Skip to content
Noroxi

National notices

National security notices (Türkiye)

The Cybersecurity Directorate (formerly USOM) publishes security notices daily; CVE ids appear inside the text. Here each notice is linked to the records in our database: which is in KEV, which has a mature exploit, what to look at first.

Source: the public notice API of siberguvenlik.gov.tr; the notice text and remediation advice live on the agency's page. Mapping is automatic by CVE id; notices without an id are listed by title only.

8,051 notices · 44,675 linked CVE recordsLatest notice: Oct 2, 2026 RSSList only records cited in national notices

  1. TR-26-1245 · Oct 2, 2026

    (Loglama.net​ - TurkHotspot Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-5782No exploit5.2 · 0%Reflected XSS in Loglama.NET's TurkHotspot
  2. TR-26-1244 · Oct 2, 2026

    (GG Soft Yazılım - Paperwork Güvenlik Bildirimi)

    Open the notice on the agency's page
  3. TR-26-1243 · Oct 2, 2026

    (Softtr Bilişim - E-Ticaret Paketi Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-11795No exploit5.3 · 0%User Enumeration in Softtr's E-Commerce Pack
  4. TR-26-1242 · Oct 2, 2026

    (AVEZ Elektronik - LMS Güvenlik Bildirimi)

    Open the notice on the agency's page
  5. TR-26-1241 · Oct 2, 2026

    (HAVELSAN - Sef - AI Chatbot Platform Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-80298No exploit8.8 · 0%SQL Injection in HAVELSAN's Sef - AI Chatbot Platform
    • CVE-2026-80337No exploit5.3 · 0%Unauthorized Cross-Chatbot Tool Invocation in HAVELSAN's Sef - AI Chatbot Platform
    • CVE-2026-80443No exploit7.4 · 0%Insecure TLS Certificate Validation in API Tool Runner in HAVELSAN's Sef - AI Chatbot Platform
    • CVE-2026-80464No exploit4.9 · 0%API Tool Runner SSRF in HAVELSAN's Sef - AI Chatbot Platform
  6. TR-26-1240 · Oct 2, 2026

    (Wind River VxWorks 7 Güvenlik Bildirimi)

    Open the notice on the agency's page
  7. TR-26-1239 · Oct 2, 2026

    (JohnsonControls Çoklu Ürün Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-27873No exploit5.6 · 0%- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying.
    • CVE-2026-34493No exploit7.2 · 0%- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations.
    • CVE-2026-34494No exploit7.2 · 0%- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations.
    • CVE-2026-64892No exploit6.3 · 0%- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations.
    • CVE-2026-64893No exploit7.3 · 0%- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack.
    • CVE-2026-71448No exploit5.6 · 0%: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse.
    • CVE-2026-71449No exploit9.3 · 0%: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data.
  8. TR-26-1238 · Oct 2, 2026

