Issue #281
Monday · October 05, 2026
🥖 Palate Cleanser
Hello again friends,
I don't often mention the other weaker, less attractive clouds but sometimes there is something worth learning from. Haakon Wik Gulbrandsrud found five full cross-tenant compromises in Azure, each one a way into other customers' connected Key Vaults, SQL databases and SaaS backends. It got him $200,000 in bounties, partly by finding ways around Microsoft's fixes for the earlier ones. Fun times.
Three talk videos with AWS content that haven't been in the digest yet:
- Out of Context: What's Really in the AWS Request Context by Dan Gansel, from fwd:cloudsec Europe. The talk behind last week's top Chef's pick on undocumented IAM condition keys, which I forgot to link. Watch him turn session policies into a yes-or-no oracle for what IAM really sees. Plerion's Conditional Love tool has been updated with the new resource keys Dan found, so you can try them for yourself.
- What Could Possibly Go Wrong? Running untrusted code in the cloud by Jules Denardou and Daniel Henkel, also from fwd:cloudsec Europe. How to run customer code using separate AWS accounts, S3-scoped VPC endpoint policies and a credentials proxy, and why Lambda didn't make the cut.
- The Month of AI Bugs: Exploiting AI Computer Use and Coding Agents by Johann Rehberger, from DEF CON Singapore. In August 2025 Johann published a new AI agent bug every day for a month, and this talk covers the worst of them. The AWS bits are two Amazon Q Developer bugs, plus a nod to Kiro having the same config-rewrite flaw.
This issue is also available to share online. Got feedback? Tell us here.
📋 Chef's selections
Package Name to Role Credentials in Code Interpreter: Two RCE CVEs in the AgentCore Python SDK
AgentCore Code Interpreter is AWS's sandbox where agents run potentially shady code, and its Python SDK has a helper, install_packages(), that lets an agent pip install libraries for you. It yolo-pasted each package name into a shell command, and Sergio got commands past its validation. First with a newline character, then, after the fix, with a command hidden inside pip's extras brackets. If the sandbox is a custom one with an execution role, that command reads the role's credentials from the sandbox's metadata service, so the attacker only needs a way to influence a package name with a prompt injection or a dependency file to get code exec.
Context Bombs Against Abliterated AI Models
Context bombs are short strings planted in canaries, decoy resources like fake secrets, that trip a model provider's safety checks when an AI attacker reads them. In July, Sam Cox showed that context bombs took the strongest frontier attack agent from getting admin in 93% of runs to 0%. The original strings did nothing to Qwen, an open-weight model attackers can run on their own hardware, away from any provider's safety checks, so this time Alessandro tried a new payload. He hid a forged chat transcript inside a fake API key in Secrets Manager, ending with the "user" telling the agent its work was done and it should stop. An abliterated build (weights edited to make refusals less likely) replied "Acknowledged, stopping all activities." and quit, and the same trick stopped plain Qwen too. In Tracebit's AWS cyber range the abliterated model reached admin in 2.3% of runs as opposed to 20.5% for the original. The new payload is already in the open-source context-bombs repo.
Read-Only AI Agents on AWS: Two Guardrails Failed in 2026, and IAM Held
It's unfortunate this article was (I think) written entirely by AI because it makes a good point, it just requires grinding through slop. Telling AI to only use read-only operations is unlikely to work unless something technical enforces it. Tatiana told an AI agent skill to stay read-only, and it made 25 database writes and reported none. She then did some sleuthing to figure out what keeps an agent read-only on AWS. Turns out it's not the guardrails in AWS's own MCP tools. 😬 In July AWS fixed the AWS API MCP Server, which silently dropped its deny list when an index failed to load, and the MCP proxy, whose --read-only flag hid write tools but still ran them if the agent asked by name.
