By year

Vulnerabilities disclosed in 2026

CVEs published in 2026 with SEC.co analysis.

8541 published vulnerabilities · page 19 of 86

  • CVE-2023-54353HIGH 7.8

    Chromacam 4.0.3.0 has a vulnerability in how it registers and starts its PsyFrameGrabberService. The service path is not properly enclosed in quotes, meaning Windows will search for and execute the first matching executable it finds in the path sequence. An attacker with local write access can place a malicious executable (named Program.exe or PsyFrameGrabberService.exe) in a directory that Windows checks before the legitimate service, causing their malicious code to run with the highest system privileges (LocalSystem) each time the system boots or the service restarts.

  • CVE-2025-12694HIGH 7.8

    A flaw in Forcepoint VPN Client for Windows allows any logged-in user without administrator rights to gain full system-level (SYSTEM) access. An attacker with a regular user account can exploit this locally to take complete control of the machine. The vulnerability affects VPN Client version 6.11.3 and all earlier versions.

  • CVE-2025-14098HIGH 7.8

    Avira Antivirus contains a critical flaw in its scanning engine that can be triggered when examining a specially crafted MS-DOS executable file. The vulnerability stems from an integer overflow that causes the engine to write data beyond the bounds of a heap buffer. An attacker can exploit this by tricking a user into scanning a malicious file, potentially leading to arbitrary code execution with the privileges of the antivirus process or crashing the antivirus engine entirely. This affects Windows, macOS, and Linux installations.

  • CVE-2025-22424HIGH 7.8

    A vulnerability in Android allows a user with local access to view images that should be restricted to other users. The flaw stems from insufficient validation of user input across multiple code locations. While this requires someone already on the device and user interaction to exploit, it can lead to privilege escalation, meaning an attacker could gain elevated access to sensitive data and system resources.

  • CVE-2025-22426HIGH 7.8

    CVE-2025-22426 is a privilege escalation vulnerability in Android's ComputerEngine component that allows a local attacker with basic user-level access to bypass security boundaries and access resources (URIs) belonging to other users on the same device. The flaw stems from a logic error in multiple functions within ComputerEngine.java that fails to properly enforce cross-user access controls. An attacker needs only local access to the device and their own user account—no special permissions or user interaction required—making this a straightforward path to elevated privileges.

  • CVE-2025-24815HIGH 7.8

    Nokia MantaRay NM contains a file upload vulnerability that fails to properly validate uploaded file types. An authenticated user with local access could upload malicious files to the system, potentially leading to unauthorized code execution or system compromise. The vulnerability requires valid credentials but poses significant risk once an attacker is inside the network perimeter.

  • CVE-2025-26418HIGH 7.8

    A vulnerability in Android's device management system allows a local attacker with basic app permissions to bypass the user confirmation dialog that normally protects account additions on managed devices. This enables privilege escalation without requiring any special system access or user interaction. The flaw stems from a missing permission check in the CarDevicePolicyService component.

  • CVE-2025-31272HIGH 7.8

    A vulnerability in macOS allows locally authenticated applications to circumvent built-in launch constraint protections—security mechanisms designed to prevent unauthorized code execution. An attacker with local access could potentially run malicious code with elevated system privileges by exploiting a weakness in how these protections are enforced. Apple has patched this issue in macOS Sequoia 15.4 with stricter validation checks.

  • CVE-2025-32348HIGH 7.8

    CVE-2025-32348 is a privilege escalation vulnerability affecting Android that allows a local attacker to launch background activities without proper permission validation. An attacker with basic user-level access can exploit this flaw to gain elevated privileges on the device—no special capabilities or user interaction required. The vulnerability exists across multiple code paths where permission checks are missing, creating a consistent attack surface.

  • CVE-2025-41278HIGH 7.8

    A memory read vulnerability exists in Waterfall Security's WF-500 RX Host (version 7.10.0.0 R2601141040) that allows an attacker with access to the TX Host to execute arbitrary code. The flaw stems from improper memory access controls, enabling an authenticated insider to move laterally within the Waterfall appliance and gain control of the receive-side components. This is a serious concern for organizations using Waterfall's unidirectional security gateways, as it undermines the trust boundary between the TX and RX sides of the architecture.

  • CVE-2025-41280HIGH 7.8

    Waterfall Security's WF-500 RX Host contains a path traversal vulnerability (Zip Slip) that allows attackers who have already gained access to the TX Host to execute arbitrary code on the RX Host, provided MySQL connector functionality is configured and file compression is enabled. The vulnerability stems from improper handling of file paths during decompression operations, enabling attackers to write files outside their intended directory. This is a privilege escalation concern within an already-compromised environment rather than an initial access vector.

  • CVE-2025-41281HIGH 7.8

    Nozomi Networks Labs discovered a code execution vulnerability in Waterfall's WF-500 RX Host that allows attackers already inside a network to run arbitrary commands. The vulnerability is triggered when a MySQL connector is configured and an attacker with access to the connected TX Host sends malicious input. This is a local privilege escalation scenario where internal network access is the prerequisite for exploitation.

  • CVE-2025-48570HIGH 7.8

    A vulnerability in Android's PipTaskOrganizer component allows a malicious application with basic system privileges to launch activities from the background without user interaction. An attacker exploiting this flaw could escalate their privileges within the system, potentially gaining access to sensitive functionality or data. The vulnerability stems from a confused deputy issue—where a trusted system component is tricked into performing privileged actions on behalf of an unprivileged attacker.

