Vendor Security News

Vendor security advisories, disclosures and statements from software and hardware makers about issues in their own products.

When a vendor issues its own security advisory — acknowledging a flaw, describing its impact, or announcing a fix — it is usually the most authoritative account of what actually happened. This feed tracks vendor-issued advisories and statements across the ecosystem, from routine security bulletins to public responses following in-the-wild exploitation. It is the direct-from-the-source counterpart to third-party CVE and exploit reporting.

Recent Vendor items

CVE-2026-86172 A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID result…
@cveNotify · Sep 6, 2026
CVE-2026-86171 A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument ID lea…
@cveNotify · Sep 6, 2026
DeathShotXD/0xM0nCrush: Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust. https://github.com/DeathShotXD/0xM0nCrush 🎖
@malwr · Sep 6, 2026
CVE-2026-86170 A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID causes…
@cveNotify · Sep 6, 2026
CVE-2026-86167 A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argum…
@cveNotify · Sep 6, 2026
CVE-2026-86166 A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a…
@cveNotify · Sep 6, 2026
CVE-2026-86165 A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/ur…
@cveNotify · Sep 6, 2026
CVE-2026-86164 A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of the argument I…
@cveNotify · Sep 6, 2026
CVE-2026-86163 A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argument ID leads…
@cveNotify · Sep 6, 2026
CVE-2026-86162 A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument…
@cveNotify · Sep 6, 2026
CVE-2026-86161 A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation…
@cveNotify · Sep 6, 2026
CVE-2026-86160 A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of t…
@cveNotify · Sep 6, 2026
CVE-2026-86159 A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql…
@cveNotify · Sep 6, 2026
CVE-2026-85046 Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity:…
@cveNotify · Sep 6, 2026
CVE-2026-6554 libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations.…
@cveNotify · Sep 5, 2026
CVE-2026-6244 libpcap BPF interpreter for the 'div #k ' and 'mod #k ' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can…
@cveNotify · Sep 5, 2026
CVE-2026-31912 libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates…
@cveNotify · Sep 5, 2026
CVE-2026-31911 libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS proce…
@cveNotify · Sep 5, 2026
CVE-2026-18313 rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory e…
@cveNotify · Sep 5, 2026
CVE-2026-18238 The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the c…
@cveNotify · Sep 5, 2026
CVE-2026-0799 In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does no…
@cveNotify · Sep 5, 2026
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code https://ift.tt/f2nCQ3D
@ctinow · Sep 5, 2026
A critical VMware flaw can turn local VM admin access into host code execution.Broadcom fixed CVE-2026-59346 and an HGFS flaw in Workstation and Fusion 26H1u1. Both affect 25H2 and 26H1, with no worka…
@thehackernews · Sep 5, 2026
CVE-2026-76139 A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This scri…
@cveNotify · Sep 5, 2026
CVE-2026-86145 PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly…
@cveNotify · Sep 5, 2026
CVE-2026-76139 A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This scri…
@cveNotify · Sep 5, 2026
CVE-2026-86197 Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping…
@cveNotify · Sep 5, 2026
CVE-2026-86196 Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset to…
@cveNotify · Sep 5, 2026
CVE-2026-86195 grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but f…
@cveNotify · Sep 5, 2026
CVE-2026-86194 Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restric…
@cveNotify · Sep 5, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.