    (WordPress Eklenti Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-10026No exploit7.2 · 0%CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution
    • CVE-2026-101888No exploit8.6 · 1%Prime Mover < 2.2.1 Zip Slip Path Traversal File Write
    • CVE-2026-101889No exploit7 · 0%Prime Mover < 2.2.1 Path Traversal via wprime-config.json
    • CVE-2026-101890No exploit5.1 · 0%Prime Mover < 2.2.1 Stored XSS via Package Metadata
    • CVE-2026-14378Proof of concept9.8 · 0%DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow
    • CVE-2026-15896No exploit9.1 · 1%Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter
    • CVE-2026-15897No exploit8.8 · 0%Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login
    • CVE-2026-15989Proof of concept9.8 · 0%Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter
    • CVE-2026-19660Proof of concept9.8 · 0%Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
    • CVE-2026-19807No exploit8.8 · 0%ByteCoreStack <= 1.2.3 - Authenticated (Subscriber+) Privilege Escalation via wp_update_user_meta MCP Tool
    • CVE-2026-19902No exploit6.1 · 0%Ad Inserter <= 2.8.18 - Reflected Cross-Site Scripting via {search-query} Dynamic Tag (Referer Header)
    • CVE-2026-62071No exploit9.3 · 0%WordPress WordPress File Upload plugin <= 5.1.10 - SQL Injection vulnerability
    • CVE-2026-75957No exploit9.8 · 1%Ultimate Multisite <= 2.15.0 - Unauthenticated Authentication Bypass via 'checkout_form' Parameter
    • CVE-2026-78471No exploit5.4 · 0%Autoptimize <= 3.1.15.1 - Unauthenticated Stored Cross-Site Scripting via Comment Author Name
    • CVE-2026-84925No exploit6.1 · 0%Avada | Website Builder For WordPress & WooCommerce <= 7.16.1 - Reflected Cross-Site Scripting via 'lang' Parameter
    • CVE-2026-89047No exploit6.1 · 0%Social Media Share Buttons & Social Sharing Icons <= 3.0.1 - Reflected DOM-Based Cross-Site Scripting via URL
    • CVE-2026-90438No exploit7.2 · 0%Ninja Forms <= 3.15.4 - Unauthenticated Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission
    • CVE-2026-92144No exploit7.2 · 1%Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter
    • CVE-2026-92174No exploit7.5 · 1%SiteOrigin Widgets Bundle <= 1.73.2 - Authenticated (Contributor+) Local File Inclusion via 'theme' Parameter
    • CVE-2026-92820No exploit8.1 · 1%Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload
    • CVE-2026-93367No exploit7.2 · 0%Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)
    • CVE-2026-93882No exploit7.5 · 0%LearnPress <= 4.4.8 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'item_id' Parameter
    • CVE-2026-96256No exploit6.4 · 0%Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'marker' Attribute
  9. TR-26-1237 · Oct 2, 2026

    (Apache HTTP Server Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-63686No exploit7.5 · 0%Apache HTTP Server: mod_xml2enc crash on charset conversion failure
    • CVE-2026-63718No exploit7.5 · 0%Apache HTTP Server: mod_proxy_uwsgi Transfer-Encoding response smuggling
    • CVE-2026-73636No exploit8.1 · 0%Apache HTTP Server: mod_auth_digest one-time-nonce replay attack
    • CVE-2026-73637No exploit7.3 · 0%Apache HTTP Server: mod_auth_digest DoS attack
    • CVE-2026-79768No exploit5.3 · 0%Apache HTTP Server: mod_userdir information disclosure
    • CVE-2026-93546No exploit8.8 · 0%Apache HTTP Server: mod_dav_fs namespace overflow
  10. TR-26-1236 · Oct 2, 2026

    (Red Hat Keycloak Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-103884No exploit6.5 · 0%Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read
  11. TR-26-1235 · Oct 2, 2026

    (cPanel WHM Mass Modify Accounts/Multilang adminbin Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-93029No exploit9 · 0%There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.
    • CVE-2026-93697No exploit9 · 0%There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
    • CVE-2026-93698No exploit9.9 · 0%Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.
  12. TR-26-1234 · Oct 2, 2026

