Latest Cybersecurity Vulnerabilities - Real-Time Updates
Stay ahead of cybersecurity threats with real-time updates on the latest vulnerabilities.
This page lists the 30 most recently disclosed Common Vulnerabilities and Exposures (CVEs),
including risk scores, affected vendors, and mitigation insights.
Keeping track of emerging threats helps security professionals protect their systems.
Latest 30 CVEs - Real-Time Cyber Threats
Cyber threats are constantly evolving, making real-time vulnerability tracking essential.
Below are the 30 most recently disclosed Common Vulnerabilities and Exposures (CVEs),
providing key details such as affected vendors, impact levels, and risk scores.
Each CVE entry includes a brief summary and a direct link to its full details,
enabling cybersecurity professionals, system administrators, and developers to quickly assess
and mitigate potential security risks.
-
CVE-2026-96274 Exploitable Vulnerability Warning
In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the eNodeB and core network re-establish connectivity.
Score: 7.4/10
🔥 Very High Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
-
CVE-2026-94953 Technical Report
A stack-based buffer overflow vulnerability exists in the web management interface of TOTOLINK N150RT (NTR150) firmware V3.4.0-B20201030. It is reachable through the route /boafrm/formAjaxSet using the topicurl=setting/setWiFiRepeaterConfig branch and the ApCliWEPKey field.
⏳ Analysis in Progress
29 Sep 2026, 20:17 UTC (57 minutes ago)
-
CVE-2026-79538 Technical Report
metatool-ai MetaMCP up to and including 2.4.22 is vulnerable to Code Execution in the internal MCP inspector proxy endpoint GET /mcp-proxy/server/stdio (createTransport, STDIO branch, routers/mcp-proxy/server.ts).
⏳ Analysis in Progress
29 Sep 2026, 20:17 UTC (57 minutes ago)
-
CVE-2026-79537 Technical Report
metatool-ai MetaMCP through 2.4.22 contains an insecure direct object reference (IDOR) in the MCP transport session dispatch. The session store (getSession in session-lifetime-manager.ts) is keyed only by the client-supplied mcp-session-id header with no owner, namespace, or endpoint binding, and the per-endpoint authorization middleware validates only the URL endpoint's owner, never the session. An attacker who supplies another tenant's session id " obtained without authentication from GET /metamcp/health/sessions, which discloses active session IDs and namespace UUIDs " can list and execu...
⏳ Analysis in Progress
29 Sep 2026, 20:17 UTC (57 minutes ago)
-
CVE-2026-79536 Vulnerability Insight
bytebase dbhub v1.2.0 was discovered to contain a SQL injection vulnerability in the /utils/sql-parser.ts component. This vulnerability allows attackers to access sensitive databse information via a crafted SQL statement.
⏳ Analysis in Progress
29 Sep 2026, 20:17 UTC (57 minutes ago)
-
CVE-2026-79535 Security Notice
mbailey VoiceMode <= 8.10.1 is vulnerable to OS Command Injection. The update_config MCP tool (and the "voicemode config set" CLI) writes a caller-supplied value into ~/.voicemode/voicemode.env without shell-safe escaping.
⏳ Analysis in Progress
29 Sep 2026, 20:17 UTC (57 minutes ago)
-
CVE-2026-79534 Technical Report
mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved path, so write_file (and modify_file, copy_file, move_file, create_directory) follows a pre-existing dangling symlink located inside an allowed directory and creates a file outside the configured allowed directories.
⏳ Analysis in Progress
29 Sep 2026, 20:17 UTC (57 minutes ago)
-
CVE-2026-79417 Technical Report
Improper Access Control in ArgusMonitor.sys in Argotronic eGbR ArgusMonitor 7.4.02 and earlier allows local, low-privileged users to bypass device handle access restrictions via a TOCTOU condition in IRP_MJ_CREATE and send a crafted IOCTL 0x9C4024A8 request, causing denial-of-service.
