CVE ID :CVE-2026-76969 Published : Sept. 8, 2026, 12:12 a.m. | 42 minutes ago Description :@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility…
CVE-2026-76958 – XML External Entity (XXE) Vulnerability in SAP Integration Suite
CVE ID :CVE-2026-76958 Published : Sept. 8, 2026, 12:11 a.m. | 44 minutes ago Description :SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An…
CVE-2026-66768 – Improper Access Control in SAP NetWeaver (SAP GUI for Java)
CVE ID :CVE-2026-66768 Published : Sept. 8, 2026, 12:11 a.m. | 44 minutes ago Description :SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a…
CVE-2026-58240 – Missing Authentication check in SAP NetWeaver (Message Server)
CVE ID :CVE-2026-58240 Published : Sept. 8, 2026, 12:10 a.m. | 44 minutes ago Description :SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An…
CVE-2026-44756 – Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing
CVE ID :CVE-2026-44756 Published : Sept. 8, 2026, 12:10 a.m. | 45 minutes ago Description :A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated…
CVE-2026-82751 – Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning
CVE ID :CVE-2026-82751 Published : Sept. 6, 2026, 5:17 p.m. | 7 hours, 34 minutes ago Description :Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate…
CVE-2026-82750 – Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation
CVE ID :CVE-2026-82750 Published : Sept. 6, 2026, 5:17 p.m. | 7 hours, 34 minutes ago Description :Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate…
CVE-2026-19633 – PostgreSQL Anonymizer: unprivileged masked users can execute code via operators, domain casts and view subqueries
CVE ID :CVE-2026-19633 Published : Sept. 6, 2026, 4:16 p.m. | 8 hours, 35 minutes ago Description :PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators,…
CVE-2026-86259 – OpenMAIC before 1.0.1 SSRF via Environment-Gated URL Validation
CVE ID :CVE-2026-86259 Published : Sept. 6, 2026, 1:17 p.m. | 11 hours, 35 minutes ago Description :OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud…
CVE-2026-86258 – nbviewer through 1.0.1 Path Traversal via LocalFileHandler
CVE ID :CVE-2026-86258 Published : Sept. 6, 2026, 1:17 p.m. | 11 hours, 35 minutes ago Description :nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper…