Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-86510 — D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The a…

Remote | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.6 CRITICAL
CVE-2026-86509 — D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow

A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffe…

| Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
2.3 LOW
CVE-2026-82710 — Terminal escape sequence injection in mix usage_rules.search_docs via package documentati…

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in ash-project usage_rules allows a malicious package publisher to inject terminal control sequences into the output of mix…

usage_rules | Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-76977 — Clickjacking vulnerability in SAPUI5(Frame Options Allowlist)

SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing restrictions. If an authen…

sapui5 | Remote | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-76971 — Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence

Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker could cause the server to initiate arbitrary outbound requests. If processed b…

manufacturing_integration_and_intelligence | Remote | Server-Side Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.4 CRITICAL
CVE-2026-76969 — Credential disclosure in multitenant applications using SAP Cloud Application Programming…

@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially…

Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-76968 — Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manage…

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacker to access certain administrative functionality or interface and obtain sensit…

Remote | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.8 HIGH
CVE-2026-76967 — Insecure Deserialization in SAP NetWeaver Business Client

SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could …

netweaver_business_client | Misconfiguration
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-76963 — Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform

Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive system configuration informat…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-76962 — Missing Authorization check in SAP S/4HANA (Manage Bank Chains app)

SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to d…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
3.5 LOW
CVE-2026-76961 — Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Paym…

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a mali…

Remote | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
3.5 LOW
CVE-2026-76960 — Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Paym…

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests, due to this an attacker with low privileges could craft a mali…

Remote | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.6 MEDIUM
CVE-2026-76959 — Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Paym…

SAP S/4HANA Finance (Advanced Payment Management) does not perform sufficient Cross-Site Request Forgery protection on certain requests due to this an attacker with low privileges could craft a malic…

Remote | Cross-Site Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.5 HIGH
CVE-2026-76958 — XML External Entity (XXE) Vulnerability in SAP Integration Suite

SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML p…

Remote | XML External Entity
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.0 CRITICAL
CVE-2026-66768 — Improper Access Control in SAP NetWeaver (SAP GUI for Java)

SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating…

netweaver | Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.7 HIGH
CVE-2026-66767 — Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Pla…

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potenti…

netweaver_application_server_abap | Remote | Race Condition
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.8 CRITICAL
CVE-2026-58240 — Missing Authentication check in SAP NetWeaver (Message Server)

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affe…

netweaver | Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
2.2 LOW
CVE-2026-58234 — Denial of Service vulnerability in SAP Process Integration (SOAP Adapter)

SAP Process Integration (SOAP Adapter) allows a privileged user to send specially crafted requests containing deeply nested entity definitions, which under certain conditions could temporarily increa…

process_integration | Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-44766 — SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation)

SAP S/4HANA (Intercompany Matching and Reconciliation) allows a low-privileged authenticated user to inject malicious input into certain functions, which may be processed by the database without prop…

Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
10.0 CRITICAL
CVE-2026-44756 — Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request contain…

Remote | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
Showing 20 of 12514 Results