  • CVE-2025-48617HIGH 7.8

    A permissions bypass vulnerability exists in Android's CarrierConfigLoader that allows an app with basic user-level access to escalate its privileges by circumventing UID validation checks. An attacker doesn't need special system permissions or user interaction to exploit this—just the ability to run code on the device with standard app-level rights. This means a malicious app could gain unauthorized access to sensitive functionality normally restricted to system components.

  • CVE-2025-48643HIGH 7.8

    CVE-2025-48643 is a high-severity local privilege escalation vulnerability affecting Google Android. An attacker with basic user-level access to a device can exploit improper input validation in the Android provisioning system to gain full system privileges without needing to execute additional code or interact with the user. Once exploited, the attacker gains complete control over the device, including access to all data and system functions.

  • CVE-2025-48649HIGH 7.8

    CVE-2025-48649 is a local privilege escalation vulnerability affecting Google Android in which an attacker with limited user privileges can reset user-selected permission settings, effectively bypassing the permissions model that Android uses to protect sensitive device capabilities. Because no additional privileges are needed and user interaction is not required, any application with basic local access can trigger this issue to gain unauthorized access to protected device functions—a significant departure from Android's intended permission architecture.

  • CVE-2025-48652HIGH 7.8

    A logic flaw in Android's application installation validation code allows a local attacker to bypass Mobile Device Management (MDM) security policies. An attacker with local access to the device can exploit this vulnerability to gain elevated privileges without requiring additional permissions or user interaction. MDM policies are a key security control for organizations managing corporate Android devices, making this bypass a significant concern for enterprise environments.

  • CVE-2025-56814HIGH 7.8

    OpenCPN, a navigation software widely used in maritime and recreational boating contexts, contains a vulnerability in how it executes system commands. When the software calls the wxExecute() function, it does not properly sanitize user-supplied input, allowing an attacker with local system access to inject shell commands and run arbitrary code with the privileges of the user running OpenCPN. This is a local privilege escalation risk that requires an attacker to first have access to the affected system.

  • CVE-2025-59604HIGH 7.8

    CVE-2025-59604 is a memory corruption vulnerability affecting Qualcomm Snapdragon processors across multiple generations. The flaw occurs during memory copy operations when a null pointer is dereferenced, causing invalid writes to memory. An attacker with local access to a device can exploit this to gain elevated privileges and potentially read or modify sensitive data. The vulnerability is rated HIGH severity and requires local execution context, meaning an attacker must already have a foothold on the device.

  • CVE-2025-59605HIGH 7.8

    CVE-2025-59605 is a memory corruption flaw affecting Qualcomm wireless and networking chipsets. When a device processes identifier strings longer than designed, the software fails to properly validate input length, allowing the overflow to corrupt adjacent memory regions. An attacker with local access and standard user privileges can exploit this to read sensitive data, modify system behavior, or crash the device. The vulnerability requires direct local access and cannot be exploited remotely.

  • CVE-2025-59606HIGH 7.8

    CVE-2025-59606 is a memory corruption vulnerability affecting multiple Qualcomm chipsets and wireless components. The flaw occurs when a device exhausts heap memory during secure data initialization, causing the firmware to write to invalid memory locations. An attacker with local access and limited privileges can exploit this to crash the system or potentially execute code with elevated permissions. This is a local privilege escalation risk rather than a remote attack vector.

  • CVE-2025-60464HIGH 7.8

    A use-after-free vulnerability exists in GPAC Project's MP4Box tool, specifically in code that processes supplemental enhancement information (SEI) data from MPEG-2 transport stream files. An attacker can craft a malicious MPEG-2 TS file that, when processed by vulnerable versions of MP4Box, triggers a memory safety error leading to denial of service. The application crashes when attempting to access memory that has already been freed, preventing legitimate media processing tasks.

  • CVE-2025-7002HIGH 7.8

    Avira Antivirus contains a vulnerability in its scanning engine that triggers when processing a specially crafted PDF file. The flaw allows an attacker to read data from memory locations outside the intended buffer, potentially leading to either arbitrary code execution on the infected system or a crash of the antivirus engine itself. This is a local attack—the malformed PDF must reach the scanner on a user's machine, typically via email, web download, or file share. The vulnerability affects Windows, macOS, and Linux installations running engine versions prior to 8.3.70.68.

  • CVE-2025-7003HIGH 7.8

    Avira Antivirus contains a flaw in its scanning engine that can crash or potentially allow code execution when it processes a specially crafted PDF file. The vulnerability exists in how the engine allocates and reads memory while parsing malformed PDF content. Any user on a Windows, macOS, or Linux system running an affected version of Avira could trigger this by opening or scanning a malicious PDF, even without administrator privileges. The issue affects all Avira Antivirus builds before version 8.3.70.56.

  • CVE-2025-7004HIGH 7.8

    A heap buffer overflow flaw exists in multiple antivirus products from Gen Digital (Avast, AVG, and Norton) across Windows, macOS, and Linux. When the antivirus engine scans a deliberately malformed Windows PE (executable) file, it can write data beyond allocated memory boundaries. An attacker who can trick a user into opening a malicious file on a system running vulnerable antivirus software could either crash the antivirus process entirely or, in some cases, execute arbitrary code with the privileges of that process. The vulnerability is resolved through an automatic virus definition update; once your antivirus definitions reach build VPS 25040308 or later, you are protected regardless of which Gen Digital product you use.

