Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-9516

Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws_CVE-2026-9516

Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip ...

RURBAN Cpanel::JSON::XS CVE
HIGH 7.3 CVE-2026-9334

Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled_CVE-2026-9334

Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() col...

RURBAN Cpanel::JSON::XS CVE
HIGH 7.3 CVE-2026-37462

CVE-2026-37462_CVE-2026-37462

An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) vi...

n/a n/a n/a CVE
HIGH 7.8 CVE-2026-40290

OP-TEE has a Use-After-Free race in FF-A shared-memory teardown_CVE-2026-40290

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZo...

OP-TEE optee_os >= 3.16.0, < 4.11.0 CVE
HIGH 8.8 CVE-2026-36608

CVE-2026-36608_CVE-2026-36608

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows UPnP AddPortMapping to forward external ports to the router's own admin inte...

Mercusys Mercusys AC12G AC12G(EU)_V1_200909 CVE
HIGH 8.8 CVE-2026-36607

CVE-2026-36607_CVE-2026-36607

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 allows unauthenticated brute-force attacks via the TDDP password change endpoint (c...

Mercusys Mercusys AC12G AC12G(EU)_V1_200909 CVE
HIGH 7.1 CVE-2026-36606

CVE-2026-36606_CVE-2026-36606

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups with a hardcoded DES key using single DES in ECB mod...

n/a n/a n/a CVE
HIGH 8.6 CVE-2026-20230

CVE-2026-20230_CVE-2026-20230

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified C...

Cisco Cisco Unified Communications Manager N/A CVE
HIGH 8.4 CVE-2026-7888

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction._CVE-2026-7888

Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that la...

Concrete CMS Concrete CMS 5.0 CVE
HIGH 8.8 472EEC26-F9C7-

coruna_472EEC26-F9C7-50CA-A4D6-2E1879CAC2F3

iOS Orchestrator — Coruna Web server, C2 listener, and interactive shell for the Coruna exploit chain CVE-2024-23222. Targets Safari on iOS 13–17.2...

N/A N/A GITHUBEXPLOIT