    (Ghost Platformu Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-103266No exploit7.1 · 0%Ghost 5.2.0 before 6.62.0 Unauthenticated Stripe Checkout Account Modification
    • CVE-2026-103267No exploit5.3 · 0%Ghost 0.5.0 before 6.62.0 Arbitrary Email Registration via Staff Invite
    • CVE-2026-103268No exploit8.7 · 0%Ghost 1.0.0 before 6.62.0 Suspension Bypass via Password Reset
    • CVE-2026-103269No exploit6.9 · 0%Ghost 5.3.0 before 6.62.0 Missing Authorization via Post Excerpts
    • CVE-2026-103271No exploit8.7 · 0%Ghost 4.0.0 before 6.63.0 Restricted Content Bypass
    • CVE-2026-103272No exploit8.7 · 0%Ghost 2.10.0 before 6.63.0 Staff Enumeration via Content API
    • CVE-2026-103273No exploit5.3 · 0%Ghost 4.3.0 before 6.58.0 Incorrect Authorization via Staff Token
    • CVE-2026-103274No exploit6.9 · 0%Ghost 5.3.0 before 6.58.0 Unauthenticated Comment Read
    • CVE-2026-103275No exploit5.3 · 0%Ghost 5.42.2 before 6.58.0 Password Hash Disclosure
    • CVE-2026-103276No exploit6.9 · 0%Ghost before 6.20.0 File Read via URL Encoding Bypass
    • CVE-2026-103277No exploit8.6 · 0%Ghost 2.5.0 before 6.34.0 Untrusted Script Execution via oEmbed
    • CVE-2026-103278No exploit8.5 · 0%Ghost 5.8.0 before 6.34.0 Staff Account Takeover via Admin iframe
    • CVE-2026-103279No exploit7.6 · 0%Ghost 3.10.0 before 6.34.0 Session Invalidation Bypass
    • CVE-2026-103280No exploit6.9 · 0%Ghost 0.8.0 before 6.23.0 Information Disclosure via Setup Endpoint
    • CVE-2026-103281No exploit5.3 · 0%Ghost 3.23.0 before 6.23.0 API Key Exposure via Admin API
    • CVE-2026-103282No exploit5.3 · 0%Ghost 0.5.0 before 6.23.0 Multiple Account Creation via Invite Token
    • CVE-2026-103283No exploit8.6 · 0%Ghost 6.20.0 before 6.57.1 Authentication Bypass via Session Handling
    • CVE-2026-103284No exploit5.3 · 0%Ghost 5.125.1 before 6.57.1 Information Disclosure via Feedback
    • CVE-2026-103285No exploit5.3 · 0%Ghost 5.19.0 before 6.57.1 Cross-Site Request Forgery
    • CVE-2026-103286No exploit8.5 · 0%Ghost 2.21.0 before 6.56.0 Privilege Escalation via Notifications
    • CVE-2026-103287No exploit5.1 · 0%Ghost 1.18.0 before 6.27.0 Server-Side Request Forgery via Webhook
    • CVE-2026-103288No exploit7.1 · 0%Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like
    • CVE-2026-103289No exploit7.1 · 0%Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comments
    • CVE-2026-103290No exploit5.1 · 0%Ghost 6.14.0 before 6.27.0 Path Traversal via ImageSize
    • CVE-2026-103291No exploit5.3 · 0%Ghost 3.20.2 before 6.51.0 SSRF via image-size fetch
    • CVE-2026-103292No exploit8.6 · 0%Ghost 0.5.3 before 6.50.0 Cross-Site Scripting via ghost_head
    • CVE-2026-70590No exploit4.8 · 0%Ghost: Blind Password Hash Disclosure in Ghost Admin API
  13. TR-26-1233 · Oct 1, 2026

    (Anthropic Claude Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-103012No exploit2 · 0%Claude Code selected an API key stored by Claude Code, for example from an earlier `/login` or written directly to its configuration, ahead
  14. TR-26-1232 · Oct 1, 2026

    (ASUS Çoklu Ürün Güvenlik Bildirimi )

    Open the notice on the agency's page
    • CVE-2026-13313No exploit8.9 · 1%An Active Debug Code vulnerability in certain ASUS router models allows a remote authenticated user, via a crafted HTTP request, to bypass s
    • CVE-2026-14157No exploit9.4 · 1%Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via
    • CVE-2026-93495No exploit7 · 0%Improper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a
  15. TR-26-1231 · Oct 1, 2026

    (Cato Networks SDP Client Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-10726No exploit6.8 · 0%Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation
    • CVE-2026-10739No exploit8.5 · 0%Cato Networks SDP Client for Windows is vulnerable to Local Privilege Escalation
  16. TR-26-1230 · Oct 1, 2026

    (Deno Runtime Güvenlik Zafiyeti)

    Open the notice on the agency's page
    • CVE-2026-103473No exploit9.2 · 1%Deno 2.7.0 through 2.9.7 Command Injection via node:child_process
  17. TR-26-1229 · Oct 1, 2026

    (MISP Güvenlik Zafiyeti)

    Open the notice on the agency's page
    • CVE-2026-103239No exploit8.6 · 0%MISP Tag Collection Save Allows Privilege Escalation via Sibling Model Injection
    • CVE-2026-103321No exploit8.3 · 0%MISP Stored Cross-Site Scripting (XSS) via Unvalidated Event Graph Preview Image
    • CVE-2026-103388No exploit6.2 · 0%MISP Stored Cross-Site Scripting via JavaScript URL in Galaxy Cluster Source Field
    • CVE-2026-103389No exploit6.2 · 0%MISP Stored Cross-Site Scripting via Unvalidated Galaxy Icon Field in Correlation Graph
  18. TR-26-1228 · Oct 1, 2026

