🛡️ V-Secure Jingyun Antivirus Kernel Driver Access-Control Flaw
Systems running this V-Secure version should be treated as a high-priority patch or mitigation target, especially on shared or otherwise exposed endpoints. Public exploit code is available, although the entry does not state that active exploitation has been observed.
CVE-2026-19195 affects V-Secure Jingyun Antivirus 2.4.2.39 and involves improper access controls in the ZyArk.sys kernel driver. The flaw requires local access, and a public exploit has been disclosed and may be used. It is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD
🛡️ Jiangmin Antivirus Minifilter Driver Access-Control Vulnerability
Organizations still running Jiangmin Antivirus 21 should prioritize remediation or compensating controls on affected endpoints. The exploit is public, increasing urgency even though the entry does not confirm active exploitation.
CVE-2026-19193 affects Jiangmin Antivirus 21 in the MessageNotifyCallback function of the kvcore.sys Minifilter Port component. Local manipulation can result in improper access controls, and an exploit has been published and may be used. It is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD
⚠️ DeepCool DisplayService Improper Access-Control Flaw
Anyone running DeepCool DisplayService 1.2.12 should update or restrict local access as soon as a vendor fix or mitigation is available. Public exploit availability makes this more urgent for multi-user and less-trusted Windows systems.
CVE-2026-19192 affects DeepCool DisplayService 1.2.12 and involves improper access controls in DeepCoolDisplayService.exe. Exploitation requires local access, and the exploit is public and may be used. It is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD
⚠️ StableBit DrivePool Service Permission Flaw Exposes Local Systems
Administrators using this StableBit DrivePool release should prioritize updating or applying vendor mitigations, particularly on systems accessible to untrusted local users. The public exploit raises the risk, though active exploitation is not stated.
CVE-2026-19191 affects StableBit DrivePool 2.3.13.1687 in the DrivePool.Service.exe component. Local manipulation can cause permission issues, and a public exploit has been disclosed and may be used. It is rated HIGH with CVSS 7.8.
🔗 Read more 🔗
Source: NVD
🚨 TrueBooker WordPress Flaw Lets Attackers Take Over Admin Accounts
WordPress operators using TrueBooker 1.2.3 or earlier should patch or disable the plugin immediately. The vulnerability is remotely reachable without authentication and can directly lead to administrator account compromise.
CVE-2026-14365 affects the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress through version 1.2.3. An authorization bypass allows unauthenticated attackers to change arbitrary user passwords, including administrator passwords, enabling account takeover. It is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
🚨 TrueBooker Password Reset Flaw Enables Unauthenticated Account Takeover
Sites running TrueBooker 1.2.3 or earlier should patch or disable the plugin immediately. Because no authentication is required and administrator accounts can be seized, this should be treated as an emergency remediation item.
CVE-2026-14364 affects the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress through version 1.2.3. Improper password-reset validation lets unauthenticated attackers reset passwords for arbitrary accounts, including administrators, and gain access to those accounts. It is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
🌐 Chrome CrashReporting Heap Overflow Could Enable Sandbox Escape
Chrome users and enterprise administrators should update to 151.0.7922.109 or later promptly. The flaw can form part of a browser exploit chain by turning renderer compromise into a potential sandbox escape.
CVE-2026-19138 is a heap buffer overflow in Google Chrome CrashReporting before version 151.0.7922.109. A remote attacker who has already compromised the renderer process could use a crafted HTML page to potentially escape the Chrome sandbox. It is rated HIGH with CVSS 8.3.
🔗 Read more 🔗
Source: NVD
🚨 Chrome Android WebGL Use-After-Free Threatens Sandbox Isolation
Android Chrome deployments should be updated to 151.0.7922.109 or later as soon as possible. Its potential role in a renderer-to-sandbox-escape chain makes rapid browser patching especially important.
CVE-2026-19137 is a use-after-free vulnerability in WebGL in Google Chrome on Android before version 151.0.7922.109. A remote attacker who has compromised the renderer process could potentially escape the sandbox through a crafted HTML page. NVD rates it HIGH with CVSS 8.3, while Chromium security severity is stated as Critical.
🔗 Read more 🔗
Source: NVD
🔐 Chrome Windows Race Condition Enables Local Privilege Escalation
Windows environments using Chrome should update to 151.0.7922.109 or later promptly, particularly on shared endpoints or systems where untrusted users can obtain local access. The impact reaches beyond the browser because successful exploitation can elevate operating-system privileges.
CVE-2026-19139 is a race condition in Google Chrome CredentialProvider on Windows before version 151.0.7922.109. A local attacker can exploit it through a malicious file to perform OS-level privilege escalation. It is rated HIGH with CVSS 7.4.
🔗 Read more 🔗
Source: NVD
🌐 Chrome GPU Use-After-Free Could Break Out of the Sandbox
Users and managed fleets should update Chrome to 151.0.7922.109 or later promptly. This is particularly important because sandbox-escape vulnerabilities can be combined with renderer exploits for more serious browser compromise.
CVE-2026-19140 is a use-after-free vulnerability in the GPU component of Google Chrome before version 151.0.7922.109. A remote attacker who has already compromised the renderer process could use a crafted HTML page to potentially perform a sandbox escape. It is rated HIGH with CVSS 8.3.
🔗 Read more 🔗
Source: NVD
💥 Chrome Translate Use-After-Free Allows Code Execution Inside Sandbox
Chrome users and enterprise fleets should move to 151.0.7922.109 or later quickly. Arbitrary code execution is significant even when initially contained by the sandbox and may become more severe when chained with a sandbox-escape flaw.
CVE-2026-19145 is a use-after-free vulnerability in the Translate component of Google Chrome before version 151.0.7922.109. A remote attacker can use a crafted HTML page to execute arbitrary code inside the browser sandbox. It is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
🚨 Critical Chrome Linux Aura Flaw Could Enable Sandbox Escape
Linux Chrome installations should be upgraded to 151.0.7922.109 or later immediately. With a critical rating and potential sandbox escape, this is a top-priority browser patch for both individual users and managed fleets.
CVE-2026-19149 is a use-after-free vulnerability in the Aura component of Google Chrome on Linux before version 151.0.7922.109. A remote attacker can potentially perform a sandbox escape through a crafted HTML page. It is rated CRITICAL with CVSS 9.6.
🔗 Read more 🔗
Source: NVD