Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-94575 — Brocade Fabric OS RBAC Bypass Vulnerability

A logic vulnerability in Brocade Fabric OS versions before 10.0.1 web management framework allows an authenticated, low-privileged user to bypass inner Role-Based Access Control (RBAC) checks under s…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.5 HIGH
CVE-2026-87688 — Brocade Fabric OS Command Injection Vulnerability

An input validation vulnerability exists in the security certificate management component of the Brocade Fabric OS administrative management API. When processing certificate management operations, us…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.5 HIGH
CVE-2026-87687 — Brocade Fabric OS Improper Authorization Vulnerability

An authorization and input validation vulnerability exists in Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An authenticated user with restricted privileges in one Virtual Fab…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.4 HIGH
CVE-2026-87685 — Brocade Fabric OS WebTools Arbitrary File Manipulation Vulnerability

An arbitrary file manipulation vulnerability exists in the WebTools management interface of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When processing configuration transfe…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.3 HIGH
CVE-2026-87675 — Brocade Fabric OS OS Command Injection Vulnerability

An OS command injection vulnerability exists in the configuration management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When performing a configuration downloa…

fabric_operating_system fabric_os | Remote | Injection
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.5 HIGH
CVE-2026-87674 — Brocade Fabric OS Local Privilege Escalation Vulnerability

A local privilege escalation vulnerability exists in the system logging daemon of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. Insufficient access controls on internal inter-…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.0 HIGH
CVE-2026-87673 — Brocade Fabric OS OS Command Injection Vulnerability

An OS command injection vulnerability exists in maintenance command-line diagnostic utilities on Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. The binary fails to sanitize use…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.4 HIGH
CVE-2026-87667 — Brocade Fabric OS Argument Injection Vulnerability

An argument injection vulnerability exists in the configuration management command-line utility of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When executing configuration v…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
8.6 HIGH
CVE-2026-87666 — Brocade Fabric OS OS Command Injection Vulnerability

An OS command injection vulnerability exists in the time and zone management subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. When updating system timezone settings …

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.0 HIGH
CVE-2026-87660 — Brocade Fabric OS Improper Authorization and File Permission Vulnerability

An improper file permission and missing authorization vulnerability exists in the diagnostic kernel module subsystem of Brocade Fabric OS versions before 9.2.2d and 10.0.0 through 10.0.0a1. An unpriv…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
3.4 LOW
CVE-2026-107448 — Magic: The Gathering Arena Improper URI Scheme Validation Vulnerability

Magic: The Gathering Arena (Windows/Steam client; 2026.59.30.12801.127931.6 and certain later 2026.60.x builds) passes a server-supplied URL from a home-screen carousel GoToExternalUrl action directl…

| Misconfiguration
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.8 MEDIUM
CVE-2026-107446 — containerd overlaybd Integer Overflow and Out-of-Bounds Heap Access

containerd overlaybd through 1.0.18 has a do_load_index (LSMT index loading) integer overflow (and resultant out-of-bounds heap access) for index_bytes, if an untrusted overlaybd blob from a registry…

Remote | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.4 MEDIUM
CVE-2026-107445 — Rubygem-katello: katello flatpak remote repositories api cross-organization authorization…

A flaw was found in Katello where the Flatpak Remote Repositories API does not properly enforce authorization when accessing a flatpak remote repository by identifier. An authenticated user with perm…

satellite satellite hardened_images | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.3 MEDIUM
CVE-2026-107444 — Rubygem-katello: katello docker tags repositories api cross-organization authorization by…

A flaw was found in Katello where the Docker Tags repositories API does not properly enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permissio…

satellite satellite hardened_images | Remote | Authorization
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
2.1 LOW
CVE-2026-94583 — Brocade Fabric OS Race Condition Vulnerability

A race condition vulnerability exists in the request processing logic of the REST management interface on Brocade Fabric OS versions before 10.0.1. When handling concurrent incoming network managemen…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
6.8 MEDIUM
CVE-2026-94582 — Brocade Fabric OS FSPF Component Memory Buffer Overflow

A memory buffer overflow vulnerability exists in the internal diagnostic and route validation routines used by the Fabric Shortest Path First (FSPF) protocol component of Brocade Fabric OS versions b…

fabric_operating_system fabric_os | Memory Corruption
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
7.5 HIGH
CVE-2026-94578 — Brocade Fabric OS Authorization Bypass Vulnerability

Brocade Fabric OS versions before 10.0.1 contain an authorization logic vulnerability in the AAA (Authentication, Authorization, and Accounting) integration framework allows remote authenticated user…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
4.6 MEDIUM
CVE-2026-92862 — Ticket Ryutsu Center Improper Intent Handling Vulnerability

The Android application "Ticket Ryutsu Center" improperly handles custom URL schemes, allowing a malicious application to cause access to an arbitrary website via a crafted Intent.

| Server-Side Request Forgery
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.1 MEDIUM
CVE-2026-92861 — Ticket Ryutsu Center Hard-Coded Credentials Vulnerability

The Android application "Ticket Ryutsu Center" contains hard-coded credentials, which may allow an attacker to obtain an API key used by the application.

| Authentication
Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
5.3 MEDIUM
CVE-2026-87686 — Brocade Fabric OS Authentication Bypass Vulnerability

An authentication and access control bypass vulnerability exists in the web server management interface of Brocade Fabric OS versions before 10.0.1. The web dispatcher routine evaluates internal mana…

Oct 08, 2026 Oct 08, 2026
Oct 08, 2026
Oct 08, 2026
Showing 20 of 15565 Results