THREAT OPS › Threat News
Threat Intelligence News
12139 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- VerdantBamboo: Just Another BRICKSTORM in the Firewallvolexity · 2026-06-04
- [NVD] CVE-2026-25551 (HIGH 7.8) — Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-privileged local users to escalate privileges. The DataServiceSingleton .NET Remoting endpoint is bound to localhost on TCP port 7375 via BtSystem.Service.exe, limnvd · 2026-06-04
- [NVD] CVE-2026-25550 (CRITICAL 9.8) — Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .NET Remoting service exposed on TCP port 7375 via BtSystem.Service.exe. The service registers an unauthenticated singleton endpoint — BarTenderSystem for BarTendnvd · 2026-06-04
- Ghostwriter v7: Safer Tokens, Scoped Access, and Better Automationspecterops · 2026-06-04
- [NVD] CVE-2026-8037 (CRITICAL 9.6) — OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpointsnvd · 2026-06-04
- Cybercriminals Are Targeting the FIFA World Cup 2026fortinet_research · 2026-06-04
- [NVD] CVE-2026-10840 (HIGH 7.1) — A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are pnvd · 2026-06-04
- Srsly Risky Biz: NATO's cyber approach needs to changeriskybiz_news · 2026-06-04
- [NVD] CVE-2026-10805 (MEDIUM 6.7) — A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileges by triggering a script via nvd · 2026-06-04
- Remembering Sir Alex Youngerrecordedfuture · 2026-06-04
- [NVD] CVE-2026-7888 — Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. The Form block and File/Set sinks were addressed in 9.5.2; the Workflow component sinks were addrnvd · 2026-06-03
- [NVD] CVE-2026-46273 (HIGH 8.6) — In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power systems do not support segmentation offload when the MSS is less than 224 bytes. Attempting to send such packets causes the adaptenvd · 2026-06-03
- [NVD] CVE-2026-46266 (CRITICAL 9.1) — In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having one RAW socket on protocol IPPROTO_RAW (255) was dangerous. socket(AF_INET, SOCK_RAW, 255); A malicious innvd · 2026-06-03
- [NVD] CVE-2026-42318 — GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI. Upgrade to 11.0.7 or 10.0.25 to receive a patch. As a workaround, disable deletenvd · 2026-06-03
- Cisco Webex Meetings Cross-Site Scripting Vulnerabilitycisco_psirt · 2026-06-03
- [NVD] CVE-2026-5241 (CRITICAL 9.6) — A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remonvd · 2026-06-03
- Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystemcheckpoint_research · 2026-06-03
- Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMOfortinet_research · 2026-06-03
- The sorry state of skill distributiontrailofbits · 2026-06-03
- Risky Bulletin: FSB calls out Western spyware operationriskybiz_news · 2026-06-03
- [CISA KEV] CVE-2026-45247 — Mirasvit Mirasvit Full Page Cache Warmer: Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerabilitycisa_kev · 2026-06-03
- [NVD] CVE-2026-27145 (MEDIUM 6.5) — (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same input hostname. With a large DNS SAN list, verification costs scaled quadraticnvd · 2026-06-02
- [NVD] CVE-2026-34993 (MEDIUM 6.4) — AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this isnvd · 2026-06-02
- [NVD] CVE-2026-47117 (CRITICAL 9.8) — OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the user-supplied model_name parameter, allowing a value such as attacker/foo-privacy-filter-bar to rounvd · 2026-06-02
- [NVD] CVE-2026-43965 — Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content. Package keys read from build/packages/packages.toml by LocalPackages::read_from_disc are passed without validation to paths.buildnvd · 2026-06-02
- [NVD] CVE-2026-42795 — Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball. The file collection helpers (gleam_files, native_files, private_files) in compiler-cli/src/fs.rs use follow_links(true) when walkinvd · 2026-06-02
- [NVD] CVE-2026-32685 — Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory. The documentation.pages entries from gleam.toml are incorporated into filesystem paths without sufficientnvd · 2026-06-02
- LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukrainesentinelone · 2026-06-02
- [NVD] CVE-2026-1784 (HIGH 8.8) — The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configurationnvd · 2026-06-02
- Between Two Nerds: The intelligence cultriskybiz_news · 2026-06-02
- Iran Expands Handala Brand to Physical Threatsrecordedfuture · 2026-06-02
