Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
CVSS Score
7.4
EPSS Score
0.002
Published
2026-09-17
Memory corruption while processing rear sensor IOCTL calls.
CVSS Score
6.7
EPSS Score
0.001
Published
2026-09-17
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-09-17
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-09-17
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-09-17
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVSS Score
7.8
EPSS Score
0.002
Published
2026-09-17
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
CVSS Score
7.8
EPSS Score
0.002
Published
2026-09-17
Memory Corruption when copying large input data exceeds normal allocation limits.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-09-17
CVE-2026-76460
Known exploited
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.
CVSS Score
10.0
EPSS Score
0.008
Published
2026-09-16
Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coordinates as filesystem path components without rejected parent-directory names, and the path-containment check compared an unnormalized resolved path. An authenticated user authorized to write and delete bundles in a bucket can upload a NAR with a crafted manifest resulting in file system operations outside of the file persistence directory. Upgrading to Apache NiFi Registry 2.12.0 is the recommended mitigation, which rejects parent-directory coordinates and requires a normalized path to remain a strict child of the storage root location.
CVSS Score
7.2
EPSS Score
0.004
Published
2026-09-16


Contact Us

Shodan ® - All rights reserved