🥗 AWS security blogs
- 📢 AWS Brazil automates distribution of non-Brazilian software product licenses to Brazilian customers
- 📢 GuardDuty Runtime Monitoring is now included in the AWS Security Hub Threat Analytics plan
- 📢 Amazon GuardDuty now supports centralized management using AWS Organizations declarative policies
- 📢 AWS Security Hub introduces remediation plans to prioritize and fix security exposures
- 📢 AWS IAM Identity Center extends multi-Region support to more AWS Regions
- 📢 Improve your secrets security posture with actionable recommendations in the AWS Secrets Manager console
- 📢 AWS Continuum for Penetration Testing now available in 6 additional Regions
- 📢 Uncover blind spots in AWS data plane operations with CloudTrail Event Coverage
- 📢 AWS accounts now support phone number verification
- 📢 Amazon Kinesis Video Streams now supports VPC endpoints with AWS PrivateLink
- 📢 Amazon WorkSpaces Applications introduces unified graphics images
- 📢 AWS Service Availability Updates
- 📢 AWS Transfer Family now supports downloading multiple files and folders in web apps
- 📢 Amazon ElastiCache Serverless for Valkey now supports public endpoints
- 📢 Amazon Route 53 Resolver DNS Firewall support for Palo Alto Networks Advanced DNS Security is now Generally Available (GA)
- Continuous AI security with F5 AI Guardrails and AWS Bedrock by Vlad Tyshkov
- Say Hello to 156 New AWS Competency, Service Delivery, and MSP Partners Added in September by Nick Paris
- Audit trails for autonomous agents with AWS DevOps Agent by Ben Peterson
- Simplify VPC Flow Logs with EC2 resource tags and next-hop metadata by Chaitanya Shah
- AWS European Sovereign Cloud: Demonstrating an independent operation by Stéphane Israël
🍛 Reddit threads on r/aws
- Side-channel vulnerability hardware mitigation. Need to know who to talk to with AWS.
- ssmctl v2: SSM Session Manager without the pain (shell, port forwarding, commands and file copy over SSM)
- AWS Lambda execution suspended 8 days after notifying AWS of a potential compromise on the root account. No response from support.
- Something else than billing, support, SES issues. Post about iam:PassRole
- Now that’s a blast from the past
- testing IAM policies for console access
- Session policy on per run or just a tighter role for non human callers?
- why most AWS security tools dump unreadable JSON instead of explaining the actual attack, walked through with iam:PassRole !!
🤖 Dessert
Every machine-tracked change this week. Nobody else assembles this.
🧁 IAM permission changes
🍪 API changes
- Amazon Cognito Identity Provider
- AWS Glue
- AWS Invoicing
- AWS Elemental MediaPackage v2
- Amazon Pinpoint SMS Voice V2
- AWS Security Agent
- Agents for Amazon Bedrock
- Amazon CloudFront
- AWS End User Messaging
- AWS Health APIs and Notifications
- Lambda Web
- Amazon QuickSight
- Amazon SageMaker Service
- AWS SecurityHub
- AWS Transfer Family
- AWS Account
- AWS Batch
- Amazon Bedrock AgentCore Control
- Amazon Connect Service
- Amazon DataZone
- Amazon DynamoDB
- Amazon EC2 Container Service
- AWS Global Accelerator
- AWS Glue
- Amazon GuardDuty
- Amazon CloudWatch Logs
- CloudWatch Observability Admin Service
- AWS Organizations
