Vulnerabilities (CVE)

Total 396413 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-78579 2026-09-10 N/A 6.8 MEDIUM
The Okta Access Gateway does not sanitize SAML assertion attribute values before interpolating them into LDAP search filters in the LDAP datastore configuration. The raw values are substituted directly into the filter string and passed to the LDAP search operation, resulting in modification of the intended query logic.
CVE-2026-78574 2026-09-10 N/A 7.5 HIGH
The Okta Hyperdrive Integration plugin resolves a required assembly using a registry path within the current user's hive without integrity verification. The referenced path is loaded via Assembly.LoadFrom without signature validation, resulting in an unverified assembly executing within the context of the host process or elevated installer.
CVE-2026-78560 2026-09-10 N/A 4.8 MEDIUM
The Okta Access Gateway includes an optional pass-through authentication source that accepts user identity from a client-supplied HTTP header without cryptographic validation. In architectures where this optional source is enabled without an upstream reverse proxy or firewall configured to sanitize and enforce client headers, an unauthenticated user can supply an arbitrary identity value to initiate a session.
CVE-2026-72986 2026-09-10 N/A 8.8 HIGH
Heap-based buffer overflow in Graphic Fonts allows an unauthorized attacker to execute code over a network.
CVE-2026-6485 2026-09-10 N/A 8.2 HIGH
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
CVE-2026-69470 2026-09-10 N/A 7.0 HIGH
Use after free in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
CVE-2026-69420 2026-09-10 N/A 7.8 HIGH
Heap-based buffer overflow in Windows VOLSNAP.SYS allows an authorized attacker to elevate privileges locally.
CVE-2026-69407 2026-09-10 N/A 7.8 HIGH
Integer overflow or wraparound in Volume Manager Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-69356 2026-09-10 N/A 9.3 CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-69322 2026-09-10 N/A 8.0 HIGH
Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
CVE-2026-69305 2026-09-10 N/A 7.1 HIGH
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
CVE-2026-69299 2026-09-10 N/A 7.0 HIGH
Use after free in Microsoft COM for Windows allows an authorized attacker to elevate privileges locally.
CVE-2026-69284 2026-09-10 N/A 7.8 HIGH
Heap-based buffer overflow in Windows DCOM Server allows an authorized attacker to elevate privileges locally.
CVE-2026-68892 2026-09-10 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Standard XPS allows an authorized attacker to elevate privileges locally.
CVE-2026-45531 2026-09-10 N/A 7.8 HIGH
In read_boot_region of fsck.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-45528 2026-09-10 N/A 7.3 HIGH
In getManageSpaceActivityIntent of StorageManagerService.java, there is a possible LaunchAnyWhere chain due to an unsafe PendingIntent. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.
CVE-2026-45520 2026-09-10 N/A 7.8 HIGH
In onAttach of BiometricsSettingsBase.java, there is a possible authentication bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-45515 2026-09-10 N/A 7.8 HIGH
In a2dp_vendor_opus_decoder_decode_packet of a2dp_vendor_opus_decoder.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28668 2026-09-10 N/A 7.8 HIGH
In LimitRealloc of malloc_limit.cpp, there is a possible use after free due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-28666 2026-09-10 N/A 8.8 HIGH
In multiple functions of LocalImageResolver.java, there is a possible Remote Persistent Denial of Service due to a DNG image rendering check bypass. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.