ZeroHour

Search: “vulnerability disclosure”

67 stories

ZDI-26-582: Cisco Identity Services Engine PatchUpdateListener Directory Traversal Information Disclosure Vulnerability

Cisco Identity Services Engine's PatchUpdateListener has an authenticated directory traversal (CVE-2026-20148, CVSS 4.9) enabling sensitive information disclosure.

ZDI advisory ZDI-26-582 describes a directory traversal information disclosure vulnerability in the PatchUpdateListener component of Cisco Identity Services Engine. Remote attackers can disclose sensitive information, but valid authentication is required to exploit the flaw. ZDI assigned a CVSS rating of 4.9 and CVE-2026-20148.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-20148

ZDI-26-557: (Pwn2Own) Amazon Smart Plug Insecure Fallback Information Disclosure Vulnerability

ZDI disclosed a Pwn2Own information disclosure flaw (CVSS 4.3) in Amazon Smart Plug, letting unauthenticated network-adjacent attackers access sensitive information.

The Zero Day Initiative published ZDI-26-557 for an insecure fallback information disclosure flaw in Amazon Smart Plug, demonstrated at Pwn2Own. Unauthenticated network-adjacent attackers can disclose sensitive information on affected installations. ZDI rated the issue CVSS 4.3.

ZDI Published Advisories · Aug 12, 2026Advisory

ZDI-26-601: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability

Foxit PDF Reader has a use-after-free vulnerability (CVE-2026-13129, CVSS 3.3) allowing sensitive information disclosure when a user opens malicious content.

ZDI-26-601 describes a use-after-free vulnerability in the annotation feature of Foxit PDF Reader, tracked as CVE-2026-13129 with a CVSS score of 3.3. Successful exploitation allows remote attackers to disclose sensitive information, but requires user interaction such as visiting a malicious page or opening a malicious file. The advisory does not mention any exploitation in the wild.

ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure Vulnerability

ZDI advisory ZDI-26-668 reports an annotation use-after-free (CVE-2026-81984) causing information disclosure in Adobe Acrobat Reader DC.

The Zero Day Initiative published advisory ZDI-26-668 for a use-after-free condition in the annotation feature of Adobe Acrobat Reader DC. Exploitation allows remote attackers to disclose sensitive information when the target opens a malicious file or page. ZDI rated the issue 3.3 on the CVSS scale and assigned CVE-2026-81984.

ZDI-26-682: Linux Kernel IPv6 Neighbour Discovery Uninitialized Memory Information Disclosure Vulnerability

ZDI discloses an uninitialized-memory flaw in Linux kernel IPv6 neighbor discovery (CVE-2026-43040, CVSS 6.0) allowing information disclosure by already-privileged local attackers.

ZDI advisory ZDI-26-682 describes an uninitialized memory vulnerability in the Linux kernel's IPv6 Neighbour Discovery code, tracked as CVE-2026-43040 with a CVSS score of 6.0. Exploitation requires the attacker to already execute high-privileged code on the target, which severely limits practical impact to kernel memory information disclosure. No active exploitation is mentioned.

ZDI-26-643: Oracle VirtualBox VMSVGA Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI publishes ZDI-26-643 for CVE-2026-60162, an out-of-bounds read information disclosure flaw in Oracle VirtualBox VMSVGA, rated CVSS 6.1.

Zero Day Initiative published advisory ZDI-26-643 describing an out-of-bounds read in Oracle VirtualBox's VMSVGA component. Local attackers with the ability to execute high-privileged code on the guest system can disclose sensitive information. ZDI rated the issue CVSS 6.1 and assigned CVE-2026-60162.

ZDI-26-599: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability

ZDI published advisory ZDI-26-599 for a use-after-free information disclosure flaw (CVE-2026-57238, CVSS 3.3) in Foxit PDF Reader requiring user interaction.

The Zero Day Initiative released advisory ZDI-26-599 describing a use-after-free vulnerability in Foxit PDF Reader's annotation handling. The flaw allows remote attackers to disclose sensitive information when a target opens a malicious file or visits a malicious page. ZDI rated the issue CVSS 3.3 and assigned CVE-2026-57238.

Cisco Identity Services Engine Information Disclosure Vulnerability

Cisco patched an ISE API flaw letting an authenticated administrator view sensitive data including hashed credentials via crafted API requests.

A vulnerability in the Cisco Identity Services Engine API allows an authenticated remote attacker with valid administrative credentials to view sensitive information, including hashed credentials usable in future attacks. The flaw is caused by insufficient validation of user-supplied API request parameters. Cisco has released software updates.

Cisco Security Advisories · 12h agoAdvisory 15 sources

ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI discloses Linux Kernel TLS protocol out-of-bounds read (CVE-2026-64046) allowing high-privileged local attackers to disclose sensitive information, CVSS 6.7.

ZDI-26-701 covers an out-of-bounds read information disclosure vulnerability in the Linux Kernel TLS protocol implementation, tracked as CVE-2026-64046 with a CVSS rating of 6.7. Exploitation requires the attacker to already have the ability to execute high-privileged code on the target system. Impact is limited to disclosure of sensitive information from affected installations.

ZDI-26-699: Linux Kernel NTFS3 Out-of-Bounds Read Information Disclosure Vulnerability

ZDI-26-699: Linux Kernel NTFS3 out-of-bounds read (CVSS 5.2) lets local low-privileged attackers disclose sensitive information.

ZDI advisory ZDI-26-699 describes an out-of-bounds read in the Linux Kernel NTFS3 driver rated CVSS 5.2. An attacker must already have the ability to execute low-privileged code on the target system to trigger the flaw. Successful exploitation results in information disclosure. No CVE identifier is listed in the advisory.

ZDI-26-690: Linux Kernel MCTP Routing Uninitialized Memory Information Disclosure Vulnerability

ZDI discloses Linux Kernel MCTP routing uninitialized memory flaw (CVE-2026-45930) letting high-privileged local attackers leak sensitive kernel information.

ZDI-26-690 describes an uninitialized memory information disclosure vulnerability in the Linux Kernel MCTP routing subsystem, tracked as CVE-2026-45930 with a CVSS rating of 6.0. Exploitation requires the attacker to already have the ability to execute high-privileged code on the target system. Impact is limited to disclosure of sensitive information from affected installations.

ZDI-26-631: NI LabVIEW VI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI disclosed CVE-2026-18444, an out-of-bounds read in NI LabVIEW VI file parsing that can disclose sensitive information, rated CVSS 3.3.

The Zero Day Initiative published advisory ZDI-26-631 describing an out-of-bounds read vulnerability in NI LabVIEW's parsing of VI files. Exploitation can disclose sensitive information and requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned the flaw a CVSS rating of 3.3.

ZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerability

ZDI advisory ZDI-26-605 details an improper input validation flaw (CVE-2026-50508, CVSS 3.3) in Microsoft Windows localized filenames that leaks NTLM responses.

The Zero Day Initiative released advisory ZDI-26-605 describing improper input validation in Microsoft Windows handling of localized filenames. Remote attackers can disclose NTLM authentication responses if the target opens a malicious file or visits a crafted page. ZDI rated the issue CVSS 3.3 and assigned CVE-2026-50508. Leaked NTLM responses could enable offline credential cracking.

ZDI Published Advisories · 23d agoAdvisoryCVE-2026-505081

ZDI-26-607: Microsoft Office HTML Injection Information Disclosure Vulnerability

ZDI disclosed an HTML injection flaw in Microsoft Office (CVSS 7.6) that lets remote attackers disclose sensitive information via malicious pages or files.

Zero Day Initiative advisory ZDI-26-607 describes an HTML injection vulnerability in Microsoft Office that leads to information disclosure. Remote attackers need the target to visit a malicious page or open a malicious file to trigger it. ZDI rated the issue 7.6 on the CVSS scale and the advisory lists no CVE identifier. The advisory does not indicate active exploitation.

ZDI Published Advisories · 23d agoVulnerability1

ZDI-26-600: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability

Foxit PDF Reader annotation use-after-free (CVE-2026-57237, CVSS 3.3) can disclose sensitive information when users open malicious PDFs.

ZDI-26-600 documents a use-after-free in Foxit PDF Reader annotation handling that allows remote information disclosure, tracked as CVE-2026-57237 with CVSS 3.3. Exploitation requires user interaction such as opening a malicious file or visiting a malicious page. The advisory was published by the Zero Day Initiative on August 24, 2026.

ZDI-26-596: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

Foxit PDF Reader out-of-bounds read in PDF parsing (CVE-2026-57253, CVSS 3.3) can leak sensitive information via malicious files.

ZDI-26-596 covers an out-of-bounds read in Foxit PDF Reader's PDF file parsing, tracked as CVE-2026-57253 and rated CVSS 3.3. Successful exploitation allows remote attackers to disclose sensitive information and requires the target to open a malicious file or page. The advisory was published by the Zero Day Initiative on August 24, 2026.

Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People

Hackers who removed a Flock Safety license plate camera dumped its data, revealing person-detection capabilities and an encryption key stored unencrypted on the device.

A hacker collective calling itself stegan0gram physically removed a Flock Safety automatic license plate reader camera from a roadway, copied its storage, and shared the files with 404 Media, WIRED, and Distributed Denial of Secrets. Analysis found an encryption key in an unencrypted 'media' partition that unlocked videos of thousands of vehicle detections, with logs showing more than a million images generated in weeks. The software explicitly detects people, bicycles, and even bumper stickers, and records from one Georgia city were searchable by more than 2,000 agencies nationwide. The findings follow 2025 research by Jon Gaines documenting flaws enabling root-level access to Flock cameras.

404 Mediaupdated · 6h agofirst · 18h agoResearch in the wild 3 sources

Microsoft confirms KB5002914 Excel update breaks copy and paste

Microsoft confirms KB5002914 Office security update silently breaks copy-paste, autofill, and formula dragging in Excel 2016 through 2024.

Microsoft confirmed the September 2026 KB5002914 security update breaks copy-and-paste, autofill, and formula dragging in Excel 2024, 2021, 2019, and 2016. Failures occur silently with no beep or error message, leaving the destination unmodified. Uninstalling KB5002914 via OfficeC2RClient or Oarpmany restores functionality while Microsoft investigates.

BleepingComputerupdated · 1d agofirst · 1d agoAdvisory 3 sources1

HashiCorp security advisory (AV26-910)

Canada's Cyber Centre warns HashiCorp Consul and consul-template have authorization bypass and information disclosure flaws, urging users to apply available updates.

Advisory AV26-910 relays HashiCorp security advisories HCSEC-2026-34, HCSEC-2026-37 and HCSEC-2026-38 covering Consul and consul-template. Consul has an authorization bypass in the catalog node-write path and another in the Connect service mesh, while consul-template has an information disclosure issue in error handling. Fixed versions include Consul 2.0.4, Consul Enterprise 1.21.18 and consul-template 0.43.0. The Cyber Centre encourages users and administrators to review the linked advisories and apply updates.

Canadian Centre for Cyber Security · 5d agoAdvisory1

USN-8731-1: MiniUPnPd vulnerability

Ubuntu issued USN-8731-1 fixing a MiniUPnPd integer underflow allowing remote DoS or information disclosure via malformed SOAPAction headers.

Ubuntu released USN-8731-1 to address an integer underflow vulnerability in MiniUPnPd's SOAPAction header parsing. A remote attacker could send a malformed SOAPAction header containing a single quote to trigger a denial of service or information disclosure. MiniUPnPd is a lightweight UPnP daemon widely deployed on routers and gateways.

Ubuntu Security Notices · 9d agoAdvisory1

USN-8675-2: Perl vulnerabilities

Ubuntu issued USN-8675-2 fixing two Perl flaws (CVE-2026-12087, CVE-2026-13221) enabling information disclosure and regex-based security bypass on 26.04 LTS.

Ubuntu released USN-8675-2, extending the fixes from USN-8675-1 to Perl packages on Ubuntu 26.04 LTS. The update addresses CVE-2026-12087, an out-of-bounds heap read in the Socket module when handling short source addresses, which could lead to information disclosure. It also fixes CVE-2026-13221, where regular expressions containing many fixed string alternatives could produce incorrect matches and bypass security restrictions. No exploitation is reported in the notice.

Cisco Nexus Dashboard Software Security Hardening Release: September 2026

Cisco released Nexus Dashboard hardening updates for multiple internally discovered vulnerabilities, grouped by CWE and not known to be exploited.

Cisco's Nexus Dashboard engineering team conducted an internal security review that found multiple vulnerabilities, addressed via software hardening releases. The issues were discovered during internal testing and are not known to be actively exploited. Cisco grouped the issues by CWE class and assigned a single CVE ID per issue before releasing fixes.

Cisco Security Advisories · 12h agoAdvisory

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco released IOS XR security hardening fixes for multiple internally discovered vulnerabilities, grouped by CWE class, with no known active exploitation.

Cisco's IOS XR engineering team conducted a comprehensive internal security review and released hardening updates addressing multiple internally discovered vulnerabilities. The issues were found during internal testing and are not known to be actively exploited. Cisco grouped the vulnerabilities by CWE class and assigned a single CVE ID to each grouping to streamline patching and disclosure.

Cisco Security Advisories · 12d agoAdvisory

Cisco Crosswork Security Hardening Release: August 2026

Cisco released an August 2026 Crosswork security hardening update addressing multiple internally discovered vulnerabilities, grouped by CWE class with one CVE per grouping.

Cisco's Crosswork engineering team completed a comprehensive internal security review and shipped a hardening release fixing multiple internally discovered vulnerabilities. The issues were found during internal testing, are grouped by CWE class, and each grouping received a single CVE ID. Cisco states these vulnerabilities are not known to be actively exploited.

Cisco Security Advisories · 26d agoAdvisory

Cisco Secure Workload Software Security Hardening Release: August 2026

Cisco shipped August 2026 hardening releases for Secure Workload fixing multiple internally discovered vulnerabilities that are not actively exploited.

Cisco's Secure Workload engineering team completed an internal security review that found multiple vulnerabilities during internal testing. The issues are grouped by CWE class with a single CVE assigned per grouping, and none are known to be actively exploited. Cisco has released hardening updates for customers to patch.

Cisco Security Advisories · 28d agoAdvisory

Flextype v1.0.0-alpha.3 Path Traversal in Entry Copy Allows Arbitrary Directory Copy and File Disclosure

Flextype CMS v1.0.0-alpha.3 entries copy endpoint accepts path traversal in source and destination parameters, enabling arbitrary directory copies and file disclosure.

Flextype CMS v1.0.0-alpha.3 constructs entry directory paths in the copy functionality by directly concatenating supplied entry identifiers with the configured entries directory. The /api/v1/entries/copy endpoint accepts directory traversal sequences in both the source id and destination new_id parameters. An authenticated remote attacker can thereby copy arbitrary directories and disclose files outside the intended entries directory. Ron E disclosed the issue on the Full Disclosure mailing list on September 3, 2026.

Full Disclosure · 13d agoVulnerability 8 sources

Forgery of C2PA on a Pixel 10

Researcher forged a Google Pixel 10 C2PA content credential with genuine signatures, showing root-level attackers can fake photo provenance.

A Hacker Factor blog post demonstrates an AI-generated 'unicorn glitter milk' news photo carrying a valid, cryptographically signed C2PA manifest traceable to Google's Pixel camera certificate chain, passing validation in Adobe Inspect and the CAI Verify tool with a verified timestamp. The author, working with UMBC's PASAWG working group, reported to Google and C2PA in November 2025 that root access on a Pixel device could sign arbitrary images as camera captures; after 90 days without resolution, details were published. The finding undermines C2PA Assurance Level 2 claims made for Pixel 10 Content Credentials.

Lobsters · security · 15h agoResearch

New hardware device can RAM into encrypted memory, expose your data

Researchers built a $200 DDR5 interposer that silently drops memory writes to break TDX, SGX, and SEV-SNP confidential VM integrity, requiring physical access.

Researchers from KU Leuven, ETH Zurich, Durham University, and Google demonstrated DDRop, a hardware interposer costing under $200 that corrupts DDR5 bus commands to silently drop writes to encrypted memory, enabling replay attacks on confidential VMs. Because scalable memory encryption lacks freshness checks, protected VMs keep computing on stale attacker-selected data; on an Intel TDX server the attack forces debug mode for plaintext memory reads or forges attestation reports, succeeding in under two minutes without crashing. Intel and AMD both called the attack out of scope for their cloud threat models, with no mitigation planned, and proposed cache line versioning appears still vulnerable. The full interposer design is being released as open-source hardware.

The Register · Security · 2d agoResearch

Re: CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs

Follow-up on oss-security asks why CVE-2026-82434, Apache Storm ZooKeeper credential disclosure to read-only users and logs, lacks a severity rating.

Gabriel Ravier replied to the oss-security disclosure thread for CVE-2026-82434, which affects Apache Storm Nimbus and Apache Storm Client. The vulnerability involves disclosure of the topology ZooKeeper credential to read-only users and to logs. The reply questions whether the CVE was filed without a severity rating or if it is simply missing from the listing. No exploitation details or affected versions are provided in the post.

CVE-2026-77883: Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist

Apache Syncope's JEXL template engine permits one-hop navigation past the JexlContextBuilder name denylist, enabling administrator-driven information disclosure.

CVE-2026-77883 is a moderate-severity exposure of sensitive information through data queries in Apache Syncope's syncope-core-provisioning-api module. An administrator can bypass the JexlContextBuilder name denylist using one-hop JEXL navigation to reach sensitive data. Affected versions are 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2.

oss-security · 2d agoVulnerabilityCVE-2026-778831