Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.3 CVE-2026-55964

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)_CVE-2026-55964

Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usag...

wolfSSL wolfSSL 5.7.4 CVE
MEDIUM 4.2 CVE-2026-2299

Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint_CVE-2026-2299

The Mattermost Google Drive plugin before version 1.1.0 fails to validate channel membership in the file creation endpoint, allowing authenticated ...

Mattermost Mattermost Google Drive Plugin CVE
MEDIUM 6.3 CVE-2026-12340

Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation_CVE-2026-12340

Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 signature, the Subject Key Id...

wolfSSL wolfSSL 5.6.4 CVE
MEDIUM 6.3 CVE-2026-10592

Wildcard DNS SAN bypasses CA name-constraint checks_CVE-2026-10592

Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA name-constraint checks. A certificate with a wildcard DNS SAN that should be r...

wolfSSL wolfSSL 3.9.10 CVE
MEDIUM 6.3 CVE-2026-10097

ML-KEM-1024 x64 AVX2 implicit rejection failure breaks IND-CCA2 security_CVE-2026-10097

ML-KEM-1024 x64 AVX2 implicit rejection failure in the Fujisaki-Okamoto transform breaks IND-CCA2 security, allowing decapsulation to deviate from ...

wolfSSL wolfSSL 5.7.0 CVE
MEDIUM 6.3 1455C226-77CD-

Exploit for Improper Authentication in Google Android_1455C226-77CD-5803-A0CE-7D7BC815D6F6

BlueDucky Ver 2.1 Android 🦆 Thanks to all the people at HackNexus. Make sure you come join us on VC ! https://discord.gg/HackNexus NOTES: I will n...

N/A N/A GITHUBEXPLOIT
MEDIUM 6.1 CVE-2026-48942

Joomla Extension – getk2.com – Stored-XSS in K2 extension for Joomla < 2.26_CVE-2026-48942

K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both cases without HTML escaping.

getk2.com K2 extension for Joomla 1.0-2.26 CVE
MEDIUM 4.6 CVE-2026-9799

Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass_CVE-2026-9799

A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource c...

Red Hat Red Hat Build of Keycloak CVE
MEDIUM 6.5 CVE-2026-9705

Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token_CVE-2026-9705

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), coul...

Red Hat Red Hat Build of Keycloak CVE
MEDIUM 4.9 CVE-2026-9083

Keycloak: keycloak: information disclosure through arbitrary filesystem path probing_CVE-2026-9083

A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesyst...

Red Hat Red Hat Build of Keycloak CVE