- [CISA KEV] CVE-2022-0492 — Linux Kernel: Linux Kernel Improper Authentication Vulnerabilitycisa_kev · 2026-06-02
- [CISA KEV] CVE-2025-48595 — Android Framework: Android Framework Integer Overflow Vulnerabilitycisa_kev · 2026-06-02
- From API key to live threat detections in minutes: how Elastic Security ingests Google Threat Intelligenceelastic_security · 2026-06-02
- [NVD] CVE-2026-28581 (MEDIUM 4.0) — In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local escalation with User execution privileges needed. User interaction is needed for exploitation.nvd · 2026-06-01
- [NVD] CVE-2026-5419 (LOW 3.7) — A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing side-channel could allow a remote attacker to potentially leak sensitive information about the padding bytes through observable timing differences. This vulnerabinvd · 2026-06-01
- [NVD] CVE-2026-43958 (HIGH 7.8) — A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulnerability can lead to a denial of service by crashing the daemon or potentially allnvd · 2026-06-01
- [NVD] CVE-2024-52011 (HIGH 8.3) — launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Windows by supplying a filename that containnvd · 2026-06-01
- Hackers Used Meta’s AI Support Bot to Seize Instagram Accountskrebs · 2026-06-01
- [NVD] CVE-2026-46243 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that cifs.upcall treats as kernel-originating innvd · 2026-06-01
- CVE-2026-4387: StrongDM State File Reusespecterops · 2026-06-01
- 1st June – Threat Intelligence Reportcheckpoint_research · 2026-06-01
- Overview of Content Published in Maydidier_stevens · 2026-06-01
- Risky Bulletin: Recently patched PAN 0day exploited in the wildriskybiz_news · 2026-06-01
- Vulnerability & Patch Roundup — May 2026sucuri_blog · 2026-06-01
- [CISA KEV] CVE-2024-21182 — Oracle WebLogic Server: Oracle WebLogic Server Unspecified Vulnerabilitycisa_kev · 2026-06-01
- Sponsored: Inside CISA's disastrous secrets leakriskybiz_news · 2026-05-31
- [Breach] Atlas Menu — 63,926 accounts exposedhibp_breaches · 2026-05-30
- [NVD] CVE-2026-46385 (HIGH 7.5) — iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the underlying reader's error state inside the loop body. Reader.ReadBlockHeader returns the count as a Go int, which isnvd · 2026-05-29
- [NVD] CVE-2026-46384 (HIGH 7.5) — iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed them to platform-sized int before bounds-checking, or summed them with overflow-prone signed-int arithmetic. On 32-nvd · 2026-05-29
- [NVD] CVE-2026-45700 (CRITICAL 9.8) — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinatenvd · 2026-05-29
- [NVD] CVE-2026-46579 (HIGH 7.4) — A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Clienvd · 2026-05-29
- [NVD] CVE-2026-42965 (HIGH 7.7) — A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requestsnvd · 2026-05-29
- Risky Bulletin: Dutch police take down 17m device botnetriskybiz_news · 2026-05-29
- [NVD] CVE-2026-8070 — Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s validation mechanism, resulting in unauthorized read and write access to physical memory.Refer to the ' Security Update for Armoury Crate App ' section on the ASnvd · 2026-05-29
- [CISA KEV] CVE-2026-0257 — Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS Authentication Bypass Vulnerabilitycisa_kev · 2026-05-29
- [Breach] BCD Travel — 396,313 accounts exposedhibp_breaches · 2026-05-29
- [NVD] CVE-2026-45292 (MEDIUM 5.3) — opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing telemetry recorded by the API. Prior to 1.62.0, a vulnerability affects the baggage propagation implementation in opentelemetry-api and opentelemetry-extension-tranvd · 2026-05-28
- [NVD] CVE-2026-48526 (HIGH 7.4) — PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer publnvd · 2026-05-28
- [NVD] CVE-2026-48523 (MEDIUM 5.4) — PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-listnvd · 2026-05-28
- The Case for Practicing Response Before You Need Itspecterops · 2026-05-28
- Don’t Jump the Turnstile: Lessons from the Fieldspecterops · 2026-05-28
- Microsoft’s stance on zero day exploits is a dumpster fire of their own makingdoublepulsar · 2026-05-28
- [NVD] CVE-2026-46193 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: xfrm: ah: account for ESN high bits in async callbacks AH allocates its temporary auth/ICV layout differently when ESN is enabled: the async ahash setup appends a 4-byte seqhi slot before the ICV or auth_data anvd · 2026-05-28