  • CVE-2025-7008HIGH 7.8

    Avast and its sister antivirus products (AVG, Norton, Avast One, and Avast Business) contain a memory safety flaw in their scanning engine that can be triggered by a specially crafted Windows executable file. When the antivirus scans such a file, it may read memory outside the intended buffer, potentially allowing an attacker with local access to execute code or crash the antivirus process itself. The vulnerability exists in the engine's handling of .NET metadata within PE files and is distributed across multiple consumer and business antivirus products via a shared Gen Digital virus definition update. The good news: updating virus definitions to build 25021310 or later eliminates the risk, regardless of which Gen Digital product you're running.

  • CVE-2025-7009HIGH 7.8

    A heap buffer overread vulnerability exists in Avast Antivirus and related products from Gen Digital. When the antivirus engine scans a specially crafted Windows PE file, it can read beyond allocated memory boundaries, potentially allowing an attacker with local access to crash the antivirus process or execute code with the privileges of the scanning service. The vulnerability is patched through automatic virus definition updates; users running the latest virus definition builds (VPS 25021310 and later) are protected regardless of product version.

  • CVE-2025-7011HIGH 7.8

    A heap memory error in antivirus software from Avast, AVG, Norton, and related Gen Digital products can cause the antivirus to crash or potentially execute code when scanning specially crafted zip files containing malformed XML. The vulnerability affects Windows, macOS, and Linux systems running older virus definition builds. Users are vulnerable only if their antivirus definitions are outdated; installing the patched definition build resolves the issue across all affected products that share this scanning engine.

  • CVE-2025-7017HIGH 7.8

    A flaw in Avira's antivirus scanning engine allows a specially crafted Windows installer (MSI) file to trigger a memory corruption issue. When scanned, this malformed file can crash the antivirus process or potentially enable an attacker to execute code with the privileges of the antivirus engine—typically system-level on Windows. The vulnerability requires user interaction (opening or scanning the malicious file) but no special privileges to exploit.

  • CVE-2025-71326HIGH 7.8

    AVAST Antivirus version 25.11 has a local privilege escalation vulnerability affecting its SecureLine service. The vulnerability stems from an unquoted service path—a configuration weakness where the service executable path lacks quotation marks. This allows a non-privileged local user to place a malicious executable with a specially crafted name in a directory that Windows searches before finding the actual service binary. When the service starts, it executes the attacker's code with SYSTEM-level privileges instead of the legitimate application. An attacker with basic local access can escalate from a standard user account to full system control.

  • CVE-2025-7406HIGH 7.8

    CVE-2025-7406 is a privilege escalation flaw in Nokia MantaRay NM that allows a local administrator to gain full root access to the system. An attacker who already has administrative privileges on the host can exploit a misconfigured sudo policy to execute arbitrary commands with root-level permissions, bypassing normal access controls. This is a local-only attack requiring existing administrative credentials, but it completely breaks the privilege boundary once successful.

  • CVE-2025-9032HIGH 7.8

    Avira Antivirus contains a memory safety flaw that triggers when the scanning engine processes a specially crafted Windows executable file. An attacker who tricks a user into opening a malformed PE file can crash the antivirus process or potentially execute code with the privileges of the user running the scanner. The vulnerability affects Windows, macOS, and Linux systems running older Avira engine builds.

  • CVE-2025-9033HIGH 7.8

    Avira Antivirus contains a memory handling flaw that can be triggered when the engine scans a specially crafted PDF file. The vulnerability allows an attacker to either execute code on the system with the privileges of the scanning process or crash the antivirus engine, disabling its protection. This affects Windows, macOS, and Linux users running vulnerable versions of Avira Antivirus.

  • CVE-2026-0009HIGH 7.8

    A logic error in Android allows a local attacker to hijack touch input through tapjacking attacks, potentially gaining elevated privileges on the device. No special permissions or user interaction are required for exploitation, making this a direct path to privilege escalation for any app already running on the compromised system.

  • CVE-2026-0019HIGH 7.8

    CVE-2026-0019 is a privilege escalation vulnerability in Android's SettingsLib component that allows a local attacker with basic user-level access to disable critical system components and escalate their privileges to a higher level of control. The vulnerability stems from a logic error in the code and requires no user interaction to exploit, making it a straightforward attack vector for any app or process running on an affected device.

  • CVE-2026-0036HIGH 7.8

    CVE-2026-0036 is a tapjacking vulnerability in Android's StageCoordinator animation handler that allows a malicious app to escalate privileges without requiring user interaction or special permissions. An attacker with a local account on the device can overlay transparent windows to intercept touch events or manipulate the animation state, gaining unauthorized access to sensitive device functions and data. The vulnerability affects multiple Android versions and is rated HIGH severity due to its direct path to privilege escalation.

  • CVE-2026-0045HIGH 7.8

    A logic error in Android's Bluetooth RFCOMM connection handling allows a local attacker to bypass the bonding requirement for secure connections. An attacker with local access can escalate privileges without needing special permissions or user interaction, potentially gaining full control over sensitive device functions protected by Bluetooth pairing.

