing a manipulation of the argument NG-IoT-DefaultPagingDRX results in improper input validation. Remote exploitation of the attacknvd · 2026-08-30
- [NVD] CVE-2026-82549 (HIGH 8.3) — A vulnerability was identified in Linux Foundation Magma 1.9.0. This affects an unknown function of the component SecurityModeComplete Handler. Such manipulation leads to improper validation of integrity check value. The attack may be launched remotely. The exploit is publicly avnvd · 2026-08-30
- [NVD] CVE-2026-78699 — Unchecked Return Value vulnerability in ash-project ash_postgres allows a user who can drive a tenant rename to a name that collides with an existing tenant's schema to have their tenant record repointed at that other tenant's live schema, gaining access to its data. AshPostgresnvd · 2026-08-30
- [qilin] AFSARD posted to leak siteransomware_live · 2026-08-30
- [Security Blog] Mid-Year Review: HKCERT Security Incident Statistics and Cybersecurity Trends in the First Half of 2026hkcert · 2026-08-30
- [Wallstreet] Andover posted to leak siteransomware_live · 2026-08-30
- [NVD] CVE-2026-82658 (MEDIUM 4.3) — Admidio versions before 5.0.12 contain a broken access control vulnerability in profile_function.php that allows authenticated low-privilege users to read another user's future role memberships. Attackers can bypass profile-level authorization by directly calling the reload_futurnvd · 2026-08-30
- [NVD] CVE-2026-82657 (HIGH 7.5) — Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/announcements.php, disclosing titnvd · 2026-08-30
- [NVD] CVE-2026-82656 (LOW 2.6) — Admidio before 5.0.12 fails to sanitize album names in the photo ZIP download functionality, allowing authenticated users with album-creation rights to include path traversal segments in archive entry names. Attackers can craft malicious album names containing directory traversalnvd · 2026-08-30
- [NVD] CVE-2026-82655 (HIGH 7.5) — Admidio before 5.0.12 contains a blind SQL injection vulnerability in the relation_type_list parameter of lists_show.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can bypass authentication by providing a dummy UUID in role_list and inject Snvd · 2026-08-30
- [NVD] CVE-2026-82654 (HIGH 8.9) — SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that blocknvd · 2026-08-30
- [NVD] CVE-2026-82653 (HIGH 8.9) — SiYuan before v3.8.1 contains a stored cross-site scripting vulnerability in confirmDialog() where unescaped package names and notebook names are interpolated directly into innerHTML assignments. Attackers can submit malicious bazaar packages with HTML/script payloads in the namenvd · 2026-08-30
- [NVD] CVE-2026-82652 (MEDIUM 5.3) — SiYuan before v3.8.1 fails to filter invisible-tier content from SQL embed blocks, attribute-view keys, and attribute-view backlinks in publish mode. Anonymous readers can enumerate invisible content through these three listing mechanisms despite admin configuration marking contenvd · 2026-08-30
- [NVD] CVE-2026-82651 (MEDIUM 4.9) — SiYuan before v3.8.1 does not apply the IsForbiddenAbsPath guard (introduced in GHSA-c8r8-95hg-mp34) to the /history/*path and /repo/diff/*path endpoints in kernel/server/serve.go. These routes require admin authentication but construct file paths independently, so an authenticatnvd · 2026-08-30
- [NVD] CVE-2026-82650 (MEDIUM 4.4) — SiYuan 3.8.0 contains a path traversal / sensitive file exposure vulnerability in the RenderTemplate function (kernel/model/template.go), reachable via the POST /api/template/render endpoint (kernel/api/template.go). The endpoint restricts the supplied path only to the workspace nvd · 2026-08-30
- [NVD] CVE-2026-82649 — SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolvesnvd · 2026-08-30
- [NVD] CVE-2026-82648 (HIGH 7.1) — WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fenvd · 2026-08-30
- [NVD] CVE-2026-82647 (MEDIUM 6.1) — WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can craft a malicious web page that, when visitnvd · 2026-08-30
- [NVD] CVE-2026-82646 (MEDIUM 6.1) — WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML metacharacters. Attackers can mint an encrypted evideo payload containing unescapenvd · 2026-08-30
- [NVD] CVE-2026-82645 (HIGH 8.6) — AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the envd · 2026-08-30