    (OpenClaw Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-101879No exploit7.1 · 0%OpenClaw Windows Node before 2026.7.1-3 Missing Authorization
    • CVE-2026-101880No exploit8.7 · 1%OpenClaw Windows Node before 2026.7.1 Authorization Bypass
    • CVE-2026-101881No exploit7.1 · 0%OpenClaw Windows Node before 2026.7.1 Denial of Service
    • CVE-2026-101882No exploit8.7 · 1%OpenClaw Windows Node before 2026.7.1 Remote Code Execution via system.execApprovals.set
    • CVE-2026-101883No exploit5.3 · 0%OpenClaw Windows Node through 2026.9.4 SSRF via canvas.present
    • CVE-2026-101884No exploit7.7 · 0%OpenClaw Windows Node before 2026.7.1 Remote Code Execution via Environment Override
  19. TR-26-1227 · Oct 1, 2026

    (Kiteworks Çoklu Bileşen Güvenlik Zafiyeti)

    Open the notice on the agency's page
    • CVE-2026-102103No exploit9.1 · 0%Kiteworks Email Protection Gateway server-side request forgery
    • CVE-2026-102104No exploit9.1 · 0%Kiteworks Email Protection Gateway server-side request forgery
    • CVE-2026-102105No exploit9.1 · 0%Kiteworks Email Protection Gateway server-side request forgery
    • CVE-2026-102106No exploit9.1 · 0%Kiteworks Email Protection Gateway improper authentication
    • CVE-2026-102107No exploit4.6 · 0%Kiteworks Core user impersonation in a file-request feature
    • CVE-2026-102108No exploit7.2 · 0%Kiteworks Email Protection Gateway deserialization of untrusted data
    • CVE-2026-102109No exploit7.1 · 0%Kiteworks Secure Data Forms SQL injection
    • CVE-2026-102111No exploit4.9 · 0%Kiteworks Core Improper Validation of Specified Quantity in Input
    • CVE-2026-102112No exploit7.8 · 0%Kiteworks Core Local Privilege Escalation
    • CVE-2026-102113No exploit7.8 · 0%Kiteworks Core Local Privilege Escalation
    • CVE-2026-102114No exploit7.2 · 1%Kiteworks Core OS Command Injection
    • CVE-2026-102115No exploit9.8 · 0%Kiteworks Core Authentication Bypass in the Password Reset Workflow
    • CVE-2026-102116No exploit7.2 · 1%Kiteworks Email Protection Gateway Path Traversal
    • CVE-2026-102118No exploit7.8 · 0%Kiteworks Core before version 9.5.0 is vulnerable to Local Privilege Escalation
    • CVE-2026-102120No exploit8.8 · 0%Kiteworks Core OS Command Injection
    • CVE-2026-102122No exploit4.3 · 0%Kiteworks Core Incorrect Authorization
    • CVE-2026-102123No exploit7.4 · 0%Kiteworks Core Path Traversal
    • CVE-2026-102124No exploit6.5 · 0%Kiteworks Core Missing Authentication for Critical Function
    • CVE-2026-102125No exploit8.8 · 0%Kiteworks Core Sandbox Escape
    • CVE-2026-102126No exploit8.1 · 0%Kiteworks Core Stored Cross-site Scripting (XSS)
  20. TR-26-1226 · Oct 1, 2026