  • CVE-2026-0063HIGH 7.8

    A logic error in Android's phone service management allows a local attacker with basic user privileges to bypass carrier restrictions on a device. The vulnerability exists in code that controls which carriers are allowed to operate on the phone, and exploiting it requires only local access—no special permissions, user interaction, or additional steps. An attacker who gains a foothold on the device can remove or alter these carrier controls, potentially hijacking the device's cellular identity or enabling unauthorized network operations.

  • CVE-2026-0068HIGH 7.8

    A flaw in Android's PackageInstallerService allows an attacker to uninstall a Device Policy Controller (DPC) app—security software that enforces organizational policies on managed devices—without the Device Owner's knowledge or consent. The vulnerability stems from a synchronization gap between runtime state and persistent storage. An attacker would need to trick a user into installing a malicious app, after which the flaw could be exploited to remove critical management controls. This is particularly dangerous in corporate environments where DPC apps enforce compliance, security policies, and data protection.

  • CVE-2026-0071HIGH 7.8

    CVE-2026-0071 is a privilege escalation vulnerability in Android's SettingsLib component. A flaw in permission-checking logic allows a local attacker with basic user privileges to escalate to higher system permissions without needing to interact with the user or perform any additional actions. This is a logic error—not a memory corruption or injection flaw—making it a relatively straightforward vulnerability for attackers to exploit once they gain initial local access.

  • CVE-2026-0072HIGH 7.8

    A missing permission check in Android's input method manager allows a local attacker with minimal privileges to escalate their access and take full control of the affected device. No user action is required to exploit this flaw, making it a practical risk in multi-user or compromised environments.

  • CVE-2026-0076HIGH 7.8

    CVE-2026-0076 is a local privilege escalation vulnerability in Android's ResourceTypes.cpp component. An attacker with local access to a device can trigger an out-of-bounds memory read through a flawed bounds check in the validateNode function. Successful exploitation allows the attacker to escalate privileges without requiring additional permissions or user interaction, potentially gaining elevated system access.

  • CVE-2026-0077HIGH 7.8

    CVE-2026-0077 is a privilege escalation vulnerability in Android's ActivityRecord component that allows a local attacker with limited user privileges to launch background applications and gain elevated system access. The flaw stems from a logic error in the resumeConfigurationDispatch function that fails to properly validate or constrain application launch permissions. No special privileges or user interaction are required for exploitation, making this a straightforward attack vector for any app running on an affected device.

  • CVE-2026-0078HIGH 7.8

    A flaw in Android's device policy management system allows a local user to escalate their privileges by exploiting improper validation of proxy configuration settings. The vulnerability exists in how the system persists global proxy changes, creating a state mismatch that can be leveraged without requiring special permissions or user interaction. An attacker with basic local access can trigger the flaw to gain elevated system privileges.

  • CVE-2026-0081HIGH 7.8

    CVE-2026-0081 is a local privilege escalation flaw in Android's NFC (Near Field Communication) subsystem. An attacker with local access can forge NFC events by exploiting a missing permission check, allowing them to elevate their privileges without needing special system permissions or user interaction. This is a significant risk for multi-user or enterprise-managed Android devices where lateral movement or privilege abuse could unlock sensitive functionality.

  • CVE-2026-0082HIGH 7.8

    A flaw in Android's NFC (Near Field Communication) dispatcher allows a locally authenticated app to automatically gain special permissions it shouldn't have through an insecure default setting. An attacker with basic app-level access can exploit this without user interaction to escalate their privileges and potentially compromise confidentiality, integrity, and availability of system data. This is a local-only threat but poses meaningful risk in multi-app environments.

  • CVE-2026-0087HIGH 7.8

    A logic error in Android's domain verification service allows a local attacker to hijack app links associated with arbitrary applications. By exploiting this flaw, an attacker can redirect app links to malicious apps, potentially intercepting sensitive user actions or data. The vulnerability requires local access but no special permissions or user interaction, making it a meaningful escalation path on compromised or personally-owned devices.

  • CVE-2026-0088HIGH 7.8

    A flaw in Android's certificate installer component allows a malicious app with basic system privileges to bypass security dialogs that normally protect sensitive operations. By exploiting misleading UI presentation, an attacker can escalate their permissions without user knowledge or interaction. The vulnerability is particularly dangerous because it requires no special execution rights—a standard app can trigger it.

  • CVE-2026-0089HIGH 7.8

    CVE-2026-0089 is a vulnerability in Android's PackageInstallerService that allows a local attacker with basic user-level permissions to bypass security checks and install applications without proper verification. Because the vulnerability exists in multiple functions that lack proper permission validation, an attacker can escalate their privileges by sidestepping the normal app installation safeguards. No user interaction or special device access is required to exploit this flaw once an attacker has obtained standard user privileges on the device.

  • CVE-2026-0091HIGH 7.8

    A privilege escalation vulnerability exists in Android where an over-privileged shell user can execute arbitrary code within the launcher process. An attacker with local access can exploit this weakness to gain elevated privileges without needing special execution rights or user interaction. This is a local-only threat that targets the core launcher functionality central to Android's user interface and app management.