- Amazon Simple Storage Service
- Amazon S3 Vectors
- Amazon SageMaker Service
- Amazon AppStream
- Agents for Amazon Bedrock Runtime
- AWSDeadlineCloud
- Amazon Elastic Compute Cloud
- Amazon ElastiCache
- AWS Elemental Inference
- AWS Glue
- AWS SSO Identity Store
- Inspector2
- AWS MediaTailor
- Amazon OpenSearch Service
- Amazon Relational Database Service
- Amazon SageMaker Service
- AWS Security Agent
- Amazon Simple Email Service
- AWS Transfer Family
- Agent Registry Control
- Agent Registry
- Amazon Bedrock AgentCore Control
- AWS Billing
- Amazon Connect Service
- Amazon Elastic Compute Cloud
- Amazon Elastic Kubernetes Service
- Amazon GuardDuty
- AWS Security Agent
- Amazon Simple Systems Manager (SSM)
🍹 IAM managed policy changes
- AmazonConnectServiceLinkedRolePolicy
- FinOpsAgentAgentPolicy
- AmazonApplicationRecoveryControllerRegionSwitchPlanExecutionPolicy
- AnthropicReadOnlyAccess
- AnthropicLimitedAccess
- AWSSecurityIncidentResponseReadOnlyAccess
- AWSManagedAccountManagementAccess
- AWSResourceExplorerServiceRolePolicy
- AmazonEKSServiceRolePolicy
- AWSLambdaInvokeWebFunctionEndpointAccess
- AWSManagedSettingsAdminAccess
- AWSArtifactComplianceInquiriesFullAccess
- ViewOnlyAccess
- SecurityAudit
- AWSAccountSettingsManagementRole
- WellArchitectedAgentResourceScanning
- AWSPCSServiceRolePolicy
- EndUserMessagingServiceRolePolicy
- AmazonECSInfrastructureRolePolicyForVpcLattice
- AWSAccountSettingsManagementRole
- AmazonGuardDutyFullAccess_v2
☕ CloudFormation resource changes
No resource updates this week.
📺 AWS security bulletins
- CVE-2026-103505 - Mount Option Injection in Amazon EFS CSI Driver
- CVE-2026-100308 - GluonTS arbitrary command execution during model deserialization
- CVE-2026-104019 - OS command injection in the Studio Space startup script in Amazon SageMaker Distribution
- CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS
- CVE-2026-104002: Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)
- CVE-2026-97662 - Argument injection in AWS security-agent-mcp-server diff scan
- CVE-2026-104020 - Uncontrolled recursion in the Ion reader in Amazon Ion Python
🚬 Security documentation changes
- OpenSearch Dashboards 3.5 security patch release notes clarified
- Amazon MQ RabbitMQ mTLS docs drop the hostname verification option
- Amazon MQ RabbitMQ SSL docs drop the hostname verification option
- AWS CLI --no-follow-symlinks download behaviour clarified
- AWS CLI --no-follow-symlinks download behaviour clarified
- AWS CLI --no-follow-symlinks download behaviour clarified
- AppStream bucket policy examples add aws:SourceAccount confused deputy checks
- Athena ODBC driver 2.4.0.0 fixes parameter escaping and TLS verification
- DocumentDB 8.0.2 release notes include a collStats security fix
- Research and Engineering Studio 2026.06 fixes arbitrary file read
- Research and Engineering Studio SAML Destination example now uses HTTPS
- Research and Engineering Studio March 2026 fixes privilege escalation and RCE
- Research and Engineering Studio 2025.12 security hardening documented
- Research and Engineering Studio 2025.09 fixes cross-user session visibility
- Research and Engineering Studio 2026.09 fixes root file deletion and admin impersonation