- [NVD] CVE-2026-82644 (HIGH 7.5) — WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlobal) that silently discards writesnvd · 2026-08-30
- [NVD] CVE-2026-82643 (MEDIUM 6.5) — WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit correct credentials repeatedly to trigger uncapped two-factor confirmation emails andnvd · 2026-08-30
- [NVD] CVE-2026-82548 (MEDIUM 5.3) — A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed annvd · 2026-08-30
- [NVD] CVE-2026-82547 (MEDIUM 6.5) — A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The manipulation results in improper authentication. The attack can be launched remotelnvd · 2026-08-30
- [NVD] CVE-2026-82545 (MEDIUM 6.3) — A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed tonvd · 2026-08-30
- [direwolf] THQ Nordic posted to leak siteransomware_live · 2026-08-30
- [direwolf] Erdem Hospital posted to leak siteransomware_live · 2026-08-30
- [direwolf] Hospital Clnico Universidad de Chile posted to leak siteransomware_live · 2026-08-30
- [Falcon] Globus Medical posted to leak siteransomware_live · 2026-08-30
- [Falcon] DistributionNOW (DNOW Inc.) posted to leak siteransomware_live · 2026-08-30
- [NVD] CVE-2026-82642 (HIGH 8.8) — Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the <script> tag (FORBID_TAGS: ['script']) in apps/readest-app/src/services/transformers/sanitizer.ts. DOMPunvd · 2026-08-30
- [NVD] CVE-2026-82641 (HIGH 8.6) — keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog lines and decrypt nvd · 2026-08-30
- [NVD] CVE-2026-82640 (MEDIUM 5.5) — browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.nvd · 2026-08-30
- [NVD] CVE-2026-82639 (HIGH 7.5) — NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any Unvd · 2026-08-30
- [NVD] CVE-2026-82638 (HIGH 7.5) — jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal snvd · 2026-08-30
- [NVD] CVE-2026-82637 (MEDIUM 5.3) — browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or save_downloanvd · 2026-08-30
- [NVD] CVE-2026-82636 (HIGH 7.9) — Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in core-admin-nvd · 2026-08-30
- [NVD] CVE-2026-82544 (MEDIUM 4.3) — A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attanvd · 2026-08-30
- [qilin] Crystalpharmatech posted to leak siteransomware_live · 2026-08-30
- [qilin] Absolute Consultancy Services posted to leak siteransomware_live · 2026-08-30
- [qilin] Black Cat Engineering Construction Wll posted to leak siteransomware_live · 2026-08-30
- [NVD] CVE-2026-82635 (HIGH 8.8) — Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolvesnvd · 2026-08-30
- [NVD] CVE-2026-82634 (MEDIUM 6.5) — Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template strings. Attackers with print permission on any document can execute arbitrary SEnvd · 2026-08-30
- [NVD] CVE-2026-82633 (MEDIUM 4.3) — Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers tnvd · 2026-08-30
- [NVD] CVE-2026-82543 (HIGH 7.3) — A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of the file apps/base/views.py of the component Pickup Limit Handler. Performing a manipulation results in race condition. It is possible to initiate the attacknvd · 2026-08-30
- [NVD] CVE-2026-82542 (CRITICAL 10.0) — A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to bnvd · 2026-08-30
- [NVD] CVE-2026-82541 (MEDIUM 6.3) — A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The envd · 2026-08-30
- [NVD] CVE-2026-82540 (MEDIUM 6.3) — A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publiclynvd · 2026-08-30
- [NVD] CVE-2026-81318 — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a distinct query, AshSql.AggregateQuery.add_single_aggs/5 renvd · 2026-08-30
- [NVD] CVE-2026-81316 — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary. AshSql.Aggregate.differentnvd · 2026-08-30
- [NVD] CVE-2026-80227 — Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the reverse)nvd · 2026-08-30
- [NVD] CVE-2026-78691 — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, turning a literal substring search into an anvd · 2026-08-30
- [NVD] CVE-2026-78228 — Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. The generated worker's atomic handle_error/4 runs the trigger's on_error action onnvd · 2026-08-30
- [NVD] CVE-2026-78038 — Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across tenants.nvd · 2026-08-30