  • CVE-2026-0093HIGH 7.8

    CVE-2026-0093 is a local privilege escalation vulnerability affecting Google Android. The flaw stems from misleading user interface elements that obscure the true nature of certain operations, potentially tricking users into granting elevated permissions. An attacker with local access to the device can exploit this weakness to escalate privileges without needing special system permissions beforehand, and notably, without requiring any user interaction during the actual exploitation phase. The vulnerability allows an attacker to read, modify, or delete sensitive data and potentially take control of affected system functions.

  • CVE-2026-0094HIGH 7.8

    A flaw in Android's KeyChain component allows a local attacker with user-level privileges to manipulate the certificate approval interface in a way that tricks the system into granting access to certificates without explicit user consent. The vulnerability stems from misleading or incomplete UI messaging in the getApplicationLabel function, enabling privilege escalation entirely through local interaction. No special permissions or user action is required to exploit it once initiated.

  • CVE-2026-0096HIGH 7.8

    CVE-2026-0096 is a local privilege escalation vulnerability in Android's ForgetDeviceDialogFragment that allows an attacker with local access to manipulate or bypass a device-forget confirmation flow due to misleading UI elements. The vulnerability requires no user interaction to exploit and can result in unauthorized privilege escalation on the affected device.

  • CVE-2026-0098HIGH 7.8

    CVE-2026-0098 is a local privilege escalation vulnerability in Android's package-calling logic that allows a malicious app to bypass restrictions on which activities it can start. The flaw stems from a confused deputy problem—the system incorrectly trusts the calling context of an app requesting activity launches. An attacker with a local app installation can exploit this without special permissions or user interaction to gain elevated privileges, potentially accessing sensitive device functions or data reserved for system components.

  • CVE-2026-0099HIGH 7.8

    A vulnerability exists in Android's host emulation manager that allows a malicious app to launch activities (screen components) from the background without proper authorization. The flaw stems from a logic error in how the system validates binding requests. While an attacker needs to be a local user with some system access already, they can exploit this to gain elevated privileges on the device. The vulnerability requires user interaction to trigger—likely through social engineering or user action within a compromised app context.

  • CVE-2026-0100HIGH 7.8

    A heap buffer overflow vulnerability exists in Android's resource loading code (LoadedArsc.cpp) that allows a local attacker with standard user privileges to write data beyond the intended buffer boundaries. This memory corruption can be exploited to gain elevated system privileges without requiring special permissions or user interaction, making it a serious local privilege escalation vector.

  • CVE-2026-0133HIGH 7.8

    CVE-2026-0133 is a local privilege escalation vulnerability in Android's ARM SMMU v3 driver. An attacker with limited user-level access can bypass a missing permission check to sign malicious Android Runtime bootclass artifacts, gaining elevated system privileges without needing special rights or user interaction. This is a kernel-level flaw that allows an unprivileged local user to escalate their permissions substantially.

  • CVE-2026-0135HIGH 7.8

    CVE-2026-0135 is a buffer read vulnerability in Android's modem component that allows an attacker with local system access to execute arbitrary code without elevated privileges. The flaw stems from inadequate boundary checking when reading memory, potentially exposing sensitive data or enabling full system compromise. Exploitation requires no user action, making it a direct threat once an attacker gains initial foothold on a device.

  • CVE-2026-0137HIGH 7.8

    CVE-2026-0137 is a use-after-free memory vulnerability in Google Android's Edge TPU (Tensor Processing Unit) driver code. An attacker with local system access can exploit this flaw to escalate privileges and gain elevated system-level control. The vulnerability resides in the kernel-level driver for the Edge TPU hardware accelerator and does not require user interaction to trigger—a malicious process running with standard local privileges can execute the attack directly.

  • CVE-2026-0138HIGH 7.8

    CVE-2026-0138 is a memory corruption vulnerability in Android's light-weighted image stabilization (LWIS) subsystem that allows a local attacker with system-level privileges to write data beyond allocated buffer boundaries. An attacker who can trigger the vulnerable code path gains the ability to escalate privileges and execute arbitrary code with system permissions. No user interaction is required—the exploit can run silently once triggered.

  • CVE-2026-0143HIGH 7.8

    A use-after-free memory flaw exists in Google Android's Light Weight Image Sensor (LWIS) event handling code. An attacker with system-level privileges can trigger this defect to corrupt memory and escalate their access, potentially running arbitrary code with elevated system privileges. No user interaction is required—the vulnerability can be exploited automatically once the attacker has obtained initial system access.

  • CVE-2026-0150HIGH 7.8

    A flaw in Google Android's EdgeTPU firmware allows a local attacker with basic user privileges to overflow a buffer and gain root-level control of the device. The vulnerability stems from an integer overflow in the ExecuteGraph command handler that fails to properly validate array bounds before writing data. No special user interaction is required—an attacker with local access can trigger the issue directly.

  • CVE-2026-0152HIGH 7.8

    A memory management vulnerability exists in Android's OSMMapPMRGeneric function that allows a local attacker to manipulate virtual memory allocation beyond intended boundaries. By exploiting a logic error in the code, an authenticated user on the device can escalate their privileges to a higher level without needing any special system permissions or user interaction. This is a serious flaw because privilege escalation on mobile devices can grant attackers access to sensitive data and system-level controls.