- [NVD] CVE-2026-46173 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: exit: prevent preemption of oopsing TASK_DEAD task When an already-exiting task oopses, make_task_dead() currently calls do_task_dead() with preemption enabled. That is forbidden: do_task_dead() calls __schedunvd · 2026-05-28
- [NVD] CVE-2026-46172 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() xfrm6_rcv_encap() performs an IPv6 route lookup when the skb does not already have a dst attached. ip6_route_input_lookup() returns a referenced dst entry nvd · 2026-05-28
- [NVD] CVE-2026-46170 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: free sk if last When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(), and released at the end. If at that moment, it was the last reference being held, the sk would nonvd · 2026-05-28
- [NVD] CVE-2026-46158 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(). It should then be released in all cases at the end. Some (unlikely) checks were returnvd · 2026-05-28
- [NVD] CVE-2026-46152 (HIGH 8.8) — In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: drop stray 'static' from fast-RX rx_result ieee80211_invoke_fast_rx() is documented as safe for parallel RX, but its per-invocation rx_result is declared static. Concurrent callers then share onnvd · 2026-05-28
- [NVD] CVE-2026-46145 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Validate rx_hash_key_len Sashiko points out that rx_hash_key_len comes from a uAPI structure and is blindly passed to memcpy, allowing the userspace to trash kernel memory. Bounds check it so the memnvd · 2026-05-28
- [NVD] CVE-2026-46132 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo rtnl_fill_vfinfo() declares struct ifla_vf_broadcast on the stack without initialisation: struct ifla_vf_broadcast vf_broadcanvd · 2026-05-28
- [NVD] CVE-2026-46130 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: dm-verity-fec: fix reading parity bytes split across blocks (take 3) fec_decode_bufs() assumes that the parity bytes of the first RS codeword it decodes are never split across parity blocks. This assumption isnvd · 2026-05-28
- [NVD] CVE-2026-46117 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() Sashiko points out that the user can specify WQs sharing the same CQ as a part of the uAPI and this will trigger the WARN_ON() then go on nvd · 2026-05-28
- [NVD] CVE-2026-46116 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete KASAN reproduces a slab-use-after-free in __xfrm_state_delete()'s hlist_del_rcu calls under syzkaller load on linux-6.12.y stable (reproduced on nvd · 2026-05-28
- [NVD] CVE-2026-9804 (HIGH 7.7) — A flaw was found in KubeVirt's virt-exportserver component. An attacker with specific namespace-level access can exploit a path traversal vulnerability in the VMExport directory endpoint. By placing a symbolic link (symlink) within an exported filesystem Persistent Volume Claim (nvd · 2026-05-28
- [NVD] CVE-2026-7526 (MEDIUM 4.3) — The PDF Embedder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.3 via the enqueue_block_assets. This makes it possible for authenticated attackers, with contributor-level access and above, to extract configuration danvd · 2026-05-28
- [NVD] CVE-2026-4408 (CRITICAL 9.0) — A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passednvd · 2026-05-28
- [NVD] CVE-2026-44604 (HIGH 7.0) — A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizinvd · 2026-05-28
- [NVD] CVE-2026-9796 (MEDIUM 6.5) — A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users nvd · 2026-05-28
- [NVD] CVE-2026-44724 (HIGH 7.8) — systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable vnvd · 2026-05-27
- [NVD] CVE-2026-42790 (HIGH 8.1) — Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. Two flaws combine to allow a subordinate CA whose DNS nameConstraints arenvd · 2026-05-27
- Spelunking through Splunkspecterops · 2026-05-27
- [NVD] CVE-2026-46101 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: netfilter: reject zero shift in nft_bitwise Reject zero shift operands for nft_bitwise left and right shift expressions during initialization. The carry propagation logic computes the carry from the adjacent 3nvd · 2026-05-27
- [NVD] CVE-2026-46099 (HIGH 8.1) — In the Linux kernel, the following vulnerability has been resolved: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels seg6_input_core() and rpl_input() call ip6_route_input() which sets a NOREF dst on the skb, then pass it to dst_cache_set_ip6() invoking dst_hold() uncondinvd · 2026-05-27