    (JetBrains Çoklu Ürün Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-100253No exploit8.8 · 0%In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings
    • CVE-2026-100254No exploit8.8 · 0%In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection
    • CVE-2026-100255No exploit9.8 · 0%In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset
    • CVE-2026-100256No exploit7.8 · 0%In JetBrains IntelliJ IDEA before 2026.2.3 rCE via Structural Search script constraints was possible in untrusted projects
    • CVE-2026-100257No exploit4.3 · 0%In JetBrains YouTrack before 2026.2.18991 sSRF via stored XHTML injection was possible during PDF export
    • CVE-2026-100258No exploit4.3 · 1%In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed read-only users to read project settings
    • CVE-2026-100259No exploit4.3 · 0%In JetBrains YouTrack before 2026.2.18991 improper access control on Gantt chart allowed edits by users with view-only access
    • CVE-2026-100260No exploit5.3 · 0%In JetBrains YouTrack before 2026.2.18991 mailbox integration allowed authentication after a password reset
    • CVE-2026-100261No exploit5.4 · 0%In JetBrains YouTrack before 2026.2.18991 changing article visibility settings was possible without update permission
    • CVE-2026-100262No exploit7.1 · 0%In JetBrains YouTrack before 2026.2.18991 missing authorisation allowed users with read-only project access to overwrite project notificatio
    • CVE-2026-100263No exploit6.1 · 0%In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
    • CVE-2026-100264No exploit2.7 · 0%In JetBrains YouTrack before 2026.2.18991 stored SMTP server credentials could be disclosed by changing the server host
    • CVE-2026-100265No exploit6.5 · 0%In JetBrains Rider before 2026.2.1 aI Assistant could auto-update third-party skills without user confirmation
    • CVE-2026-100266No exploit6.5 · 0%In JetBrains Hub before 2026.2.52366 missing authorisation allowed authenticated users to send arbitrary emails from the server's trusted ad
    • CVE-2026-100267No exploit5.9 · 0%In JetBrains YouTrack before 2026.2.19197 reDoS attack was possible via mailbox regex mail-rule filters
    • CVE-2026-100268No exploit2.7 · 0%In JetBrains YouTrack before 2026.2.19197 project administrators could read comments from other projects via notification templates
    • CVE-2026-100269No exploit4.3 · 0%In JetBrains YouTrack before 2026.2.19197 helpdesk project's Authorized Reporters list could be bypassed
    • CVE-2026-100270No exploit2.7 · 0%In JetBrains YouTrack before 2026.2.19197 low-level Admin Read permission users could disclose integration credentials via import configurat
    • CVE-2026-100271No exploit2.7 · 0%In JetBrains YouTrack before 2026.2.19197 missing authorisation on several endpoints allowed authenticated users to access information from
    • CVE-2026-100272No exploit4.9 · 0%In JetBrains YouTrack before 2026.2.19197 missing authorisation in the notification template preview allowed Project Administrators to read
    • CVE-2026-100273No exploit9.8 · 0%In JetBrains YouTrack before 2026.2.19197 authorisation bypass in the scripts debugger allowed arbitrary code execution
    • CVE-2026-100274No exploit6.5 · 1%In JetBrains YouTrack before 2026.2.19197 project Admin could trigger DoS via a notification template
    • CVE-2026-100275No exploit4.8 · 0%In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
    • CVE-2026-100276No exploit7.5 · 0%In JetBrains YouTrack before 2026.2.19197 guest users could remove a workflow action's visibility restriction and run the action
    • CVE-2026-100277No exploit9.8 · 0%In JetBrains YouTrack before 2026.2.19197 account takeover was possible by replaying a notification signature
    • CVE-2026-100278No exploit4.9 · 0%In JetBrains YouTrack before 2026.2.19197 users with restricted permission could edit and hide other users' comments
    • CVE-2026-100279No exploit6.5 · 0%In JetBrains YouTrack before 2026.2.19197 changing an integration URL exposed its stored credentials
    • CVE-2026-100280No exploit4.3 · 0%In JetBrains YouTrack before 2026.2.19197 creating a project from an unreadable custom template was possible
  21. TR-26-1225 · Sep 30, 2026

    (Trex Dijital -Trex MES Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-18782Proof of concept9.8 · 0%SQL Injection in Trex Digital Manufacturing's Trex MES
    • CVE-2026-18783Proof of concept8.8 · 0%Missing Server-Side Authentication on REST API Endpoint in Trex Digital Manufacturing's Trex MES
  22. TR-26-1224 · Sep 30, 2026

    (Dolusoft Yazılım - SOPLOG Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-82307No exploit9.8 · 0%Multiple Vulnerabilities in Dolusoft Software's SOPLOG
  23. TR-26-1223 · Sep 30, 2026

    (Maksisoft Teknoloji - Maksisoft Gym Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-86778No exploit5.3 · 0%Username Enumeration in Maksisoft Technology's Maksisoft Gym
  24. TR-26-1222 · Sep 30, 2026

    (Hitachi Energy RTU500 Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-8065Proof of concept9.1 · 1%An authentication bypass vulnerability in the firmware update endpoint of Hitachi Energy RTU500 end-of-life versions allows an unauthenticat
    • CVE-2026-8066No exploit9.1 · 1%A directory traversal vulnerability in the file upload functionality of Hitachi Energy RTU500 end-of-life versions allows an unauthenticated
  25. TR-26-1221 · Sep 30, 2026