  • CVE-2026-0153HIGH 7.8

    A buffer overflow vulnerability exists in Android's msg_to_host_buffer.cc component where the system fails to properly validate the size of data before writing to memory. An attacker with local access to a device can exploit this flaw to write data beyond the allocated buffer, potentially gaining elevated privileges without requiring special system permissions or user interaction. This is a straightforward but dangerous memory-safety issue that could allow unauthorized code execution at higher privilege levels.

  • CVE-2026-0271HIGH 7.8

    A privilege escalation vulnerability exists in Palo Alto Networks' Prisma Access Agent on Linux systems. An attacker with local access to an affected Linux device can exploit this flaw to gain elevated privileges and run code with higher permissions than their current account level. This capability is limited to Linux deployments; Windows, macOS, iOS, Android, and ChromeOS installations are unaffected.

  • CVE-2026-0276HIGH 7.8

    A privilege escalation flaw in Palo Alto Networks Cortex XDR Broker VM allows a user with local access to the system to gain root-level control. An authenticated attacker could exploit this to execute arbitrary commands with the highest privileges, potentially compromising the security monitoring infrastructure itself.

  • CVE-2026-0278HIGH 7.8

    A local user on Windows can circumvent data loss prevention (DLP) controls in Palo Alto Networks' Prisma Access Agent by exploiting multiple protection mechanism failures. An attacker with local access can bypass the DLP policies meant to prevent sensitive data from leaving the system. This vulnerability requires local access and does not affect the macOS version of Prisma Access Agent.

  • CVE-2026-10043HIGH 7.8

    MosaicML Composer contains a remote code execution vulnerability triggered when users open malicious checkpoint files. An attacker can craft a specially designed checkpoint file that, when deserialized by the application, executes arbitrary code with the privileges of the current user. Exploitation requires user interaction—a victim must be tricked into opening or visiting a malicious file or page. This is a deserialization flaw: the application fails to validate checkpoint data before processing it, allowing attackers to inject executable instructions into the saved model or training state.

  • CVE-2026-10046HIGH 7.8

    Bitdefender Napoca is a bare-metal hypervisor—a foundational piece of virtualization software that runs directly on hardware. A vulnerability exists in how it handles a legacy BIOS memory lookup request (INT 0x15). When a guest operating system makes this request with specific register values, the hypervisor fails to check whether the destination memory address is valid, allowing data to be written beyond the allocated buffer. An attacker with access to a guest system can exploit this to write data into the hypervisor's internal memory, potentially compromising the entire virtualization layer. Importantly, Napoca is end-of-life and no longer receives vendor support.

  • CVE-2026-10047HIGH 7.8

    Bitdefender's Napoca bare-metal hypervisor contains a memory safety flaw that allows a local attacker with limited privileges to write data beyond the boundaries of an internal memory buffer. By crafting specific processor register values, an attacker can overflow into the hypervisor's heap memory, potentially corrupting critical hypervisor state or executing arbitrary code. This vulnerability affects an end-of-life product that is no longer receiving security updates.

  • CVE-2026-10118HIGH 7.8

    Poppler, a widely-used PDF rendering library, contains a vulnerability in its Splash graphics backend that allows attackers to execute arbitrary code or crash applications by delivering specially crafted PDF files. The flaw stems from an integer overflow in the tiling pattern fill function—a feature used to render repeating graphical patterns in PDFs. When an attacker-controlled integer value overflows during this calculation, it causes the library to allocate insufficient heap memory. This undersized buffer is then written to beyond its boundaries, corrupting adjacent memory and potentially enabling code execution.

  • CVE-2026-10847HIGH 7.8

    Check Point Identity Agent Full for Windows contains a local privilege escalation flaw that allows an authenticated user already logged into a Windows machine to run code with SYSTEM-level permissions. The vulnerability stems from how the application resolves executables during its log collection process. An attacker with regular user access could exploit this to gain complete control over the affected endpoint.

  • CVE-2026-10942HIGH 7.8

    Google Chrome on Windows contains a UI implementation flaw that allows a local attacker to escalate privileges by opening a malicious file. The vulnerability affects Chrome versions prior to 149.0.7827.53 and requires user interaction (opening a file) but no authentication. If exploited, an attacker could gain elevated system privileges on an affected machine.

  • CVE-2026-11072HIGH 7.8

    A use-after-free flaw in Chrome's WebView component on Android allows a local attacker to run malicious code if a user opens a specially crafted file. The attacker needs physical or local access to the device and requires user interaction (opening the file), but once triggered, can gain full control over the affected application's privileges and data.

  • CVE-2026-11103HIGH 7.8

    A flaw in Google Chrome's installer on Windows allows a local attacker to gain administrative privileges on a computer by tricking a user into opening a malicious file. The vulnerability exists in how the installer validates and processes files during installation or updates. While Chrome itself is a web browser, this weakness targets the installation mechanism—the software that sets up Chrome on your system—making it a local privilege escalation risk rather than a remote internet-based attack.

  • CVE-2026-11332HIGH 7.8

    A vulnerability in ansible-core allows attackers to execute arbitrary code on systems where users install malicious Ansible roles. The attack works by embedding hidden git commands in a role's dependency specification file. When a user runs the standard ansible-galaxy role install command to fetch a role, the injected git flags execute with the privileges of that user, potentially giving an attacker full control over the victim's machine.

