PLAINTEXT REPORT / CVE Newly published vulnerabilities and exploits. High volume by nature, which is why it lives here and not on the front page. Updated 2026-09-17 23:30 UTC. Showing the last 24h. Inspired by brutalist.report, but for infosec news. Proud supporter of the small web. An Intergalactic Robots production. https://intergalacticrobots.app/ OFFENSIVE SEQUENCE ------------------ * [26m] CVE-2026-87701: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in Microsoft Azure Cosmos DB https://www.cve.org/CVERecord?id=CVE-2026-87701 * [26m] CVE-2026-85917: CWE-918: Server-Side Request Forgery (SSRF) in Microsoft Azure AI Foundry https://www.cve.org/CVERecord?id=CVE-2026-85917 * [26m] CVE-2026-85889: CWE-306: Missing Authentication for Critical Function in Microsoft Azure AI Foundry https://www.cve.org/CVERecord?id=CVE-2026-85889 * [27m] CVE-2026-85885: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') in Microsoft Microsoft 365 Copilot https://www.cve.org/CVERecord?id=CVE-2026-85885 * [27m] CVE-2026-83944: CWE-284: Improper Access Control in Microsoft Azure Logic Apps https://www.cve.org/CVERecord?id=CVE-2026-83944 * [27m] CVE-2026-78501: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') in Microsoft Microsoft 365 Copilot's Business Chat https://www.cve.org/CVERecord?id=CVE-2026-78501 * [27m] CVE-2026-77903: CWE-290: Authentication Bypass by Spoofing in Microsoft Microsoft Dataverse https://www.cve.org/CVERecord?id=CVE-2026-77903 * [27m] CVE-2026-70200: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Microsoft Azure Logic Apps https://www.cve.org/CVERecord?id=CVE-2026-70200 * [27m] CVE-2026-70009: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Microsoft Azure ARC https://www.cve.org/CVERecord?id=CVE-2026-70009 * [27m] CVE-2026-69865: CWE-639: Authorization Bypass Through User-Controlled Key in Microsoft Azure Container Registry https://www.cve.org/CVERecord?id=CVE-2026-69865 * [27m] CVE-2026-69399: CWE-441 Unintended Proxy or Intermediary in Microsoft Azure ARC https://www.cve.org/CVERecord?id=CVE-2026-69399 * [27m] CVE-2026-68791: CWE-863: Incorrect Authorization in Microsoft Azure Machine Learning https://www.cve.org/CVERecord?id=CVE-2026-68791 * [27m] CVE-2026-55946: CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') in Microsoft Microsoft Copilot https://www.cve.org/CVERecord?id=CVE-2026-55946 * [42m] CVE-2026-93436: Missing Release of Memory after Effective Lifetime in vllm-project vllm https://www.cve.org/CVERecord?id=CVE-2026-93436 * [42m] CVE-2026-93435: Uncontrolled Recursion in NodeRedis redis-parser https://www.cve.org/CVERecord?id=CVE-2026-93435 * [1h] CVE-2026-86688: CWE-384 Session Fixation in team-alembic ash_authentication https://www.cve.org/CVERecord?id=CVE-2026-86688 * [1h] CVE-2026-76949: CWE-290 Authentication Bypass by Spoofing in team-alembic ash_authentication https://www.cve.org/CVERecord?id=CVE-2026-76949 * [1h] CVE-2026-54734: CWE-918: Server-Side Request Forgery (SSRF) in prebid prebid-server-java https://www.cve.org/CVERecord?id=CVE-2026-54734 * [1h] CVE-2026-54648: CWE-862: Missing Authorization in cubecart v6 https://www.cve.org/CVERecord?id=CVE-2026-54648 * [1h] CVE-2026-54643: CWE-862: Missing Authorization in cubecart v6 https://www.cve.org/CVERecord?id=CVE-2026-54643 * [1h] CVE-2026-54642: CWE-352: Cross-Site Request Forgery (CSRF) in cubecart v6 https://www.cve.org/CVERecord?id=CVE-2026-54642 * [1h] CVE-2026-54520: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in vmDeshpande ai-agent-automation https://www.cve.org/CVERecord?id=CVE-2026-54520 * [1h] CVE-2026-54519: CWE-862: Missing Authorization in vmDeshpande ai-agent-automation https://www.cve.org/CVERecord?id=CVE-2026-54519 * [1h] New RatHat Android malware uses AI to automate device control https://radar.offseq.com/threat/new-rathat-android-malware-uses-ai-to-automate-device-control-d21d1616bc485559 * [1h] AI agents trust MCP tool descriptions the way browsers trust TLS certs. Attackers are starting to exploit that. https://radar.offseq.com/threat/ai-agents-trust-mcp-tool-descriptions-the-way-browsers-trust-tls-certs-attackers-are-starting-to-88522cb7b8b648d4 