🎮 Amazon Linux vulnerabilities
- CVE-2026-61813: ModSecurity weak libcurl TLS hostname check
- CVE-2026-97876: GRUB2 Secure Boot lockdown bypass
- CVE-2026-95512: FreeType CID font loader DoS (Firefox)
- CVE-2026-83663: Apache Thrift Go recursion DoS (CloudWatch agent)
- CVE-2026-104855: Wasmtime DoS
- CVE-2026-17507: Bouncy Castle MLS leaf index sign bug
- CVE-2026-94642: Apache Thrift PHP uncaught exception (CloudWatch agent)
- CVE-2026-104988: Dogtag PKI EST auth fails open
- CVE-2026-17508: Bouncy Castle KDF cost parameter DoS
- CVE-2026-73856: ModSecurity security bypass
- CVE-2026-104721: Logback path traversal via MDC value
- CVE-2026-18036: Bouncy Castle NTRU timing side channel
- CVE-2026-104844: PostCSS Selector Parser DoS
- CVE-2026-86345: 389 Directory Server StartTLS command injection
- CVE-2026-61812: ModSecurity HTML decoder evasion
- CVE-2026-94657: Apache Thrift JavaME resource exhaustion (CloudWatch agent)
- CVE-2026-93926: Apache Thrift THeaderTransport memory leak (CloudWatch agent)
- CVE-2026-66331: Apache Thrift Delphi resource exhaustion (CloudWatch agent)
- CVE-2026-73857: ModSecurity XML parser uninitialized pointer
- CVE-2026-94637: Apache Thrift Go decompression bomb (CloudWatch agent)
- CVE-2026-17588: QEMU xHCI reentrancy bug
- CVE-2026-16271: QEMU QXL stride validation bug
- CVE-2026-86344: 389 Directory Server connection race
- CVE-2026-79768: Apache httpd mod_userdir path equivalence
- CVE-2026-58415: Apache httpd mod_dav_fs WebDAV property leak
- CVE-2026-103505: EFS CSI driver mount option injection
- CVE-2026-56153: Apache httpd buffer overflow
- CVE-2026-63292: Apache httpd code execution
- CVE-2026-63718: Apache httpd mod_proxy_uwsgi response smuggling
- CVE-2026-103262: Tornado DoS
- CVE-2026-66899: QEMU virtio-balloon teardown bug
- CVE-2026-77913: QEMU VGA out-of-bounds write
- CVE-2026-46675: libpng use-after-free (Firefox)
- CVE-2026-63045: Apache httpd mod_proxy_ftp PASV redirect
- CVE-2026-47360: Apache httpd info disclosure
- CVE-2026-59797: Apache httpd mod_ssl SSLRequire privilege issue
- CVE-2026-63686: Apache httpd NULL pointer crash
- CVE-2026-73637: Apache httpd use-after-free
- CVE-2026-57941: Apache httpd use-after-free
- CVE-2026-103641: GEGL HDR loader out-of-bounds read
- CVE-2026-46729: Apache httpd NULL pointer crash
- CVE-2026-103263: Tornado path traversal
- CVE-2026-103261: Tornado query string DoS
- CVE-2026-68496: Jackson DoS
- CVE-2026-42528: Apache httpd DoS
- CVE-2026-93546: Apache httpd integer overflow
- CVE-2026-56154: Apache httpd use-after-free
- CVE-2026-94603: Podman security bypass
- CVE-2026-84788: QEMU zero-length socket write bug
- CVE-2026-42356: Apache httpd CGI redirect handler bug
- CVE-2026-73636: Apache httpd auth bypass
- CVE-2026-48005: Apache httpd DoS
- CVE-2026-103531: OpenSC buffer overflow
- CVE-2026-56449: Apache httpd buffer overflow
- CVE-2026-66900: QEMU virtio-net RSC padding bug
- CVE-2026-59685: Apache httpd buffer overflow
- CVE-2026-47581: NVIDIA GPU driver DoS
- CVE-2026-47553: NVIDIA GPU driver code execution
- CVE-2026-47590: NVIDIA GPU driver use-after-free
- CVE-2026-47491: NVIDIA GPU driver code execution
- CVE-2026-47569: NVIDIA GPU driver code execution