- [NVD] CVE-2026-46090 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: ALSA: aloop: Fix peer runtime UAF during format-change stop loopback_check_format() may stop the capture side when playback starts with parameters that no longer match a running capture stream. Commit 826af7fa6nvd · 2026-05-27
- [NVD] CVE-2026-46086 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: net: bridge: use a stable FDB dst snapshot in RCU readers Local FDB entries can be rewritten in place by `fdb_delete_local()`, which updates `f->dst` to another port or to `NULL` while keeping the entry alive. nvd · 2026-05-27
- [NVD] CVE-2026-46054 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: selinux: fix overlayfs mmap() and mprotect() access checks The existing SELinux security model for overlayfs is to allow access if the current task is able to access the top level file (the "user" file) and thenvd · 2026-05-27
- [NVD] CVE-2026-46046 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() The commit c8e008b60492 ("ext4: ignore xattrs past end") introduced a refcount leak in when block_csum is false. ext4_xattr_inode_dec_ref_all() callnvd · 2026-05-27
- [NVD] CVE-2026-46040 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails When fsnotify_add_inode_mark_locked() fails in inotify_new_watch(), the error path calls inotify_remove_from_idr() but does not call decnvd · 2026-05-27
- [NVD] CVE-2026-46037 (HIGH 8.2) — In the Linux kernel, the following vulnerability has been resolved: ipv4: icmp: validate reply type before using icmp_pointers Extended echo replies use ICMP_EXT_ECHOREPLY as the outbound reply type. That value is outside the range covered by icmp_pointers[], which only describnvd · 2026-05-27
- [NVD] CVE-2026-46033 (HIGH 7.1) — In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject short ahash digests during instance creation authencesn requires either a zero authsize or an authsize of at least 4 bytes because the ESN encrypt/decrypt paths always move 4 bytes onvd · 2026-05-27
- [NVD] CVE-2026-46021 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix thermal zone governor cleanup issues If thermal_zone_device_register_with_trips() fails after adding a thermal governor to the thermal zone being registered, the governor is not removed from nvd · 2026-05-27
- [NVD] CVE-2026-46015 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: tcp: call sk_data_ready() after listener migration When inet_csk_listen_stop() migrates an established child socket from a closing listener to another socket in the same SO_REUSEPORT group, the target listener nvd · 2026-05-27
- [NVD] CVE-2026-45998 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix potential UAF after skb_unshare() failure If skb_unshare() fails to unshare a packet due to allocation failure in rxrpc_input_packet(), the skb pointer in the parent (rxrpc_io_thread()) will be NULL'nvd · 2026-05-27
- [NVD] CVE-2026-45984 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix use-after-free in iomap inline data write path The inline data buffer head (dibh) is being released prematurely in gfs2_iomap_begin() via release_metapath() while iomap->inline_data still points to dinvd · 2026-05-27
- [NVD] CVE-2026-45963 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: ASoC: nau8821: Cancel delayed work on component remove Attempting to unload the driver while a jack detection work is pending would likely crash the kernel when it is eventually scheduled for execution: [ 1984nvd · 2026-05-27
- [NVD] CVE-2026-45901 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: revert commit_mutex usage in reset path It causes circular lock dependency between commit_mutex, nfnl_subsys_ipset and nlk_cb_mutex when nft reset, ipset list, and iptables-nft with '-m senvd · 2026-05-27
- [NVD] CVE-2026-45897 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_counter: serialize reset with spinlock Add a global static spinlock to serialize counter fetch+reset operations, preventing concurrent dump-and-reset from underrunning values. The lock is taken nvd · 2026-05-27
- [NVD] CVE-2026-42789 (MEDIUM 4.8) — Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be accepted as an intermediate issuer, enabling certificate chain forgery. In lib/public_key/src/pubkey_cert.erl, pubkey_cert:validate_nvd · 2026-05-27
- [NVD] CVE-2026-2340 (MEDIUM 6.5) — A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with writenvd · 2026-05-27