VULDB ----- * [1h] CVE-2026-54646 | CubeCart up to 6.7.4 Maintenance maintenance.index.inc.php tablename sql injection https://www.cve.org/CVERecord?id=CVE-2026-54646 * [1h] CVE-2026-54645 | CubeCart up to 6.7.4 Product Editing products.index.inc.php RAW cross site scripting https://www.cve.org/CVERecord?id=CVE-2026-54645 * [1h] CVE-2026-54647 | CubeCart up to 6.7.4 Settings settings.index.inc.php download_expire sql injection https://www.cve.org/CVERecord?id=CVE-2026-54647 * [1h] CVE-2026-54644 | CubeCart up to 6.7.4 GUI Message classes/gui.class.php _errorMessage cross site scripting https://www.cve.org/CVERecord?id=CVE-2026-54644 * [1h] CVE-2026-93203 | Linux Kernel up to 7.2.5 batman-adv batadv_bla_add_claim race condition https://www.cve.org/CVERecord?id=CVE-2026-93203 * [1h] CVE-2026-93118 | Linux Kernel up to 7.2.5 aspeed_udc ast_udc_probe null pointer dereference https://www.cve.org/CVERecord?id=CVE-2026-93118 * [1h] CVE-2026-93201 | Linux Kernel up to 7.2.5 dm-pcache cache_pos_decode out-of-bounds https://www.cve.org/CVERecord?id=CVE-2026-93201 * [1h] CVE-2026-93204 | Linux Kernel up to 7.2.5 batman-adv batadv_dat_entry_add race condition https://www.cve.org/CVERecord?id=CVE-2026-93204 * [1h] CVE-2026-93200 | Linux Kernel up to 6.18.51/7.2.5 i3c i3c_master_set_info use after free https://www.cve.org/CVERecord?id=CVE-2026-93200 * [1h] CVE-2026-93198 | Linux Kernel up to 6.18.51/7.2.5 dm-pcache cache_writeback_fn infinite loop https://www.cve.org/CVERecord?id=CVE-2026-93198 * [1h] CVE-2026-93199 | Linux Kernel up to 6.18.51/7.2.5 i3c i3c_master_search_i3c_dev_duplicate input validation https://www.cve.org/CVERecord?id=CVE-2026-93199 * [1h] CVE-2026-93193 | Linux Kernel up to 6.18.51/7.2.5 analogix_dp analogix_dp.c rockchip_dp_drm_encoder_enable denial of service https://www.cve.org/CVERecord?id=CVE-2026-93193 * [1h] CVE-2026-93192 | Linux Kernel up to 6.12.109/6.18.51/7.2.5 V3D drm/v3d v3d_fence_create active_job/queue_lock use after free https://www.cve.org/CVERecord?id=CVE-2026-93192 * [1h] CVE-2026-93191 | Linux Kernel up to 7.2.5 Smack ipc/msg.c smack_msg_queue_msgrcv Target improper authorization https://www.cve.org/CVERecord?id=CVE-2026-93191 * [1h] CVE-2026-93188 | Linux Kernel up to 7.2.5 HID roccat out-of-bounds https://www.cve.org/CVERecord?id=CVE-2026-93188 * [1h] CVE-2026-93187 | Linux Kernel up to 7.2.5 ipc4-topology ipc4-topology.c input validation https://www.cve.org/CVERecord?id=CVE-2026-93187 * [1h] CVE-2026-93186 | Linux Kernel up to 6.12.109/6.18.51/7.2.5 CXL Mailbox cxl_mbox_cmd_ctor allocation of resources https://www.cve.org/CVERecord?id=CVE-2026-93186 * [1h] CVE-2026-93185 | Linux Kernel up to 7.2.5 ASoC rt700_sdw_remove race condition https://www.cve.org/CVERecord?id=CVE-2026-93185 * [1h] CVE-2026-93184 | Linux Kernel up to 6.12.109/6.18.51/7.2.5 fsl_audmix fsl_audmix_runtime_resume resource consumption https://www.cve.org/CVERecord?id=CVE-2026-93184 * [1h] CVE-2026-93183 | Linux Kernel up to 7.2.5 lima drivers/gpu/drm/drm_mm.c lima_vm_create allocation of resources https://www.cve.org/CVERecord?id=CVE-2026-93183 * [1h] CVE-2026-53534 | JabRef up to 6.0-alpha.5 HTTP Server /better-bibtex/cayw CAYWQueryParams.getCommand command os command injection https://www.cve.org/CVERecord?id=CVE-2026-53534 * [1h] CVE-2026-54634 | Hamlib up to 4.7.1 Send Raw Command tests/rigctl_parse.c rigctl_send_raw/rig_send_raw out-of-bounds write https://www.cve.org/CVERecord?id=CVE-2026-54634 * [1h] CVE-2026-93181 | Linux Kernel up to 7.2.5 Uncore uncore.c uncore_event_cpu_online race condition https://www.cve.org/CVERecord?id=CVE-2026-93181 * [1h] CVE-2026-93179 | Linux Kernel up to 7.2.5 Powerplay out-of-bounds https://www.cve.org/CVERecord?id=CVE-2026-93179 * [1h] CVE-2026-93178 | Linux Kernel up to 7.2.5 powerplay drm/amdgpu/pm/powerplay vddInd/vddcInd memory corruption https://www.cve.org/CVERecord?id=CVE-2026-93178 ZERO DAY INITIATIVE ------------------- * [18h] ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-26-714/