Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 THN:3290E453B3D...

OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws_THN:3290E453B3DF6ABCA0E5674F76DA371F

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5t7SN4kPSfgifNku4Z0eWG5x1Dd8CIb99OAHuktz4ZGAeIrwDEnLwD9DUkRj8nStBQjzxOgWO2hfsGYI07Y...

N/A N/A THN
HIGH 7.8 DF5C4368-B596-

Exploit for Untrusted Pointer Dereference in Microsoft_DF5C4368-B596-5A56-B3D2-A29063405520

Note The NTOKernelBase in exp.cpp needs to be set by yourself...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 MS:CVE-2026-12447

Chromium: CVE-2026-12447 Heap buffer overflow in WebRTC_MS:CVE-2026-12447

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 7.1 CVE-2026-10658

Bluetooth Host ISO RX Missing SDU Header Length Validation in bt_iso_recv() Leads to DoS_CVE-2026-10658

A missing length validation in the Zephyr Bluetooth Host ISO receive path can be triggered by malformed HCI ISO data. In bt_iso_recv() (subsys/blue...

zephyrproject-rtos Zephyr * CVE
HIGH 7.1 CVE-2026-10651

Bluetooth Classic SDP parser truncation bug in bt_sdp_parse_attribute() leads to reachable assertion and possible out-of-bounds read_CVE-2026-10651

A malformed Bluetooth Classic SDP attribute can trigger a reachable assertion in Zephyr's SDP parser. In subsys/bluetooth/host/classic/sdp.c, bt_sd...

zephyrproject-rtos Zephyr * CVE
HIGH 8.2 CVE-2026-11833

CVE-2026-11833_CVE-2026-11833

Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting inform...

Yokogawa Electric Corporation FAST/TOOLS R9.01 CVE
HIGH 7.8 MS:CVE-2026-12449

Chromium: CVE-2026-12449 Use after free in Chromoting_MS:CVE-2026-12449

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.3 MS:CVE-2026-12465

Chromium: CVE-2026-12465 Insufficient validation of untrusted input in Metrics_MS:CVE-2026-12465

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
HIGH 8.8 CVE-2026-54232

vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile_CVE-2026-54232

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confus...

vllm-project vllm < 0.22.1 CVE
HIGH 7.5 CVE-2026-41523

vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution_CVE-2026-41523

vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation func...

vllm-project vllm < 0.22.0 CVE