ZDI-26-620: Microsoft Windows UMPDDrvPlgBlt Improper Object Management Local Privilege Escalation Vulnerability
ZDI disclosed CVE-2026-62712, a CVSS 7.8 Windows UMPDDrvPlgBlt improper object-management flaw enabling local privilege escalation.
Zero Day Initiative advisory ZDI-26-620 describes an improper object management flaw in Microsoft Windows' UMPDDrvPlgBlt component, sharing CVE-2026-62712 with the related UMPDDrvStretchBlt advisory. A local attacker able to run low-privileged code can escalate privileges on affected installations. The issue carries a CVSS 3.0 rating of 7.8.
ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability
ZDI disclosed CVE-2026-62712, a CVSS 7.8 Windows UMPDDrvStretchBlt improper object-management flaw enabling local privilege escalation.
Zero Day Initiative advisory ZDI-26-618 describes an improper object management issue in Microsoft Windows' UMPDDrvStretchBlt component. A local attacker who can already execute low-privileged code on the system can escalate privileges. The flaw carries a CVSS 3.0 rating of 7.8; details on affected versions and patch availability are limited in the advisory.
ZDI-26-619: Microsoft Windows UMPDDrvStretchBltROP Improper Object Management Local Privilege Escalation Vulnerability
ZDI disclosed CVE-2026-62712, a CVSS 7.8 improper object management flaw in Windows UMPDDrvStretchBltROP enabling local privilege escalation from low-privileged code.
The Zero Day Initiative published ZDI-26-619 covering a local privilege escalation vulnerability in Microsoft Windows' UMPDDrvStretchBltROP function, stemming from improper object management. Exploitation requires that the attacker first obtain the ability to run low-privileged code on the target system. ZDI rated the issue CVSS 7.8 and assigned CVE-2026-62712, the same identifier listed in the companion UMPDDrvRealizeBrush advisory.
ZDI-26-621: Microsoft Windows UMPDDrvRealizeBrush Improper Object Management Local Privilege Escalation Vulnerability
ZDI disclosed CVE-2026-62712, a CVSS 7.8 improper object management flaw in Windows UMPDDrvRealizeBrush enabling local privilege escalation after low-privileged code execution.
The Zero Day Initiative published ZDI-26-621 covering a local privilege escalation vulnerability in Microsoft Windows' UMPDDrvRealizeBrush component, caused by improper object management. An attacker must already be able to execute low-privileged code on the target system before exploiting the flaw. ZDI assigned the vulnerability a CVSS score of 7.8 and the CVE identifier CVE-2026-62712.
ZDI-26-542: Microsoft Windows UMPDDrvBitBlt Improper Object Management Local Privilege Escalation Vulnerability
ZDI discloses CVE-2026-62712, a CVSS 7.8 Windows UMPDDrvBitBlt improper object management flaw allowing local attackers to escalate privileges.
ZDI advisory ZDI-26-542 describes improper object management in Microsoft Windows' UMPDDrvBitBlt function, tracked as CVE-2026-62712 with a CVSS score of 7.8. The flaw allows local attackers to escalate privileges on affected Windows installations. Exploitation requires first obtaining the ability to execute low-privileged code on the target system.
TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password
Two flaws in TP-Link Tapo C200 cameras allow network-adjacent admin access without a password (CVE-2026-15315) or DoS (CVE-2026-15316); fixed in V5_1.4.6.
OPSWAT Unit 515 researchers discovered CVE-2026-15315, an authentication bypass in the Tapo C200's local HTTPS management interface on port 443, where an alternative verification path accepts a replayed device-generated value, letting unauthenticated network-adjacent attackers establish admin sessions. CVE-2026-15316 causes a denial-of-service crash in the camera's HTTPS service via oversized encrypted Wi-Fi credential data during onboarding. TP-Link confirmed both issues after the April 16, 2026 report and released firmware V5_1.4.6 on August 18, 2026. OPSWAT says additional potentially critical findings remain under coordinated disclosure.
Identifying a BOLA Vulnerability in Harbor, a Cloud
Unit 42 found a BOLA flaw, CVE-2024-22278 (CVSS 6.4), letting Maintainers improperly alter Harbor project metadata; fixed in versions 2.9.5, 2.10.3, and 2.11.0.
Unit 42 researchers identified a broken object-level authorization flaw, CVE-2024-22278, in Harbor, a CNCF-graduated cloud-native container registry with 1.8 million downloads. The flaw (CVSS 6.4) lets users with the Maintainer role create, update, and delete project metadata, actions reserved for ProjectAdmin, risking data exposure, integrity compromise, and circumvention of vulnerability scanning. Harbor patched the issue in versions 2.9.5, 2.10.3, and 2.11.0. The finding came from Unit 42's automated BOLA detection tool built on generative AI.
CVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles
Apache Syncope CVE-2026-73470 lets delegated users grant roles they do not own via crafted delegations.
Apache Syncope disclosed CVE-2026-73470, an improper privilege management vulnerability rated important. Delegations can be created or updated so that delegated users are able to grant roles they do not own, breaking ownership constraints. The flaw affects syncope-core-provisioning-java in versions 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2. Users are advised to upgrade to the latest fixed releases.
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Cisco warns of static low-privileged credentials in Secure Firewall Management Center's web interface, letting unauthenticated remote attackers log in and access sensitive data.
Cisco disclosed a vulnerability in the web interface of Secure Firewall Management Center (FMC) Software caused by the presence of static credentials for a low-privileged account. An unauthenticated remote attacker could log in to an affected device using the static account and access sensitive data within impacted systems. The attack surface is reduced when the FMC management interface does not have public internet access.
Rockwell Automation FactoryTalk Activation Manager
CISA details CVE-2026-16675, a CVSS 7.8 privilege escalation flaw in Rockwell FactoryTalk Activation Manager V5.02 and below, with vendor fixes available.
CISA issued an ICS advisory for Rockwell Automation FactoryTalk Activation Manager. CVE-2026-16675 is a privilege escalation vulnerability stemming from installer custom actions, scored 7.8. Versions V5.02 and below are affected, and Rockwell Automation has released fixes.