- [NVD] CVE-2026-77454 — Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_many?) and a parent(...)-referencing filter or sort. AshSql.Join.related_query/3nvd · 2026-08-30
- [NVD] CVE-2026-82539 (CRITICAL 9.1) — A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched remonvd · 2026-08-30
- [NVD] CVE-2026-82488 (LOW 3.5) — A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicnvd · 2026-08-30
- [NVD] CVE-2026-82487 (MEDIUM 6.3) — A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted earlynvd · 2026-08-30
- [NVD] CVE-2026-82486 (MEDIUM 5.0) — A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is nvd · 2026-08-30
- [thegentlemen] Glassdoor posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] G R Infraprojects posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Northwest Trophy posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] General Gruppo posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Ixa Systems posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Tecno Accion posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Probe Test System posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] SUNSEA posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Thai Film Industries PCL posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Adkisson Group posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] ESB Puerto Rico Corp posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Nutrypollo posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Brebur posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] MB Associates posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Exacta Optech Labcenter posted to leak siteransomware_live · 2026-08-30
- [thegentlemen] Servicios Aereos Estrella posted to leak siteransomware_live · 2026-08-30
- [NVD] CVE-2026-82485 (MEDIUM 6.3) — A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploitnvd · 2026-08-30
- [NVD] CVE-2026-82484 (MEDIUM 6.3) — A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be unvd · 2026-08-30
- [threeam] wmdn.net posted to leak siteransomware_live · 2026-08-30
- [Black X] FE CREDIT posted to leak siteransomware_live · 2026-08-30
- [Black X] i-one posted to leak siteransomware_live · 2026-08-30
- [NVD] CVE-2026-82483 (LOW 3.5) — A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched remotelynvd · 2026-08-30
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoorthehackernews · 2026-08-30
- [NVD] CVE-2026-82482 (LOW 3.5) — A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biography leads to cross site scripting. The anvd · 2026-08-30
- [NVD] CVE-2026-81766 — The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to instnvd · 2026-08-30
- [NVD] CVE-2026-81660 — The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to perfonvd · 2026-08-30
- [NVD] CVE-2026-78364 — The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege unvd · 2026-08-30
- [NVD] CVE-2026-76585 — The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.nvd · 2026-08-30
- [NVD] CVE-2026-19722 — The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore direnvd · 2026-08-30
- [NVD] CVE-2026-14835 — The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with contribunvd · 2026-08-30
- [NVD] CVE-2026-14307 — The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a victimnvd · 2026-08-30
- CyberDanube Security Research 20260611-0 | Multiple Denial of Service Vulnerabilities in Dahua IPC/SD/NVR/XVR/EVS/VTO/VTH/ASI/TPC Camera Seriesfulldisclosure · 2026-08-30
- JSON Deserialiser Unconstrained Resource Consumption Proof of Conceptfulldisclosure · 2026-08-30
- [NVD] CVE-2026-82480 (HIGH 7.4) — A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize renvd · 2026-08-30
- [NVD] CVE-2026-82479 (MEDIUM 6.3) — A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from winvd · 2026-08-30
- [NVD] CVE-2026-82478 (HIGH 7.3) — A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes stack-bnvd · 2026-08-30
- [NVD] CVE-2026-15980 (CRITICAL 9.8) — The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for unautnvd · 2026-08-30
- [NVD] CVE-2026-77846 — Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested JSON the application never exposed, disclosing private or sensitive? embedded fields. AshSqlite.Sqnvd · 2026-08-30
- [NVD] CVE-2026-75759 — Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted nvd · 2026-08-30