🔐
Onlook Authorization Flaw Lets Users Access Other Projects
Organizations running affected Onlook versions should update immediately. Any deployment with multiple users is at risk of unauthorized data access and tampering.
CVE-2026-65013 is a broken object level authorization vulnerability in Onlook through 0.2.32 with a CVSS score of 8.8. Authenticated attackers can supply arbitrary UUID values to tRPC API procedures including project.get, member.remove, and chat.conversation.delete to access, modify, or delete other users’ project data, members, and conversation history. The issue is fixed in commit 423e2e9 and is rated HIGH.
🔗 Read more 🔗
Source: NVD
🎬
FFmpeg Vulkan HEVC Decoder Buffer Overflow Risks RCE
Patch promptly if your applications process untrusted video with affected FFmpeg builds. Media processing services and desktop applications should treat this as a high-priority update.
CVE-2026-64831 is a stack buffer overflow vulnerability in the FFmpeg Vulkan HEVC hardware decoder affecting versions 8.0 through 8.1.2 with a CVSS score of 8.8. A crafted HEVC/H.265 bitstream can overflow stack-allocated arrays in the vk_hevc_end_frame function by using a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS, potentially achieving arbitrary code execution. The vulnerability is rated HIGH.
🔗 Read more 🔗
Source: NVD
📼
FFmpeg VobSub Parsing Bug Can Enable Code Execution
Update FFmpeg anywhere untrusted subtitle files are accepted. Media servers, players, and transcoding pipelines should prioritize remediation.
CVE-2026-64830 is a heap buffer overflow vulnerability in the FFmpeg VobSub subtitle demuxer affecting versions 2.1 through 8.1.2 with a CVSS score of 8.8. A malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds can trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution. The vulnerability is rated HIGH.
🔗 Read more 🔗
Source: NVD
🚨
Dell PowerProtect REST API Bug Enables Privilege Escalation
Administrators should upgrade affected PowerProtect Data Manager deployments as soon as possible. Backup infrastructure is especially sensitive and should be kept fully patched.
CVE-2026-40712 is an Improper Input Validation vulnerability in the REST API of Dell PowerProtect Data Manager, versions prior to 20.2.0.0, with a CVSS score of 9.1. A high privileged attacker with remote access could potentially exploit the vulnerability, leading to Elevation of privileges. The vulnerability is rated CRITICAL.
🔗 Read more 🔗
Source: NVD
🛡️
Fujitsu openFT Local Privilege Escalation to Root
Upgrade affected openFT installations, especially on shared systems where local users have access. The flaw requires prior authentication but still warrants timely patching.
CVE-2026-16607 affects Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 with a CVSS score of 7.8. An already authenticated user can perform local privilege escalation to root on GNU/Linux or Oracle Solaris. The vulnerability is rated HIGH.
🔗 Read more 🔗
Source: NVD
🔥
Fujitsu openFT Pre-Auth RCE Demands Immediate Attention
This is an urgent patch for any exposed openFT deployment. Internet-facing systems should be updated immediately and access restricted until remediation is complete.
CVE-2026-16606 affects Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 with a CVSS score of 9.8. The vulnerability allows unauthenticated remote code execution pre-auth on GNU/Linux or Oracle Solaris. The vulnerability is rated CRITICAL.
🔗 Read more 🔗
Source: NVD
🖼️
libheif Grid Decoding Bug Causes Out-of-Bounds Read
Update libheif to version 1.22.0 or later if your software processes untrusted HEIF or AVIF images. Image handling libraries are common attack surfaces.
CVE-2026-48029 affects libheif versions 1.19.0 through 1.21.2 with a CVSS score of 7.1. A heap OOB read in ImageItem_Grid::decode_grid_tile can be triggered via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue and the vulnerability is rated HIGH.
🔗 Read more 🔗
Source: NVD
💉
SQL Injection Hits Xpoda No Code Platform
Users of the affected platform should apply a fix as soon as one is available and consider compensating controls in the meantime. Internet-exposed deployments deserve immediate review.
CVE-2026-2395 is an SQL injection vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform affecting versions from 4.3.1.0 through 20260722 with a CVSS score of 9.8. Improper neutralization of special elements used in an SQL command allows SQL Injection. The vulnerability is rated CRITICAL, and the vendor was contacted early about this disclosure but did not respond in any way.
🔗 Read more 🔗
Source: NVD
🌐
BIND DNSSEC Validation Weakness Accepts Invalid NSEC Records
DNS operators should upgrade affected BIND resolvers on supported branches. Resolver integrity is critical for enterprise infrastructure.
CVE-2026-13321 affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1 with a CVSS score of 8.6. The resolver accepts validly-signed NSEC records where the Next Domain Name field points outside the signer’s zone. The vulnerability is rated HIGH.
🔗 Read more 🔗
Source: NVD
⚠️
BIND Assertion Failure Can Crash Resolvers
Upgrade affected BIND resolvers to prevent avoidable service interruptions. DNS infrastructure teams should schedule this update promptly.
CVE-2026-13204 affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1 with a CVSS score of 7.5. If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent and there is an RRSIG for only one type, BIND may exit unexpectedly with an assertion during validation. The vulnerability is rated HIGH.
🔗 Read more 🔗
Source: NVD
💥
BIND Resolver Crash Triggered by Crafted DNS Responses
Operators of recursive BIND resolvers should patch to avoid resolver crashes triggered by malicious or malformed DNS traffic.
CVE-2026-12617 affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1 with a CVSS score of 7.5. Specific ordering and content of responses to CNAME or DNAME and A record queries can cause named to quit unexpectedly, including delayed negative DNAME responses or self-referential CNAME responses. The vulnerability is rated HIGH.
🔗 Read more 🔗
Source: NVD
📡
BIND RPZ Processing Bug Can Bypass Policies
Organizations using RPZ should prioritize updates to preserve policy enforcement and resolver stability. DNS filtering deployments are the most affected.
CVE-2026-11331 affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1 with a CVSS score of 7.5. An attacker can craft query names long enough to trigger a NAMETOOLONG error during RPZ processing, potentially defeating RPZ wildcard CNAME policies and causing BIND 9 to exit unexpectedly. The vulnerability is rated HIGH.
🔗 Read more 🔗
Source: NVD