🕵️ RESEARCH & DEEP DIVES
-
Knot Resolver before 6.4.1 vulnerable to remote code execution via heap buffer overflow — cve.threatint.com
Knot Resolver versions before 6.4.1 are vulnerable to remote code execution via a heap buffer overflow.- Applies to Knot Resolver versions before 6.4.1
- Vulnerability is a heap-based buffer overflow in the DNS-over-QUIC (DoQ) receive path
- Allows remote code execution without user interaction or privileges
- CVSS 3.1 score 8.1 with network attack vector and high impact on integrity
-
Redis before 8.8.0 vulnerable to RCE via RESTORE command due to double free bug — cve.threatint.com
Redis versions before 8.8.0 allow remote code execution via a RESTORE command exploit.- Applies to Redis versions before 8.8.0
- Vulnerability in RESTORE command when an authenticated attacker executes it
- Double free occurs when the same NACK is referenced by multiple consumers and deleted via XGROUP DELCONSUMER
- Exploit leads to remote code execution due to incomplete fix of CVE-2026-25243
- Requires authentication and high complexity (CVSS 7.5, AV:N/AC:H/PR:L/UI:N)
🔓 CVEs & KEV
- CVE-2026-61884 — CVSS 9.8 — Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path
- CVE-2026-60134 — CVSS 8.8 — Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking
- CVE-2026-61892 — CVSS 8.8 — Weintek cMT3092X Incorrect Permission Assignment for Critical Resource
- CVE-2026-66337 — CVSS 6.5 — Libsoup: heap buffer over-read via integer underflow in soup_filter
- CVE-2026-66339 — CVSS 6.5 — Libsoup: proxy credentials leak to destination server via proxy-auth header
- CVE-2026-61886 — CVSS 6.5 — Weintek cMT3092X Plaintext Storage of a Password
- CVE-2026-60135 — CVSS 6.5 — Weintek cMT3092X Incorrect User Management
- CVE-2026-66338 — CVSS 5.4 — Libsoup: http request smuggling via permissive chunk-size parsing
- CVE-2026-55985 — CVSS 4.3 — Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information
- CVE-2026-16280 — CVSS — GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset function