China-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests.
A vulnerability classified as critical was found in Linux Kernel up to 6.18.13/6.19.3. Affected by this vulnerability is the function WARN_ON of the component coresight. The manipulation of the argument spinlock results in race condition.
This vulnerability is cataloged as CVE-2026-46272. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in Securly Chrome Extension up to 3.0.7. Affected is the function RegExp of the component Regular Expression Handler. The manipulation leads to inefficient regular expression complexity.
This vulnerability is listed as CVE-2026-8888. The attack must be carried out from within the local network. There is no available exploit.
A vulnerability described as critical has been identified in Linux Kernel up to 6.19.3. This impacts the function power_supply_changed of the component power. Executing a manipulation can lead to use after free.
This vulnerability is tracked as CVE-2026-46270. The attack is only possible within the local network. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in Securly Chrome Extension up to 3.0.7. This affects an unknown function. Performing a manipulation results in password hash with insufficient computational effort.
This vulnerability is identified as CVE-2026-8881. The attack can only be performed from the local network. There is not any exploit available.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.13/6.19.3. The impacted element is an unknown function of the component wifi. Such manipulation leads to denial of service.
This vulnerability is referenced as CVE-2026-46271. The attack needs to be initiated within the local network. No exploit is available.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Linux Kernel up to 7.1-rc1. The affected element is the function vlan_features_check of the component ibmveth. This manipulation causes stack-based buffer overflow.
The identification of this vulnerability is CVE-2026-46273. The attack needs to be done within the local network. There is no exploit available.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in Koha up to 25.11. Impacted is an unknown function of the component Configuration Handler. The manipulation results in privilege escalation.
This vulnerability was named CVE-2026-26379. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in Kimi AI 1.0. It has been rated as problematic. This issue affects some unknown processing of the component Web Interface. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-39107. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in Mercusys AC12G. It has been declared as very critical. This vulnerability affects unknown code of the component SOAP Request Handler. Executing a manipulation can lead to unintended intermediary.
This vulnerability is handled as CVE-2026-36608. The attack can only be done within the local network. There is not any exploit available.
A vulnerability was found in Mercusys AC12G. It has been classified as problematic. This affects an unknown part. Performing a manipulation results in denial of service.
This vulnerability is known as CVE-2026-36605. Access to the local network is required for this attack. No exploit is available.
A vulnerability was found in Dovestones ADPhonebook and classified as problematic. Affected by this issue is some unknown functionality of the file /Admin/Save of the component Configuration Handler. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-36460. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Mercusys AC12G and classified as critical. Affected by this vulnerability is an unknown functionality of the component Firmware Binary Handler. This manipulation causes privilege escalation.
This vulnerability appears as CVE-2026-36616. The attacker needs to be present on the local network. There is no available exploit.
A vulnerability, which was classified as problematic, was found in Securly Chrome Extension up to 3.0.7. Affected is an unknown function. The manipulation results in insecure storage of sensitive information.
This vulnerability is reported as CVE-2026-8878. The attacker must have access to the local network to execute the attack. No exploit exists.
A vulnerability, which was classified as problematic, has been found in Securly Chrome Extension up to 3.0.6. This impacts an unknown function of the component Fetch API. The manipulation leads to cleartext transmission of sensitive information.
This vulnerability is documented as CVE-2026-8874. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as critical was found in Mercusys AC12G. This affects an unknown function of the file /agileconfigreset. Executing a manipulation can lead to buffer overflow.
This vulnerability is registered as CVE-2026-36615. The attack requires access to the local network. No exploit is available.
A vulnerability classified as problematic has been found in Mercusys AC12G. The impacted element is an unknown function of the component HTTP POST Request Handler. Performing a manipulation results in uninitialized pointer.
This vulnerability is cataloged as CVE-2026-36613. The attack must originate from the local network. There is no exploit available.
A vulnerability described as very critical has been identified in Mercusys AC12G. The affected element is an unknown function of the component POST Request Handler. Such manipulation of the argument SOAPAction leads to uninitialized pointer.
This vulnerability is listed as CVE-2026-36611. The attack must be carried out from within the local network. There is no available exploit.
A vulnerability marked as problematic has been reported in Frappe ERPNext 16.16.0. Impacted is an unknown function. This manipulation of the argument email_id/mobile_no causes cross site scripting.
This vulnerability is tracked as CVE-2026-42840. The attack is possible to be carried out remotely. No exploit exists.