⏳ Analysis in Progress
29 Sep 2026, 20:17 UTC (57 minutes ago)
-
CVE-2026-79403 Technical Report
An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint
⏳ Analysis in Progress
29 Sep 2026, 20:17 UTC (57 minutes ago)
-
CVE-2026-79348 Security Flaw Alert
KitchenAsty through 0.3.0 contains a broken object level authorization (IDOR) vulnerability in the reservations API. The endpoint GET /api/reservations/:id in packages/server applies the authenticate middleware but performs no ownership or role check, and the getReservation handler in packages/server/src/controllers/reservation.controller.ts returns the record retrieved by the client-supplied identifier without comparing reservation.customerId to the authenticated principal
Score: 4.3/10
⚠️ Medium Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
-
CVE-2026-76738 Report & Risk Review
A buffer overflow vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which recovers without manual intervention.
Score: 2.7/10
🟢 Low Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
-
CVE-2026-76737 Security Risk Analysis
An authenticated path traversal vulnerability exists in the command line interface of HPE Networking Instant On. Successful exploitation could allow an attacker with administrative access to modify a limited set of files on the underlying operating system and to interrupt the normal operation of the affected service.
Score: 3.0/10
🟢 Low Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
-
CVE-2026-76736 Vulnerability Report
A buffer overflow vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow a low-privilege authenticated local attacker to interrupt the normal operation of the affected service.
Score: 3.3/10
⚠️ Moderate Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
-
CVE-2026-76735 Risk & Patch Advisory
A sensitive information disclosure vulnerability exists in the underlying operating system of HPE Networking Instant On. Successful exploitation could allow an authenticated local attacker with high privileges to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking Instant On, only if certain preconditions outside of the attacker's control are met.
Score: 4.1/10
⚠️ Medium Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
-
CVE-2026-76734 Cybersecurity Threat Advisory
A memory corruption vulnerability in the affected interface of HPE Networking Instant On could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service and to access some limited information within the affected component.
Score: 4.8/10
⚠️ Medium Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
-
CVE-2026-76733 Security Flaw Alert
A denial-of-service vulnerability exists in the API endpoint of HPE Networking Instant On that could allow an authenticated attacker with administrative privileges to cause a denial of service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service, which resumes without manual intervention.
Score: 4.9/10
⚠️ Medium Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
-
CVE-2026-76732 Critical Risk Assessment
A local privilege-escalation vulnerability has been discovered in the affected daemon of HPE Networking Instant ON. Successful exploitation of this vulnerability could allow a local attacker to achieve arbitrary code execution with root privileges if certain preconditions are met outside of the attacker's control.
Score: 6.4/10
🔥 High Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
-
CVE-2026-76731 Active Exploit Warning
An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain limited access to some data and to make limited changes within the affected component.
Score: 6.5/10
🔥 High Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
-
CVE-2026-76730 Active Exploit Warning
An authentication bypass vulnerability exists in the PAPI protocol of HPE Networking Instant ON APs that could allow an unauthenticated adjacent attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to circumvent certain existing authentication mechanisms and send unauthorized network traffic to the target device.
Score: 6.5/10
🔥 High Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
-
CVE-2026-76729 Active Exploit Warning
A format string vulnerability in the API endpoint of HPE Networking Instant ON APs could allow an authenticated remote attacker with high privileges to cause memory corruption with a modified input. Successful exploitation could allow an attacker to provoke a denial-of-service condition or remote code execution in the affected system function.
Score: 6.6/10
🔥 High Risk
Published on 29 Sep 2026, 20:17 UTC (only 57 minutes ago)
What are CVEs?
A Common Vulnerability and Exposure (CVE) is a publicly disclosed cybersecurity flaw
that can be exploited by attackers to compromise software, systems, or networks.
The CVE system is maintained by The CVE Program
and provides a unique identifier for each vulnerability.
CVEs are assigned a severity score using the Common Vulnerability Scoring System (CVSS),
which helps security teams prioritize their response to threats.
Why Tracking CVEs is Important?
Keeping track of the latest CVEs is crucial for organizations and IT security professionals.
Cybercriminals frequently exploit unpatched vulnerabilities to launch ransomware attacks, data breaches, and system takeovers.
By staying updated with the latest threats, companies can apply security patches,
adjust firewall rules, and implement security policies to minimize risks.