🚨 Critical SQL Injection Hits Travel Agency Management System
Organizations running the affected Travel Agency Management System should remediate immediately, especially on internet-facing deployments. Unauthenticated access to arbitrary database operations makes this a critical exposure.
CVE-2026-19425 is an unauthenticated SQL injection vulnerability in the Travel Agency Management System developed by Win Men Intermational. Remote attackers can inject arbitrary SQL commands to read, modify, or delete database contents. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
🛡️ ASUS Utility Flaw Can Enable Local Privilege Escalation
Administrators with affected ASUS utilities should apply the vendor security updates promptly. Give extra priority to shared endpoints or systems where untrusted local users or compromised processes could exploit the privilege-escalation path.
CVE-2026-8917 is an untrusted pointer dereference and IOCTL vulnerability affecting ASUS GPU Tweak III, GPU Tweak II, AI Suite 3, and VGAdll. A local attacker can write a specific value to an arbitrary memory address, potentially leading to privilege escalation. The vulnerability is rated HIGH with CVSS 8.4.
🔗 Read more 🔗
Source: NVD
🔑 Hard-Coded Key Puts SAP BusinessObjects Credentials at Risk
SAP BusinessObjects administrators should patch affected servers promptly and tightly review privileged local access. The attack has significant prerequisites, but credential recovery could deepen an existing compromise and enable further access.
CVE-2026-66763 affects SAP BusinessObjects Business Intelligence Platform, which stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local server access could retrieve those objects and decrypt the stored credentials, exposing authentication data and enabling modification of protected information. The vulnerability is rated HIGH with CVSS 7.9.
🔗 Read more 🔗
Source: NVD
⚠️ SAP ABAP Authorization Flaw Exposes Database Operations
SAP teams using ABAP Development Tools with NetWeaver AS ABAP should patch urgently. Low privilege requirements combined with high confidentiality, integrity, and availability impact make this a priority enterprise remediation.
CVE-2026-58243 is an authorization-check vulnerability in SAP ABAP Development Tools affecting SAP NetWeaver AS ABAP. An attacker with low privileges can execute unauthorized database operations, potentially reading sensitive data, modifying application data, and disrupting legitimate access. The vulnerability is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
🔐 SAP Approuter Token Validation Flaw Can Leak Credentials
SAP Approuter operators should patch affected deployments and determine whether the required non-default conditions exist in their environments. Prioritize externally reachable systems that match those conditions because successful exploitation can expose sensitive credentials.
CVE-2026-58230 affects SAP Approuter under specific configurations where certain token content is not sufficiently validated. An unauthenticated attacker could submit a specially crafted token that causes sensitive credential material to be sent to an attacker-controlled destination, although exploitation requires high-complexity non-default preconditions. The vulnerability is rated HIGH with CVSS 7.0.
🔗 Read more 🔗
Source: NVD
🏭 SAP MII Authorization Gap Exposes Scheduling Functions
Organizations running SAP MII should patch promptly, prioritizing systems reachable from untrusted networks. The lack of authentication increases exposure even though the reported confidentiality, integrity, and availability impacts are individually low.
CVE-2026-44765 is a missing authorization check in SAP Manufacturing Integration and Intelligence. An unauthenticated remote attacker can access scheduling-related application functions and retrieve, create, modify, or delete application-managed scheduling data. The vulnerability is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
🏭 SAP MII Cost Servlet Flaw Opens Backend Operations
SAP MII administrators should patch promptly and prioritize deployments exposed to untrusted networks. Unauthenticated access to backend business operations warrants timely remediation despite the described impact being limited.
CVE-2026-44764 is a missing authorization check in SAP Manufacturing Integration and Intelligence involving crafted requests to the Cost Servlet. An unauthenticated attacker can use specific parameter values to access backend operations and potentially read, create, modify, or delete application-managed business data. The vulnerability is rated HIGH with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
📁 SAP MII Path Validation Bug Can Write Files Outside Intended Directories
SAP MII operators should patch affected systems promptly, particularly where privileged accounts or shared filesystem access increase potential impact. Exploitation has multiple prerequisites, but successful abuse can have high confidentiality, integrity, and availability consequences.
CVE-2026-44763 affects SAP Manufacturing Integration and Intelligence through insufficient file path validation in certain functions. A privileged attacker can provide specially crafted input that, after a legitimate user accesses attacker-influenced content and other required conditions are met, may write files outside the intended directory and affect other components. The vulnerability is rated HIGH with CVSS 7.6.
🔗 Read more 🔗
Source: NVD
💥 Critical SAP MII Flaw Enables Arbitrary OS Commands
SAP MII administrators should treat this as a top-priority patch, particularly on production systems with powerful privileged accounts. High privileges are required to exploit it, but arbitrary operating-system command execution makes the potential post-compromise impact severe.
CVE-2026-44758 is an input-validation vulnerability in SAP Manufacturing Integration and Intelligence. An attacker with high privileges can submit specially crafted input that is processed without sufficient validation, potentially enabling arbitrary command execution on the underlying operating system. The vulnerability is rated CRITICAL with CVSS 9.1.
🔗 Read more 🔗
Source: NVD
🚨 Critical SAP NetWeaver DIAG Parsing Flaw Causes Memory Corruption
SAP NetWeaver AS ABAP operators should patch immediately, especially where the affected protocol is reachable from untrusted networks. Unauthenticated exploitation and a CVSS 9.8 rating justify emergency-level remediation.
CVE-2026-34265 is a memory-corruption vulnerability in SAP NetWeaver Application Server ABAP caused by logical errors in DIAG protocol parsing. An unauthenticated attacker could potentially disclose sensitive system information or crash the system, with high impact on confidentiality, integrity, and availability. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
🔓 Chiline Cloud IDOR Exposes Other Users’ Sensitive Data
Chiline Cloud operators should patch promptly and prioritize publicly reachable deployments. Because attackers do not need authentication to access other users’ sensitive information, this should be treated as a significant confidentiality risk.
CVE-2026-19424 is an insecure direct object reference vulnerability in Chiline Cloud developed by Inventec Appliances. Unauthenticated remote attackers can modify a specific parameter to read sensitive data belonging to other users. The vulnerability is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD
🧠 Zephyr DTLS Socket Flaw Can Overflow Kernel Heap
Teams shipping Zephyr systems with CONFIG_MBEDTLS_SSL_DTLS_CONNECTION_ID should update affected firmware promptly, with extra priority for CONFIG_USERSPACE builds. Exploitation requires specific DTLS configuration and an established session, but kernel-heap corruption can have serious security consequences.
CVE-2026-8718 is a buffer-overflow vulnerability in Zephyr’s TLS socket handling for DTLS peer Connection IDs. The tls_opt_dtls_peer_connection_id_value_get() path can pass an undersized caller buffer to mbedtls_ssl_get_peer_cid(), causing a write of up to 31 bytes beyond the buffer; in CONFIG_USERSPACE builds, an unprivileged user thread can trigger a kernel-heap overflow when the required DTLS Connection ID configuration and negotiated-session conditions are present. The vulnerability is rated HIGH with CVSS 8.4.
🔗 Read more 🔗
Source: NVD