Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-09-17
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-09-17
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-09-17
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVSS Score
7.8
EPSS Score
0.002
Published
2026-09-17
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
CVSS Score
7.8
EPSS Score
0.002
Published
2026-09-17
Memory Corruption when copying large input data exceeds normal allocation limits.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-09-17
CVE-2026-76460
Known exploited
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
CVSS Score
10.0
EPSS Score
0.008
Published
2026-09-16
Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticated user authorized to write and delete bundles in a bucket can upload a NAR with a crafted manifest resulting in file system operations outside of the file persistence directory. Upgrading to Apache NiFi Registry 2.12.0 is the recommended mitigation, which rejects parent-directory coordinates and requires a normalized path to remain a strict child of the storage root location.
CVSS Score
7.2
EPSS Score
0.004
Published
2026-09-16
Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods against the target Connector alone, without evaluating access to the Process Groups involved. The absence of Process Group authorization allowed an authenticated user with read access to a Connector to enumerate the identifiers, names, and flow registry details of version-controlled Process Groups outside the scope of granted read policies. It also allowed a user with write access to a Connector to migrate a Process Group without write access to that Process Group, copying the flow definition, referenced assets, and component state into the Connector, and leaving the source Process Group disabled and renamed. Migration excludes sensitive property values and requires the source Process Group to be stopped with empty queues, which limits the scope of exposure. Apache NiFi installations that do not implement component-level authorization policies for Process Groups are not subject to this vulnerability, because the framework enforces Connector write permissions as the security boundary. Upgrading to Apache NiFi 2.12.0 is the recommended mitigation, which filters migration sources to Process Groups the requesting user is authorized to read, and requires write access to the source Process Group when submitting a migration request.
CVSS Score
2.3
EPSS Score
0.003
Published
2026-09-16
Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Connector configuration step can apply Asset and Secret references, but framework authorization was limited to write privileges on the Connector itself. As a result of the missing authorization, an authenticated user authorized to modify a Connector, but not authorized to read a referenced Parameter Provider, could apply Secret values backed by that Parameter Provider. The same methods also accepted Asset identifiers without verifying that the Asset belonged to the Connector being configured. Apache NiFi installations that do not implement different levels of authorization across Connectors and Parameter Providers are not subject to this vulnerability, because the framework enforces write permissions on the Connector as the security boundary. Upgrading to Apache NiFi 2.12.0 is the recommended mitigation, which authorizes read access to referenced Parameter Providers and verifies Connector ownership of referenced Assets during configuration update and verification.
CVSS Score
0.5
EPSS Score
0.004
Published
2026-09-16


Contact Us

Shodan ® - All rights reserved