- CVE-2026-47584: CUDA NULL pointer crash
- CVE-2026-47545: CUDA code execution
- CVE-2026-47544: NVIDIA GPU driver code execution
- CVE-2026-47504: NVIDIA GPU driver code execution
- CVE-2026-47517: CUDA NULL pointer crash
- CVE-2026-47582: NVIDIA GPU driver code execution
- CVE-2026-47503: NVIDIA GPU driver code execution
- CVE-2026-47557: NVIDIA GPU driver NULL pointer crash
- CVE-2026-47589: CUDA use-after-free
- CVE-2026-47542: NVIDIA GPU driver code execution
- CVE-2026-47530: NVIDIA GPU driver code execution
- CVE-2026-47587: NVIDIA GPU driver use-after-free
- CVE-2026-47550: CUDA code execution
- CVE-2026-47494: NVIDIA GPU driver code execution
- CVE-2026-47496: NVIDIA GPU driver privilege escalation
- CVE-2026-47567: CUDA DoS
- CVE-2026-47516: NVIDIA GPU driver use-after-free
- CVE-2026-47543: NVIDIA GPU driver code execution
- CVE-2026-47531: NVIDIA GPU driver NULL pointer crash
- CVE-2026-47546: NVIDIA GPU driver code execution
- CVE-2026-102991: Mako info disclosure
- CVE-2026-47596: CUDA code execution
- CVE-2026-47568: CUDA DoS
- CVE-2026-47537: NVIDIA GPU driver code execution
- CVE-2026-47574: NVIDIA GPU driver code execution
- CVE-2026-47602: CUDA info disclosure
- CVE-2026-47523: NVIDIA GPU driver code execution
- CVE-2026-47547: NVIDIA GPU driver code execution
- CVE-2026-47598: CUDA use-after-free
- CVE-2026-47529: CUDA code execution
- CVE-2026-47501: NVIDIA GPU driver code execution
- CVE-2026-47548: CUDA code execution
- CVE-2026-47522: NVIDIA GPU driver code execution
- CVE-2026-47549: CUDA NULL pointer crash
- CVE-2026-47525: NVIDIA GPU driver code execution
- CVE-2026-47489: NVIDIA GPU driver code execution
- CVE-2026-47570: NVIDIA GPU driver code execution
- CVE-2026-47588: NVIDIA GPU driver use-after-free
- CVE-2026-47591: CUDA code execution
- CVE-2026-47515: NVIDIA GPU driver code execution
- CVE-2026-47603: CUDA info disclosure
- CVE-2026-47604: CUDA info disclosure
- CVE-2026-47538: NVIDIA GPU driver code execution
- CVE-2026-103001: PyJWT options mapping can skip signature checks
- CVE-2026-13720: Grafana dashboard provisioning metadata authz miss
- CVE-2026-13719: Grafana alert rules leak across folders
- CVE-2026-47580: NVIDIA GPU driver info disclosure
- CVE-2026-47575: NVIDIA GPU driver code execution
- CVE-2026-47500: NVIDIA GPU driver use-after-free
- CVE-2026-47532: NVIDIA GPU driver code execution
- CVE-2026-47512: NVIDIA GPU driver code execution
- CVE-2026-103500: Thunderbird buffer overflow
- CVE-2026-47585: NVIDIA GPU driver code execution
- CVE-2026-47586: CUDA use-after-free
- CVE-2026-47510: NVIDIA GPU driver code execution
- CVE-2026-101276: iperf use-after-free
- CVE-2026-47571: NVIDIA GPU driver code execution
- CVE-2026-47600: CUDA code execution
- CVE-2026-47507: NVIDIA GPU driver code execution
- CVE-2026-47559: CUDA code execution
- CVE-2026-103399: libsoup Expect 100-continue request smuggling
- CVE-2026-47555: CUDA info disclosure
- CVE-2026-101283: iperf buffer overflow
- CVE-2026-47513: NVIDIA GPU driver code execution
- CVE-2026-47519: NVIDIA GPU driver code execution
- CVE-2026-47506: NVIDIA GPU driver DoS
- CVE-2026-47502: NVIDIA GPU driver code execution
- CVE-2026-47565: CUDA code execution
