Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.7 CVE-2026-10805

Networkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backend_CVE-2026-10805

A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malfo...

Red Hat Multicluster Engine for Kubernetes CVE
HIGH 8.5 CVE-2026-50206

VPN Command Injection Vulnerability_CVE-2026-50206

Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.8 CVE-2026-50205

Plaintext Log Credential Leakage_CVE-2026-50205

System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 6.9 CVE-2026-49204

Hard-coded AWS Cognito Testing Accounts_CVE-2026-49204

Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 7.2 CVE-2026-49203

Unauthenticated eSIM Configuration Manipulation_CVE-2026-49203

Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or del...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.8 CVE-2026-49202

Unverified Meeting Recording Endpoints & Permissive CORS_CVE-2026-49202

Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that al...

Acer Connect M6E 5G Portable WiFi Router * CVE
CRITICAL 9.4 CVE-2026-49194

SCREEN_CLICK Authentication Bypass_CVE-2026-49194

The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive s...

Acer Connect M6E 5G Portable WiFi Router * CVE
HIGH 8.7 CVE-2026-49193

Publicly Readable AWS S3 Telemetry Buckets_CVE-2026-49193

Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.

Acer Connect M6E 5G Portable WiFi Router * CVE
MEDIUM 5.3 CVE-2026-49192

Summary Service Insecure Direct Object Reference_CVE-2026-49192

The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device...

Acer Connect M6E 5G Portable WiFi Router * CVE
CRITICAL 9.3 CVE-2026-49191

Exposed Hard-coded M3WebServer Backend API Key_CVE-2026-49191

The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.

Acer Connect M6E 5G Portable WiFi Router * CVE