CVE-2026-0847: Critical Path Traversal Flaw in NLTK Allows Attackers to Read Arbitrary Server Files
CVE-2026-0847 — NLTK Path Traversal Vulnerability Leading to Arbitrary File Read CVE ID: CVE-2026-0847Product: Natural Language Toolkit…
continue reading..
CVE-2026-2914: Critical Elevation Flaw in CyberArk EPM Agent Lets Local Users Gain Admin Rights
CVE-2026-2914 Product: CyberArk Endpoint Privilege Manager (EPM) AgentAffected Versions: 25.10.0 and earlierSeverity: HighCVSS v3.1: 7.8 (High)CVSS v4.0:…
continue reading..
CVE-2026-27595: Unauthenticated AI Agent Flaw in Parse Dashboard Exposes Master Key, Enables Full Database Takeover
Parse Dashboard AI Agent Endpoint – Unauthenticated Master Key Access Product Name: Parse DashboardVendor / Maintainer: Parse…
continue reading..
CVE-2026-27615: Remote Code Execution Flaw in ADB Explorer Lets Attackers Run Malicious Binaries via Network Share
CVE-2026-27615 CVE ID: CVE-2026-27615Product: ADB ExplorerAffected Versions: All versions prior to Beta 0.9.26022Fixed Version: Beta 0.9.26022CVSS v3.1…
continue reading..
CVE-2026-27809: Malformed PSD Files Can Crash psd-tools — Remote DoS Risk in Image Processing Pipelines
Overview CVE ID: CVE-2026-27809Affected component: psd-tools (Python library for Adobe Photoshop PSD files)Affected versions: Versions prior to…
continue reading..
CVE-2026-27821: Critical Stack Overflow in GPAC NHML Parser Opens Door to Remote Crashes and Possible Code Execution
GPAC NHML Parser Stack Buffer Overflow Overview A stack-based buffer overflow vulnerability was identified in the NHML…
continue reading..
CVE-2026-27804: Critical Parse Server Flaw Lets Hackers Bypass Google Login Using “alg: none” JWT Trick
CVE Information CVE ID: CVE-2026-27804Severity: CriticalCVSS Score: 9.3 (Network exploitable, no authentication required, high impact on confidentiality…
continue reading..
CVE-2026-27896: High-Severity JSON Parsing Flaw in MCP Go SDK Opens Door to Protocol Bypass Risks
CVE-2026-27896 — MCP Go SDK JSON Case-Insensitive Parsing Vulnerability CVE: CVE-2026-27896Name: Go MCP SDK improper handling of…
continue reading..
CVE-2026-27952: Agenta Sandbox Flaw Enables Authenticated Users to Achieve Remote Code Execution via NumPy Introspection
Agenta Sandbox Escape via NumPy Introspection CVE ID: CVE-2026-27952Affected Product: Agenta API (self-hosted deployments)Affected Versions: All versions…
continue reading..
