CVE-2026-86106
- EPSS 0.38%
- Veröffentlicht 16.09.2026 10:12:55
- Zuletzt bearbeitet 16.09.2026 20:36:52
An unauthenticated actor with network access to the private HA interconnect may trigger sensitive HA peer functions without verification. This could result in elevated command execution on Edge units where HA is enabled.
CVE-2026-86109
- EPSS 0.24%
- Veröffentlicht 16.09.2026 02:57:46
- Zuletzt bearbeitet 17.09.2026 18:17:12
The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either sufficient privileg...
- EPSS 0.83%
- Veröffentlicht 16.09.2026 02:50:07
- Zuletzt bearbeitet 17.09.2026 18:17:12
Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Successful exploitat...
- EPSS 99.91%
- Veröffentlicht 22.04.2026 08:15:10
- Zuletzt bearbeitet 08.09.2026 15:13:07
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-pl...