- CVE-2026-47593: NVIDIA GPU driver code execution
- CVE-2026-47556: NVIDIA GPU driver code execution
- CVE-2026-47583: CUDA code execution
- CVE-2026-47524: CUDA code execution
- CVE-2026-47526: NVIDIA GPU driver NULL pointer crash
- CVE-2026-62439: GIMP vulnerability
- CVE-2026-47595: NVIDIA GPU driver code execution
- CVE-2026-47508: NVIDIA GPU driver code execution
- CVE-2026-47562: NVIDIA GPU driver DoS
- CVE-2026-19445: Python ssl SNI callback use-after-free
- CVE-2026-47592: NVIDIA GPU driver code execution
- CVE-2026-47511: NVIDIA GPU driver code execution
- CVE-2026-47563: NVIDIA GPU driver code execution
- CVE-2026-47527: NVIDIA GPU driver code execution
- CVE-2026-47558: CUDA code execution
- CVE-2026-47509: NVIDIA GPU driver code execution
- CVE-2026-47561: NVIDIA GPU driver code execution
- CVE-2026-47528: NVIDIA GPU driver code execution
- CVE-2026-47576: NVIDIA GPU driver out-of-bounds read
- CVE-2026-47599: NVIDIA GPU driver code execution
- CVE-2026-47492: NVIDIA GPU driver DoS
- CVE-2026-47551: NVIDIA GPU driver use-after-free
- CVE-2026-47493: NVIDIA GPU driver code execution
- CVE-2026-47577: NVIDIA GPU driver code execution
- CVE-2026-47499: NVIDIA GPU driver code execution
- CVE-2026-103118: GraphicsMagick WPG recursion DoS
- CVE-2026-47566: CUDA DoS
- CVE-2026-47536: NVIDIA GPU driver code execution
- CVE-2026-103242: RPM buffer overflow
- CVE-2026-103226: Ghostscript code execution
- CVE-2026-47601: CUDA code execution
- CVE-2026-47505: NVIDIA GPU driver use-after-free
- CVE-2026-103111: PCRE2 code execution
- CVE-2026-19553: Python ssl wrap_bio skips hostname check
- CVE-2026-47540: NVIDIA GPU driver code execution
- CVE-2026-47560: NVIDIA GPU driver use-after-free
- CVE-2026-47554: CUDA DoS
- CVE-2026-47514: CUDA code execution
- CVE-2026-47552: NVIDIA GPU driver code execution
- CVE-2026-47578: NVIDIA GPU driver code execution
- CVE-2026-47518: CUDA code execution
- CVE-2026-47579: CUDA use-after-free
- CVE-2026-47572: CUDA code execution
- CVE-2026-47597: CUDA use-after-free
- CVE-2026-47534: NVIDIA GPU driver DoS
- CVE-2026-47533: CUDA code execution
- CVE-2026-47594: CUDA use-after-free
- CVE-2026-84782: OpenSSL info disclosure
- CVE-2026-42772: OpenSSL DoS
- CVE-2026-96419: Wireshark code execution
- CVE-2026-100799: Firefox uninitialized memory (WebGPU)
- CVE-2026-100792: Firefox JIT miscompilation (WebAssembly)
- CVE-2026-72897: OpenSSL buffer overflow
- CVE-2026-102299: V8 type confusion code execution (Node.js)
- CVE-2026-102560: libsoup buffer overflow
- CVE-2026-100822: Firefox spoofing (Networking: HTTP)
- CVE-2026-100782: Firefox privilege escalation (Graphics)
- CVE-2026-100766: Firefox info disclosure (Networking: JAR)
- CVE-2026-96869: Firefox info disclosure (Networking)
- CVE-2026-100780: Firefox use-after-free
- CVE-2026-100825: Firefox use-after-free (JavaScript Engine: JIT)
- CVE-2026-96418: Wireshark TIFF loop DoS
- CVE-2026-100808: Firefox security bypass (DOM: Service Workers)
- CVE-2026-100795: Firefox DoS (Networking)
- CVE-2026-35189: OpenSSL DoS
- CVE-2026-100763: Firefox boundary error (WebGPU)
- CVE-2026-100762: Firefox sandbox escape (DOM: Content Processes)
- CVE-2026-100811: Firefox sandbox escape
