๐ ADVISORIES
-
NVIDIA Cumulus Linux and NVOS August 2026 Security Bulletin
NVIDIA issued a high-severity security bulletin for Cumulus Linux and NVOS.- Cumulus Linux and NVOS deployments are affected.
- The bulletin lists three CVEs with a CVSS score of 7.8.
- No attack method or indicators of compromise are provided.
๐ Source: nvidia.custhelp.com ยท ๐ Coverage: nvidia.custhelp.com ยท ๐ via InfraTrust Advisories
-
Dell discloses 88 third-party vulnerabilities in VPLEX
Dell disclosed 88 third-party vulnerabilities affecting VPLEX.- Dell VPLEX customers and deployments are affected.
- The advisory covers 88 vulnerabilities in multiple third-party components.
- Dell rates the issue Critical with a CVSS score of 9.8.
- The reported EPSS score is 1.7%.
๐ Coverage: dell.com ยท ๐ via InfraTrust Advisories
-
FortiWeb RADIUS Admin Flaw Enables Unauthenticated GUI and CLI Access
FortiWeb is vulnerable to unauthenticated administrative access through specific RADIUS settings.- FortiWeb deployments using Remote RADIUS Type administrator authentication are affected.
- Affected versions include 8.0.0โ8.0.2, 7.6.0โ7.6.6, 7.4.0โ7.4.11, and 7.2.0โ7.2.12.
- With the non-default Wildcard setting enabled, attackers can log in to the FortiWeb GUI and CLI using random usernames and passwords.
- CVE-2026-26035 is an improper authentication flaw (CWE-287) that can grant administrative control of the web application firewall.
๐ Source: fortiguard.fortinet.com ยท ๐ Coverage: cycognito.com ยท ๐ via InfraTrust Advisories
-
Fortinet appliances affected by HTTP/2 Bomb memory-exhaustion flaw
CVE-2026-49975
Fortinet disclosed a high-severity HTTP/2 memory-exhaustion flaw affecting three products.- FortiProxy, FortiPAM, and FortiSwitch Manager appliances are affected.
- The flaw, CVE-2026-49975, can cause denial of service by exhausting system memory.
- Affected versions include FortiProxy 7.2, 7.4.0โ7.4.14, and 7.6.0โ7.6.6; FortiPAM 1.0โ1.8 and 1.9.0โ1.9.1; and FortiSwitch Manager 7.2.0โ7.2.9.
- An unauthenticated remote attacker sends specially crafted HTTP/2 header frames that trigger disproportionate memory allocation in Apache mod_http2.
- Public proof-of-concept exploit code is available; Fortinet reported no known exploitation in its products at disclosure.
๐ Source: fortiguard.fortinet.com ยท ๐ Coverage: 1898advisories.burnsmcd.com ยท ๐ via InfraTrust Advisories
-
Dell BIOS Update Addresses 16 High-Severity Vulnerabilities
Dell disclosed 16 vulnerabilities affecting multiple Client Platform BIOS models.- Dell Client Platform systems, including Alienware, Dell G15, Aurora, and ChengMing models, are affected.
- The flaws affect BIOS components involving Intel chipset, processor, UEFI, and Xeon firmware.
- Affected BIOS versions vary by model; remediated releases include Dell G15 5530 BIOS 1.34.0 and Alienware 16 Area-51 BIOS 2.5.0.
- Dell rated the advisory High, and malicious users could exploit the vulnerabilities to compromise affected systems.
๐ Coverage: dell.com ยท ๐ via InfraTrust Advisories
-
Dell warns of two high-severity AMD fTPM BIOS vulnerabilities
Dell disclosed two high-severity AMD fTPM vulnerabilities affecting client platforms.- Dell client systems using AMD firmware TPM are affected.
- CVE-2026-6726 can enable forged TPM attestations through information leakage.
- CVE-2026-6727 exposes RSA-OAEP operations to a timing side-channel attack.
- Exploitation requires local access with elevated privileges.
- Affected AMD families include Ryzen 3000โ9000, Ryzen AI, Threadripper, EPYC, and embedded processors.
๐ Source: dell.com ยท ๐ Coverage: computerbase.de ยท ๐ via InfraTrust Advisories
-
fortinet-kernel-driver-heap-overflow โ InfraTrust Advisories
-
fortinet-fgfm-authentication-weakening โ InfraTrust Advisories
-
๐ Source for NVIDIA Triton Inference Server Flaws Include Critical Path-Traversal DoS โ nvidia.custhelp.com
๐ต๏ธ RESEARCH & DEEP DIVES
- Kimi Desktop updater can install unverified code
Kimi Desktop ships with an updater that can install unverified code.- Kimi Desktop users on macOS and Windows are affected.
- The desktop app's updater can install unverified code.
- The updater is accessible through group chat functionality.
๐ Coverage: runtimewire.com ยท ๐ via r/netsec
๐ CVEs & KEV
-
CVE-2026-21580 โ CVSS 9.3 โ This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Bypass vulnerability affects multiple components and allows attackers to execute arbitrary code and escalate privileges.
-
CVE-2026-21582 โ CVSS 8.8 โ This High severity BASM (Broken Authentication & Session Management) vulnerability enables attackers to bypass authentication mechanisms and hijack user sessions.
-
CVE-2026-50186 โ CVSS 8.8 โ 4gaBoards: Path Traversal leading to Arbitrary File Read and Deletion in Boards software allows attackers to access and remove sensitive files.
-
CVE-2026-50191 โ CVSS 8.8 โ 4gaBoards: Pre-Account Takeover via SSO Email Linkage enables attackers to hijack accounts before users complete registration.
-
CVE-2026-52876 โ CVSS 8.8 โ Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback allows execution of malicious files through media player integration.
-
CVE-2026-52872 โ CVSS 8.8 โ Streambert: Local File Exfiltration and Overwrite via Subtitle file: Protocol handler flaw enables data theft and file manipulation.
-
CVE-2026-52854 โ CVSS 8.6 โ mediawiki/maps: Stored XSS through the overlays parameter in the display_map function allows persistent cross-site scripting attacks.
-
CVE-2026-52875 โ CVSS 8.4 โ Streambert: Arbitrary Directory Creation and File Manipulation via Backup Handler enables attackers to create directories and manipulate files.
-
CVE-2026-52877 โ CVSS 8.3 โ Streambert: Insecure Protocol Execution in open-external IPC Handler allows execution of untrusted protocols.
-
CVE-2026-21584 โ CVSS 7.6 โ This High severity Improper Authorization vulnerability was introduced in versions prior to 3.2.1 and allows unauthorized access to restricted functions.
-
CVE-2026-53958 โ CVSS 7.6 โ 4gaBoards: SSO Pre-Account Takeover / Hijacking via Mass Assignment enables attackers to hijack accounts using mass assignment techniques.
-
CVE-2026-52873 โ CVSS 6.9 โ Streambert: Global CSP Removal in Wyzie Redeem Window Enables Unconstrained Cross-Site Scripting attacks.
-
CVE-2026-53959 โ CVSS 6.5 โ 4gaBoards: Mass Information Disclosure (Internal PII Leakage) on /api/users through improper access controls.