  • CVE-2026-11822HIGH 7.8

    SQLite versions prior to 3.53.2 contain memory safety flaws in the FTS5 full-text search module. When a user opens a specially crafted database file and runs a full-text search query, the vulnerability can trigger memory corruption that crashes the application, exhausts available memory, or potentially allows code execution. The vulnerability requires user interaction—a victim must open the malicious database—but once triggered, the impact is severe.

  • CVE-2026-11824HIGH 7.8

    SQLite versions before 3.53.2 contain a critical flaw in their full-text search capability that can be exploited by opening a specially crafted database file. When an application uses the FTS5 feature and processes search queries against the malicious database, attackers can trigger a memory corruption issue that crashes the application or potentially executes code with the privileges of the user running SQLite. The vulnerability requires local access and user interaction (opening a file), but poses significant risk to applications that accept untrusted database files.

  • CVE-2026-11979HIGH 7.8

    libxml2's xmlcatalog utility contains a stack-based buffer overflow vulnerability in its interactive shell mode. When a user provides unusually long input lines, the application fails to validate the length before copying that data into fixed-size memory buffers on the stack. This memory corruption can crash the program or, in a worst-case scenario, allow an attacker to execute arbitrary code with the privileges of the user running xmlcatalog. The issue affects the command-parsing logic within the usershell() function.

  • CVE-2026-12112HIGH 7.8

    A vulnerability in the foreman-mcp-server, used by Red Hat Satellite and The Foreman, allows attackers with local access to steal and reuse administrative session credentials. The flaw stems from the server caching authenticated connections without properly validating them later, and it logs session identifiers in plaintext to standard output—making them discoverable. An attacker who gains local system access can read these logs, hijack an active administrator's session, and execute commands with full administrative privileges.

  • CVE-2026-12167HIGH 7.8

    A local user on a system running Little Orbit's GFAC software can send commands directly to a privileged driver component (GFAC_Sys_x64.sys) via an unprotected communication channel. This bypasses normal access controls, allowing a regular user to perform actions that should be restricted to administrators—such as reading sensitive data, modifying system files, or disrupting system availability. An attacker needs existing local access to the machine; they cannot exploit this remotely.

  • CVE-2026-12168HIGH 7.8

    A flaw in Little Orbit's GFAC driver (GFAC_Sys_x64.sys) fails to properly validate messages sent through its Minifilter communication port. An attacker with local access can exploit this to gain SYSTEM-level privileges and run arbitrary code directly in the Windows kernel, effectively taking complete control of the affected machine.

  • CVE-2026-12191HIGH 7.8

    A flaw in Comma AI's Openpilot version 0.11 allows a local attacker with basic user privileges to execute arbitrary code through unsafe deserialization of pickle files. The vulnerability exists in the model data loading component and requires an attacker to already have access to the system where Openpilot is running. While the attack surface is limited to local access, the impact is severe—an attacker can read, modify, or delete sensitive data, and compromise the integrity of the autonomous driving system.

  • CVE-2026-12193HIGH 7.8

    VS Revo RevoUninstaller versions 2.5.x and 2.6.x contain a heap-based buffer overflow flaw in the RevoDetector.sys driver's IOCTL handler. A local attacker with standard user privileges can exploit this to crash the system or potentially execute code with elevated privileges. The vulnerability requires local access and cannot be exploited remotely. A public exploit exists, elevating the practical risk. Upgrading to version 2.7.0 eliminates the vulnerability.

  • CVE-2026-12214HIGH 7.8

    Qihoo 360 Total Security version 6.0 contains a vulnerability in its Nucleus Engine Monitoring Logic that allows a local attacker with regular user privileges to bypass security protections by manipulating how the system handles network address parameters. This flaw has been publicly disclosed with working exploit code available, creating immediate risk for organizations running this software.

  • CVE-2026-12217HIGH 7.8

    DVDFab Virtual Drive version 2.0.0.5 contains a privilege escalation vulnerability in its signed kernel driver component (dvdfabio.sys). A local user with standard privileges can exploit this flaw to gain elevated system access, potentially allowing them to modify system files, install malware, or disable security controls. The vulnerability requires local access and user interaction is not needed once code execution begins. Public exploit code is available, increasing the urgency for affected organizations.

  • CVE-2026-12252HIGH 7.8

    NLTK, a widely-used natural language processing library for Python, contains a critical flaw in how it handles Stanford NLP tool integrations. Five specific classes that interface with Stanford tools (POS tagger, NER tagger, parser, and dependency parser variants) will execute Java code from JAR files without checking whether those files are legitimate. If an attacker can control the path to a JAR file loaded by an application using these classes—through a local directory listing, a misconfigured shared drive, or another vector—they can inject malicious Java code that runs with the privileges of the Python process. This is particularly dangerous in multi-tenant environments or applications that process untrusted linguistic input sources.

  • CVE-2026-12390HIGH 7.8

    AzeoTech DAQFactory contains a type confusion flaw that allows attackers to execute arbitrary code when a user opens a specially crafted .ctl (control) file. The vulnerability affects DAQFactory version 21.1 and earlier. Type confusion occurs when an application mishandles data types, treating one kind of data as another—in this case, an attacker can exploit this confusion through a malicious file to gain code execution on the affected system. User interaction is required (opening the file), but no special privileges are needed beforehand.