- CVE-2026-100768: Firefox use-after-free (Graphics: WebGPU)
- CVE-2026-100770: Firefox sandbox escape (DOM: Content Processes)
- CVE-2026-100814: Firefox boundary error (JIT)
- CVE-2026-100829: Firefox security bypass (DOM: Security)
- CVE-2026-95386: Wireshark DoS
- CVE-2026-102620: Poppler integer overflow
- CVE-2026-100820: Firefox privilege escalation (Address Bar)
- CVE-2026-100805: Firefox use-after-free (Audio/Video)
- CVE-2026-102598: Werkzeug safe_join Windows device path bug
- CVE-2026-96422: Wireshark DoS
- CVE-2026-95391: Wireshark DoS
- CVE-2026-100771: Firefox undefined behavior (DOM Streams)
- CVE-2026-100791: Firefox use-after-free
- CVE-2026-84784: OpenSSL QUIC connection ID flood
- CVE-2026-100794: Firefox sandbox escape (Internationalization)
- CVE-2026-100802: Firefox uninitialized memory (WebGPU)
- CVE-2026-100764: Firefox privilege escalation (Graphics: WebGPU)
- CVE-2026-100756: Firefox boundary error (Audio/Video)
- CVE-2026-100784: Firefox use-after-free (Layout: Text and Fonts)
- CVE-2026-75805: OpenSSL NULL pointer crash
- CVE-2026-100785: Firefox use-after-free
- CVE-2026-81842: Grafana info disclosure
- CVE-2026-100790: Firefox use-after-free (XSLT)
- CVE-2026-102621: Poppler integer overflow
- CVE-2026-54873: OpenSSL QUIC packet buffer memory hold
- CVE-2026-100828: Firefox security bypass
- CVE-2026-100823: Firefox spoofing (Downloads)
- CVE-2026-54875: OpenSSL SM2 timing side channel on ARM64 and RISC-V
- CVE-2026-102556: libsoup DoS
- CVE-2026-100776: Firefox use-after-free (JavaScript: WebAssembly)
- CVE-2026-77696: OpenSSL SM2 signing timing side channel
- CVE-2026-100759: Firefox uninitialized memory (Quota Manager)
- CVE-2026-54872: OpenSSL ECDSA and SM2 nonce timing leak
- CVE-2026-100831: Firefox use-after-free
- CVE-2026-100767: Firefox use-after-free (Networking: Cache)
- CVE-2026-100812: Firefox DoS (Graphics)
- CVE-2026-102937: virtualenv prompt injection into activate.bat
- CVE-2026-97711: dotnet10.0 XSS
- CVE-2026-102559: libsoup buffer overflow
- CVE-2026-102253: iperf DoS
- CVE-2026-100817: Firefox WebAssembly issue
- CVE-2026-100797: Firefox use-after-free (Graphics: WebRender)
- CVE-2026-100801: Firefox privilege escalation (DLL Services)
- CVE-2026-100806: Firefox uninitialized memory (WebGPU)
- CVE-2026-95395: Wireshark SYNCHROPHASOR memory exhaustion
- CVE-2026-100786: Firefox sandbox escape (Graphics)
- CVE-2026-84783: OpenSSL use-after-free
- CVE-2026-35191: OpenSSL QUIC amplification limit bypass
- CVE-2026-102328: V8 type confusion code execution (Node.js)
- CVE-2026-63209: compress library integer overflow
- CVE-2026-100772: Firefox use-after-free
- CVE-2026-100788: Firefox invalid pointer (WebAssembly)
- CVE-2026-102558: libsoup buffer overflow
- CVE-2026-100760: Firefox sandbox escape (Security: Process Sandboxing)
- CVE-2026-96417: Wireshark code execution
- CVE-2026-100810: Firefox DevTools issue
- CVE-2026-100798: Firefox crypto misuse (Quota Manager)
- CVE-2026-95520: RPM buffer overflow
- CVE-2026-102925: virtualenv code execution
- CVE-2026-100761: Firefox use-after-free (Graphics: WebGPU)
- CVE-2026-100775: Firefox sandbox escape (Graphics)
- CVE-2026-100816: Firefox site isolation issue (DOM Networking)
