The
Reassessment
Feed.

All ↑ Upgraded ↓ Downgraded = Unchanged
Sort
All reassessments
showing 1–20 of 1,879
2026-09-10
CVE-2025-14733
CWE-787
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may
Unauthenticated RCE on 117K+ internet-facing firewalls, actively exploited in ransomware campaigns.
CRITICAL 9.8 = CRITICAL
EPSS 0.27 KEV
2026-09-10
CVE-2026-88038
CWE-74
cookies vulnerable to Set-Cookie attribute injection via unvalidated domain and path options
Cookie attribute injection needs an app anti-pattern most codebases dont have
MEDIUM 4.8 ↓ LOW
2026-09-10
CVE-2026-82533
CWE-807
DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability in its local HTTP control-plane API
Localhost-only AI client lib with 15K downloads — real bug, inflated blast radius.
CRITICAL 9.6 ↓ MEDIUM
EPSS 0.00
2026-09-10
CVE-2025-20701
CWE-863
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privilege
Consumer BT peripheral flaw with proximity-only attack — not patchable by your infra team.
HIGH 8.8 ↓ MEDIUM
EPSS 0.08
2026-09-10
CVE-2026-85102
CWE-295
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may
Pre-auth RCE on your perimeter firewall — the gate IS the breach.
CRITICAL 9.8 = CRITICAL
2026-09-10
CVE-2026-69845
CWE-20
Heap-based buffer overflow in Windows DHCP Server
LAN-only attack surface caps real risk below vendor 9.8, but SYSTEM on infra is no joke.
CRITICAL 9.8 ↓ HIGH
EPSS 0.01
2026-09-10
CVE-2026-69813
CWE-416
Use after free in Windows DNS
Race-condition UAF on DNS means race-condition RCE on your domain controllers
HIGH 8.1 ↑ CRITICAL
EPSS 0.01
2026-09-10
CVE-2026-81952
CWE-122
Heap-based buffer overflow in Microsoft Office Word
Classic Word doc RCE — ubiquitous target, but Protected View and no live exploitation keep it a notch below vendor hype.
HIGH 8.8 = HIGH
EPSS 0.01
2026-09-10
CVE-2026-8195
CWE-79
JeecgBoot SVG File CommonController.java cross site scripting
Stored XSS via SVG in a niche low-code platform with ~80 exposed instances and a 2-version window.
MEDIUM 5.3 ↓ LOW
EPSS 0.00
2026-09-10
CVE-2026-83939
CWE-822
Untrusted pointer dereference in Windows Secure Kernel Mode
VBS escape needs SYSTEM first — high-value but deep in the kill chain.
HIGH 8.2 = HIGH
EPSS 0.00
2026-09-09
CVE-2026-20293
CWE-749
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could
Secure Boot bypass needs console access and a reboot — a post-compromise persistence play, not initial access.
HIGH 7.1 ↓ MEDIUM
EPSS 0.00
2026-09-09
CVE-2026-0307
CWE-426
Palo Alto Networks GlobalProtect App Local Privilege Escalation via Untrusted Search Path
Local-only DLL hijack on a VPN client — real but requires prior endpoint access
MEDIUM 5.9 = MEDIUM
2026-09-09
CVE-2026-33186
CWE-285
gRPC-Go is the Go language implementation of gRPC.
Trivial auth bypass but only fires on a narrow authz pattern most gRPC-Go deployments dont use
CRITICAL 9.1 ↓ HIGH
EPSS 0.02
2026-09-09
CVE-2026-0310
CWE-787
PAN-OS XML Processing Buffer Overflow Leading to Root RCE (PA-Series) or DoS (VM-Series)
Unauthenticated root RCE on perimeter firewalls via dataplane XML parsing — patch now.
HIGH 9.2 ↑ CRITICAL
2026-09-09
CVE-2026-85103
CWE-122
A heap-based buffer overflow in VPN certificate ASN.1 decoding may
Unauthenticated RCE on your perimeter firewall via a crafted certificate. This is as bad as it sounds.
CRITICAL 9.8 = CRITICAL
2026-09-09
CVE-2026-85083
CWE-798
CareCam Pro ANJIA AJL33PC0801 Hard-Coded Bootloader Credential
Physical-access-only bootloader flaw on a consumer IP camera is background noise for enterprise teams.
? = LOW
2026-09-09
CVE-2026-69906
CWE-122
Heap-based buffer overflow in Windows Secure Kernel Mode
VBS escape needs SYSTEM first, but breaks Credential Guard on your most critical hosts.
HIGH 8.2 = HIGH
2026-09-09
CVE-2026-67401
CWE-89
cPanel EmailTrack SQL Injection to Root Code Execution
Shared-hosting tenant to root: one SQL injection in cPanel EmailTrack owns every site on the box
? = HIGH
2026-09-09
CVE-2026-69730
CWE-416
Use after free in Windows DNS
Wormable, unauth RCE on DNS servers that usually ARE your domain controllers. Patch now.
CRITICAL 9.8 = CRITICAL
2026-09-09
CVE-2026-69676
CWE-294
Authentication bypass by capture-replay in Windows Kerberos
Any domain user can own your DCs with one crafted Kerberos request. Patch now.
HIGH 8.8 ↑ CRITICAL