Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.5 MS:CVE-2026-47655

Microsoft Graph Information Disclosure Vulnerability_MS:CVE-2026-47655

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-42824

M365 Copilot Information Disclosure Vulnerability_MS:CVE-2026-42824

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose inf...

N/A N/A MSCVE
MEDIUM 6.5 MS:CVE-2026-47644

Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability_MS:CVE-2026-47644

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unaut...

N/A N/A MSCVE
MEDIUM 6.5 CVE-2026-11322

Hermes WebUI before 0.51.221 Path Traversal via Symlink Workspace Bypass_CVE-2026-11322

Hermes WebUI prior to v0.51.221 contains a path traversal vulnerability that allows attackers to escape the workspace boundary by supplying symlink...

nesquena Hermes WebUI CVE
MEDIUM 6.5 CVE-2026-8722

Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections_CVE-2026-8722

Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes...

TEAM Net::Async::Statsd::Client CVE
MEDIUM 6.8 CVE-2026-48040

netty-incubator-codec-ohttp’s Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access_CVE-2026-48040

The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) using BoringSSL's HPKE C li...

netty netty-incubator-codec-ohttp < 0.0.22.Final CVE
MEDIUM 5.4 CVE-2026-42547

IRIS Alerts Can be Falsely Attributed to Customers_CVE-2026-42547

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, use...

dfir-iris iris-web < 2.4.28 CVE
MEDIUM 4.3 CVE-2026-42543

IRIS has a Cross-Site Request Forgery (CSRF) issue_CVE-2026-42543

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 are vul...

dfir-iris iris-web < 2.4.28 CVE
MEDIUM 4.3 CVE-2026-42540

IRIS has a Mass Assignment issue_CVE-2026-42540

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 allow a...

dfir-iris iris-web < 2.4.28 CVE
MEDIUM 6.5 CVE-2026-42539

IRIS has an Excessive Data Exposure issue_CVE-2026-42539

IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 return ...

dfir-iris iris-web < 2.4.28 CVE