Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-42390

ZONEMD validation can be bypassed_CVE-2026-42390

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

PowerDNS Recursor 5.4.0 CVE
MEDIUM 5.3 CVE-2026-42389

Reject more queries with invalid header values_CVE-2026-42389

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

PowerDNS Recursor 5.4.0 CVE
MEDIUM 5.9 CVE-2026-42388

Missing input validation for catalog zones_CVE-2026-42388

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

PowerDNS Recursor 5.2.0 CVE
MEDIUM 5.9 CVE-2026-42387

Insufficient input validation in ZoneToCache_CVE-2026-42387

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient inpu...

PowerDNS Recursor 5.2.0 CVE
CRITICAL 9.8 CVE-2026-41120

CVE-2026-41120_CVE-2026-41120

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A lo...

Dell Wyse Management Suite CVE
MEDIUM 5.3 CVE-2026-40012

Information about ECS zero scoped answers might leak to clients that use a specific ECS_CVE-2026-40012

ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;

PowerDNS Recursor 5.2.0 CVE
HIGH 8.4 CVE-2026-2815

Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys_CVE-2026-2815

Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys

Silicon Labs SiSDK CVE
HIGH 7.5 CVE-2026-27366

WordPress MainWP Child plugin <= 6.1.1 - Broken Access Control vulnerability_CVE-2026-27366

Unauthenticated Broken Access Control in MainWP Child

MainWP MainWP Child n/a CVE
LOW 2.7 CVE-2026-12755

CVE-2026-12755_CVE-2026-12755

Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with...

Devolutions Server 2026.2.4.0 CVE
MEDIUM 5.3 CVE-2026-6432

Improper bounds validation in EmberZNet SDK_CVE-2026-6432

Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.

Silicon Labs SiSDK CVE