  • CVE-2026-12449HIGH 7.8

    Google Chrome on Windows has a memory safety flaw in its Chromoting (remote desktop) feature that can allow a local attacker to gain elevated system privileges by opening a specially crafted file. The vulnerability affects Chrome versions before 149.0.7827.155 and requires user interaction but does not require special permissions to exploit. Once triggered, an attacker could potentially take full control of the affected machine.

  • CVE-2026-12505HIGH 7.8

    CVE-2026-12505 is a privilege escalation vulnerability in cifs-utils, a package that handles CIFS (Common Internet File System) operations on Linux systems. A low-privileged local attacker can manipulate the system's helper process (cifs.upcall) into loading malicious code by exploiting how it looks up user information. Because this helper runs as root but doesn't properly restrict its environment before performing sensitive operations, an attacker can inject a fake user database module that executes arbitrary commands with full system privileges. This is a local attack requiring existing system access, but the impact is severe—complete system compromise.

  • CVE-2026-12537HIGH 7.8

    Google's Gemini CLI and its accompanying GitHub Action contain a command injection vulnerability that allows an attacker to execute arbitrary code on a developer's machine or CI/CD pipeline before containerization takes place. An attacker can craft a malicious `.gemini` or `.env` configuration file that, when processed by the vulnerable tool, breaks out of intended command boundaries and runs attacker-controlled commands with the privileges of the user running the tool. This is particularly dangerous in headless CI environments where automation runs without human oversight.

  • CVE-2026-12778HIGH 7.8

    A privilege escalation flaw exists in AOMEI Partition Assistant version 10.10.1 and earlier, affecting the ampa10.sys kernel driver. An authenticated local attacker can exploit improper access controls in the driver to gain elevated system privileges, potentially compromising the entire system. The vulnerability has been publicly disclosed, and exploit code may be in circulation. The vendor has not responded to early disclosure attempts.

  • CVE-2026-12779HIGH 7.8

    AOMEI Dynamic Disk Manager versions up to 10.10.1 contain a privilege escalation vulnerability in the ddmdrv.sys kernel driver that allows a locally authenticated attacker to bypass access controls and gain elevated privileges on the system. An attacker with user-level access can manipulate the kernel driver to achieve high-impact unauthorized actions. The vendor has not responded to early disclosure efforts, and exploit code is publicly available.

  • CVE-2026-12780HIGH 7.8

    AOMEI Backupper, a widely-used backup and disaster recovery application, contains a kernel driver vulnerability that allows local attackers with user-level privileges to bypass access controls and gain elevated capabilities on affected systems. The flaw resides in the amwrtdrv.sys driver and requires an attacker to already have local access to the machine. Public exploit code exists, and the vendor has not responded to early disclosure attempts.

  • CVE-2026-12781HIGH 7.8

    EaseUS Partition Master versions up to 14.5 contain a kernel driver vulnerability that allows authenticated local users to bypass security controls and gain elevated privileges. An attacker with legitimate access to a system running the affected software can exploit an improper access control flaw in the epmntdrv.sys driver to read, modify, or disrupt system functionality. The vendor has confirmed the issue only existed in older versions and has been resolved in current releases.

  • CVE-2026-12782HIGH 7.8

    EaseUS Partition Master versions up to 14.5 contain a kernel driver vulnerability that allows local users with standard privileges to gain elevated system access and control over disk partitioning functions. The flaw stems from improper access controls in the EUEDKEPM.sys driver. Because exploit code is publicly available, this vulnerability poses an active risk to organizations running older versions of the software. The vendor has confirmed the issue is resolved in current releases.

  • CVE-2026-12784HIGH 7.8

    IM-Magic Partition Resizer versions up to 7.9.0 contain a security flaw in its kernel driver (MDA_NTDRV.sys) that fails to properly enforce access controls. An attacker with local system access could exploit this weakness to gain elevated privileges or interfere with system integrity. Public exploit code now exists, elevating the practical risk. The vendor has not responded to early disclosure attempts, leaving affected users without an official patch.

  • CVE-2026-12786HIGH 7.8

    Ezbsystems UltraISO Premium Edition versions up to 9.76 contain a vulnerability in a kernel driver (bootpt64.sys) that fails to enforce proper access controls. An attacker with local system access can exploit this weakness to gain elevated privileges and potentially read, modify, or delete sensitive data on the affected system. The vulnerability has been publicly disclosed, and while the vendor was notified early, they have not provided a response or patch.

  • CVE-2026-12921HIGH 7.8

    AzeoTech DAQFactory versions 21.1 and earlier contain a use-after-free vulnerability that can be triggered when a user opens a specially crafted control (.ctl) file. An attacker can exploit this memory safety defect to execute arbitrary code on the affected system with the privileges of the DAQFactory user. This is a local attack vector requiring user interaction—the victim must be tricked into opening a malicious file.

  • CVE-2026-12957HIGH 7.8

    Language Servers for AWS versions before 1.65.0 contain a vulnerability that allows arbitrary code execution when a user opens a malicious workspace. The vulnerability stems from insufficient trust boundary enforcement—if a local user is tricked into trusting a workspace containing malicious commands in project configuration files, those commands will execute automatically. An attacker would need to craft a malicious workspace and convince a user to open and trust it, making this a local attack that relies on social engineering.