New

CVE-2026-33565: kernel_linux_common_modules has a Race Condition vulnerability: in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

CVE-2026-28733: filemanagement_storage_service has an use after free vulnerability: in OpenHarmony v6.0 and prior versions allow a local attacker arbitrary code execution.

CVE-2026-27766: multimedia_audio_framework has a Race Condition vulnerability: in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak.

CVE-2026-25850: filemanagement_storage_service has an improper preservation of permissions vulnerability: in OpenHarmony v6.0 and prior versions allow a local attacker cause information leak

CVE-2026-25781: kernel_liteos_a has an out-of-bounds write vulnerability: in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS and it cannot be recovered.

Updated

CVE-2026-8149: GCM chunking can lead to bad tag exception on decryption: A vulnerability in Legion of the Bouncy Castle Inc. BC-LTS on Linux, X86_64, AVX, AVX-512f. This vulnerability is associated with program files gcm128w, gcm512w. This issue affects BC-LTS: from 2.73.0 before 2.73.11.

CVE-2026-5588: PKIX draft CompositeVerifier accepts empty signature sequence as valid.: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modules). This vulnerability is associated with p...

CVE-2026-3505: Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion.: Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Java, OperatorHelper.Java. This issue affects BC-J...

CVE-2026-0636: LDAP Injection Vulnerability in LDAPStoreHelper.java: Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from 1.74 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.84.

CVE-2026-5598: Non-constant time comparisons risk private key leakage in FrodoKEM.: Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.80.1, from 1.82 before 1.84.

CISA Known Exploited Vulnerabilities

CVE-2026-42897 Microsoft Microsoft: Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

CVE-2026-20182 Cisco Catalyst SD-WAN: Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

CVE-2026-42208 BerriAI LiteLLM: BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

CVE-2026-6973 Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

CVE-2026-0300 Palo Alto Networks PAN-OS: Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.