Vendor Security News

Vendor security advisories, disclosures and statements from software and hardware makers about issues in their own products.

When a vendor issues its own security advisory (acknowledging a flaw, describing its impact, announcing a fix) it is usually the most authoritative account of what happened. Coverage here ranges from routine bulletins to public statements after in-the-wild exploitation. It is the direct-from-the-source counterpart to third-party CVE and exploit reporting.

Recent Vendor items

CVE-2026-101281 A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendm…
@cveNotify · Sep 29, 2026
Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings https://ift.tt/FY2QVbG
@ctinow · Sep 29, 2026
CVE-2026-18747 The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and then unconditionally strips the trailing CRC with rx_ctxt->nb->len…
@cveNotify · Sep 29, 2026
CVE-2026-18746 parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry a Block1 option. For the first block of a transfer it called init…
@cveNotify · Sep 29, 2026
CVE-2026-18417 The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's void user_data field (ctx->user_data = INT_TO_POINTER(-status) in z…
@cveNotify · Sep 29, 2026
CVE-2026-102367 mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails to validate the enabled flag when issuing new sessions. Disabled u…
@cveNotify · Sep 29, 2026
CVE-2026-102366 mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorization checks and accept arbitrary file types without validation. Att…
@cveNotify · Sep 29, 2026
CVE-2026-102365 mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page an…
@cveNotify · Sep 29, 2026
CVE-2026-102364 mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attacke…
@cveNotify · Sep 29, 2026
CVE-2026-102363 mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking info…
@cveNotify · Sep 29, 2026
CVE-2026-102362 mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by…
@cveNotify · Sep 29, 2026
CVE-2026-102361 mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. A…
@cveNotify · Sep 29, 2026
CVE-2026-101264 A vulnerability was determined in Ziroom ZHOME A0101 1.0.1.0 . Impacted is an unknown function of the file /api/ZRnetwork/set_passwd. This manipulation of the argument password1 causes…
@cveNotify · Sep 29, 2026
CVE-2026-101263 A vulnerability was found in Ziroom ZHOME A0101 1.0.1.0 . This issue affects some unknown processing of the file /api/ZRQos/set_online_client. The manipulation of the argument mac resu…
@cveNotify · Sep 29, 2026
CVE-2026-102335 Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives.…
@cveNotify · Sep 28, 2026
CVE-2026-102334 Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers…
@cveNotify · Sep 28, 2026
CVE-2026-102332 Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use pa…
@cveNotify · Sep 28, 2026
CVE-2026-101262 A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0 . This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip lea…
@cveNotify · Sep 28, 2026
CVE-2026-101261 A flaw has been found in Ziroom ZHOME A0101 1.0.1.0 . This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can le…
@cveNotify · Sep 28, 2026
CVE-2026-101260 A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0 . Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of th…
@cveNotify · Sep 28, 2026
CVE-2026-97721 A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContentAdminController of the file publiccms-parent/publiccms-core/src/m…
@cveNotify · Sep 28, 2026
CVE-2026-97818 phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php. 🎖
@cveNotify · Sep 28, 2026
CVE-2026-92357 A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the…
@cveNotify · Sep 28, 2026
CVE-2026-92356 A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Execut…
@cveNotify · Sep 28, 2026
CVE-2026-90046 In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP"…
@cveNotify · Sep 28, 2026
CVE-2026-102297 ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API…
@cveNotify · Sep 28, 2026
CVE-2026-102296 ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixe…
@cveNotify · Sep 28, 2026
CVE-2026-102281 Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a Nest…
@cveNotify · Sep 28, 2026
CVE-2026-101188 A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak p…
@cveNotify · Sep 28, 2026
CVE-2026-101093 Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft…
@cveNotify · Sep 28, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.