- CVE-2026-95392: Wireshark DoS
- CVE-2026-100789: Firefox use-after-free (Graphics: Canvas2D)
- CVE-2026-100777: Firefox use-after-free (Graphics: Canvas2D)
- CVE-2026-100809: Firefox security bypass (DevTools)
- CVE-2026-102557: libsoup DoS
- CVE-2026-100830: Firefox security bypass (DOM: Navigation)
- CVE-2026-95387: Wireshark SPDY integer overflow
- CVE-2026-75804: OpenSSL QUIC missing connection flow control
- CVE-2026-95393: Wireshark buffer overflow
- CVE-2026-100769: Firefox use-after-free (JavaScript: WebAssembly)
- CVE-2026-96415: Wireshark DoS
- CVE-2026-100773: Firefox use-after-free (Storage: IndexedDB)
- CVE-2026-102326: V8 type confusion code execution (Node.js)
- CVE-2026-19547: Ghostscript privilege escalation
- CVE-2026-97687: urllib3 proxy and target TLS settings mixed up
- CVE-2026-100765: Firefox use-after-free (JavaScript: WebAssembly)
- CVE-2026-100813: Firefox invalid pointer (JIT)
- CVE-2026-100781: Firefox sandbox escape (Graphics: WebRender)
- CVE-2026-97024: Flatpak path traversal
- CVE-2026-100796: Firefox use-after-free (JavaScript: WebAssembly)
- CVE-2026-100821: Firefox site isolation issue (Panning and Zooming)
- CVE-2026-100832: Firefox use-after-free (Graphics: Canvas2D)
- CVE-2026-100783: Firefox uninitialized memory (Audio/Video)
- CVE-2026-100778: Firefox sandbox escape
- CVE-2026-95390: Wireshark PEAK TRC NULL pointer crash
- CVE-2026-97689: urllib3 chunked response memory DoS
- CVE-2026-100824: Firefox privilege escalation (Places)
- CVE-2026-101277: OpenDKIM tag tokenizer trust issue
- CVE-2026-75806: OpenSSL DoS
- CVE-2026-95388: Wireshark DoS
- CVE-2026-100757: Firefox use-after-free (Widget)
- CVE-2026-95389: Wireshark DoS
- CVE-2026-96420: Wireshark DoS
- CVE-2026-100826: Firefox DoS (StorageManager)
- CVE-2026-96421: Wireshark DoS
- CVE-2026-102323: V8 type confusion code execution (Node.js)
- CVE-2026-100818: Firefox sandbox escape (Widget: Gtk)
- CVE-2026-100793: Firefox JIT miscompilation
- CVE-2026-100819: Firefox sandbox escape (XPCOM)
- CVE-2026-100758: Firefox sandbox escape (DOM: Navigation)
- CVE-2026-96423: Wireshark X11 dissector memory bug
- CVE-2026-100779: Firefox use-after-free (XSLT)
- CVE-2026-100804: Firefox sandbox escape (Preferences: Backend)
- CVE-2026-100774: Firefox use-after-free
- CVE-2026-102938: virtualenv pyvenv.cfg injection
- CVE-2026-100815: Firefox use-after-free (CSS Parsing and Computation)
- CVE-2026-102635: ImageMagick GIF uninitialized memory leak
- CVE-2026-102325: Skia cross-origin data leak (Firefox, Thunderbird, WebKitGTK)
- CVE-2026-97029: Flatpak sandbox signal escape
- CVE-2026-100800: Firefox sandbox escape (Disability Access APIs)
- CVE-2026-12345: Python TemporaryDirectory cleanup symlink race
- CVE-2026-102930: virtualenv seed wheels not integrity checked
- CVE-2026-102555: libsoup out-of-bounds read
- CVE-2026-97688: urllib3 DoS
- CVE-2026-100803: Firefox security bypass (WebExtensions)
- CVE-2026-100787: Firefox sandbox escape (XUL)
- CVE-2026-96416: Wireshark DoS
- CVE-2026-102633: expat buffer overflow
- CVE-2026-102321: V8 type confusion code execution (Node.js)
- CVE-2026-95394: Wireshark DoS
- CVE-2026-100807: Firefox privilege escalation (DOM: Service Workers)