⚠️ H3C NX15 Web API Exposes Dangerous Routine
Operators running H3C NX15 V100R017 should restrict Web API access and apply vendor remediation as soon as it is available. Prioritize internet-facing devices because a public exploit is available.
CVE-2026-18901 affects the service.add function in the /api/esps Web API of H3C NX15 V100R017. Remote manipulation can expose a dangerous routine, and the exploit has been disclosed publicly and may be used. The vulnerability is rated HIGH with CVSS 7.2.
🔗 Read more 🔗
Source: NVD
💥 UTT HiPER 1200GW Hit by Remote Buffer Overflow
UTT HiPER 1200GW administrators should patch or isolate affected gateways urgently. Public exploit availability and the lack of a reported vendor response increase the immediate risk.
CVE-2026-18898 is a stack-based buffer overflow in the strcpy handling of the timestart argument at /goform/ConfigAdvideo in UTT HiPER 1200GW through v2.5.3-170306. A remote attacker may trigger the flaw, and the exploit has been released publicly and may be used for attacks. The vulnerability is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
💥 UTT HiPER 1250GW TempName Overflow Exposed
Teams managing HiPER 1250GW appliances should remediate or remove remote access urgently. Treat this as high priority because a public exploit is available and the vendor reportedly did not respond.
CVE-2026-18897 affects UTT HiPER 1250GW through v3.2.7-210907-180535. Improper copying of the tempName argument in /goform/getOneApConfTempEntry can cause a remotely triggered stack-based buffer overflow. The vulnerability is rated HIGH with CVSS 8.8, and the exploit is publicly available and might be used.
🔗 Read more 🔗
Source: NVD
🚨 UTT HiPER 1250GW 5 GHz Endpoint Overflow
Patch affected HiPER 1250GW gateways urgently or block access to the vulnerable management endpoint. Public exploit availability and no reported vendor response make exposed devices high-priority targets.
CVE-2026-18895 is a stack-based buffer overflow in the /goform/APSecurity_5g endpoint of UTT HiPER 1250GW through 3.2.7-210907-180535. Manipulating the cipher argument can remotely overflow a buffer, and the exploit has been made public and could be used. The vulnerability is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
🛢️ ESAFENET CDG KeyID Parameter Enables SQL Injection
Organizations using ESAFENET CDG should restrict access to the affected endpoint and patch as soon as remediation is available. Public exploit availability warrants an urgent review of logs for suspicious keyid requests.
CVE-2026-18859 affects ESAFENET CDG through version 20260615. Remote manipulation of the keyid argument in /CDGServer3/ukey/usbkey;logindojojs can result in SQL injection. The vulnerability is rated HIGH with CVSS 7.3, and the exploit is publicly available and might be used.
🔗 Read more 🔗
Source: NVD
📞 Malformed SDP Can Crash OpenSIPS Workers
OpenSIPS operators using dialog or QoS processing on attacker-controlled SDP should upgrade to 3.6.6 or 4.0.0-rc1 immediately. Internet-facing SIP services are the highest priority.
CVE-2026-46334 is a denial-of-service vulnerability in the SDP bandwidth-line parser of OpenSIPS versions prior to 3.6.6 and 4.0.0-rc1. An unauthenticated remote attacker can send malformed SDP that corrupts metadata and crashes a worker when dialog or QoS processing clones the state. The vulnerability is rated HIGH with CVSS 8.7 and is fixed in versions 3.6.6 and 4.0.0-rc1.
🔗 Read more 🔗
Source: NVD
📡 Oversized Watcher URI Crashes OpenSIPS Presence Service
Upgrade urgently where the presence and presence_xml modules are loaded and SUBSCRIBE routing is reachable. Until patched, limit untrusted access to presence subscription handling.
CVE-2026-45809 affects watcherinfo generation in OpenSIPS versions prior to 3.6.6 and 4.0.0-rc1. A remote attacker can use a long From URI in a presence SUBSCRIBE request to overflow a fixed-size stack buffer and crash a worker process. The configuration-dependent vulnerability is rated HIGH with CVSS 8.7 and is fixed in versions 3.6.6 and 4.0.0-rc1.
🔗 Read more 🔗
Source: NVD
🗄️ Hoteam PDM DataService Vulnerable to SQL Injection
Hoteam PDM administrators should restrict the DataService endpoint and patch urgently when a fix is available. Review database and web-service logs because a public exploit is available.
CVE-2026-18854 affects Shandong Hoteam PDM Product Data Management System through 8.3.10. Manipulating the FilterString argument passed to GetStoredClassByFilter at /Base/BaseService.asmx/DataService can enable remote SQL injection. The vulnerability is rated HIGH with CVSS 7.3, and the exploit has been disclosed publicly and may be used.
🔗 Read more 🔗
Source: NVD
🧨 H3C NX15 Backend RPC Allows OS Command Injection
H3C NX15 operators should treat this as urgent, especially on remotely reachable devices. Restrict Backend RPC access immediately and apply vendor fixes as soon as they are released.
CVE-2026-18900 is an OS command injection vulnerability in the file.exec function of the /api/esps Backend RPC component in H3C NX15 V100R017. A remote attacker can manipulate the File argument to inject operating-system commands. The vulnerability is rated HIGH with CVSS 7.2, and the exploit has been made publicly available and could be used for attacks.
🔗 Read more 🔗
Source: NVD
🔥 Critical OpenSIPS URI Overflow Corrupts Global State
Any OpenSIPS deployment calling construct_uri() with untrusted input should upgrade immediately. The deterministic corruption of shared global state makes this the highest-priority OpenSIPS issue in this set.
CVE-2026-45537 affects OpenSIPS versions prior to 3.6.6 and 4.0.0-rc1. The construct_uri() function can overflow a fixed 1024-byte global buffer when processing an attacker-controlled username, corrupting adjacent global data and altering subsequent SIP routing behavior. The vulnerability is rated CRITICAL with CVSS 9.1 and is fixed in versions 3.6.6 and 4.0.0-rc1.
🔗 Read more 🔗
Source: NVD
🔓 Odysseus Authorization Flaw Exposes Private AI Data
Odysseus administrators should update to commit bf325f6 or later immediately and inspect the embedding-backend configuration for unauthorized changes. Rotate potentially exposed secrets and investigate outbound traffic to unfamiliar endpoints.
CVE-2026-70619 is a missing-authorization vulnerability in Odysseus before commit bf325f6. Authenticated non-admin users can alter the server-wide embedding backend, redirecting chat messages, RAG queries, memory entries, and vault text in plaintext to an attacker-controlled destination, or deleting the configuration to disrupt service. The vulnerability is rated HIGH with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
🛑 Remote Request Can Deny Service to open62541
Users of open62541 v.1.5.5 or earlier should prioritize upgrading or applying available mitigations, particularly in remotely reachable industrial environments. The entry provides limited technical detail, so reducing network exposure is prudent.
CVE-2026-67861 affects open62541 v.1.5.5 and earlier. A remote attacker can cause a denial of service through the UA_Client_getRemoteDataTypes component. The vulnerability is rated HIGH with CVSS 7.5.
🔗 Read more 🔗
Source: NVD