    (GitLab CE/EE Güvenlik Bildirimi )

    Open the notice on the agency's page
    • CVE-2026-10518No exploit4.3 · 0%Incorrect Authorization in GitLab
    • CVE-2026-4523No exploit3.7 · 0%Missing Authorization in GitLab
    • CVE-2026-84739No exploit8.7 · 0%Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
    • CVE-2026-8937No exploit4.3 · 0%Missing Authorization in GitLab
  26. TR-26-1220 · Sep 30, 2026

    (WordPress Eklenti Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-100143No exploit6.5 · 0%FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email
    • CVE-2026-75823No exploit7.4 · 0%WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption
    • CVE-2026-75824No exploit5.3 · 0%WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled
    • CVE-2026-75873No exploit9.8 · 1%Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload
    • CVE-2026-80333No exploit5.3 · 0%Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes
    • CVE-2026-82127No exploit3.5 · 0%Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields
    • CVE-2026-83560No exploit5.3 · 0%New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass
    • CVE-2026-85001No exploit6.8 · 0%EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribute
    • CVE-2026-85415No exploit6.8 · 0%Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL
    • CVE-2026-85573No exploit8.8 · 0%All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG Upload
    • CVE-2026-85576No exploit4.3 · 0%All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings Update
    • CVE-2026-86789No exploit5.3 · 0%Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Disclosure via cn-api/v1 REST Routes
    • CVE-2026-87777No exploit6.8 · 0%Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attribute
    • CVE-2026-88791No exploit3.4 · 0%Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules
    • CVE-2026-88797No exploit7.1 · 0%Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation
    • CVE-2026-89190No exploit4.3 · 0%Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax
    • CVE-2026-89193No exploit7.5 · 0%Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTML Parser
    • CVE-2026-89294No exploit7.5 · 1%Simply Schedule Appointments <= 1.6.12.27 - Authenticated (Subscriber+) Local File Inclusion via 'ssa_locale' Parameter
    • CVE-2026-90953No exploit4.3 · 0%Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics Disclosure via Discarded REST Permission Callbacks
    • CVE-2026-91051No exploit6.6 · 0%EWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_page_settings' Post Meta
    • CVE-2026-91072No exploit4.4 · 0%EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path in WebP Migration Handler
    • CVE-2026-91832No exploit7.1 · 0%WP Mobile Menu 2.7.4 - 2.8.8 - Stored XSS via CSRF
    • CVE-2026-92424No exploit6.8 · 0%Content Egg < 11.9.0 - Contributor+ Stored XSS via Import Queue
    • CVE-2026-92994No exploit8.8 · 0%Verge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage API
    • CVE-2026-93580No exploit5.3 · 0%InPost for WooCommerce 1.7.5 - 1.9.7 - Unauthenticated Order Status Forgery via Shipment Webhook
    • CVE-2026-94274No exploit5.3 · 0%YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API
    • CVE-2026-94297No exploit2.7 · 0%Media Library Organizer 2.0.4 - 2.1.3 - Contributor+ Arbitrary Taxonomy Term Creation
    • CVE-2026-96649No exploit7.2 · 0%Frontend Post Submission Manager Lite <= 1.3.4 - Unauthenticated Stored DOM-Based Cross-Site Scripting via post_content Parameter (data-label DOM Sink)
    • CVE-2026-96886No exploit5.3 · 0%Course Booking System < 7.0.9 - Unauthenticated Attendee PII Disclosure via CSV Export
    • CVE-2026-97316No exploit5.8 · 0%Broken Link Notifier 1.3.1 - 2.0.0 - Unauthenticated SSRF via Redirect Bypass
  27. TR-26-1219 · Sep 30, 2026

    (Dell Secure Connect Gateway (SCG) Policy Manager Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-73593No exploit3 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerability.
    • CVE-2026-73594No exploit6.4 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Val
    • CVE-2026-73595No exploit4.7 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without
    • CVE-2026-73596No exploit3.8 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure De
    • CVE-2026-73597No exploit6.5 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability.
    • CVE-2026-73598No exploit7.8 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Res
    • CVE-2026-73599No exploit5.4 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirec
    • CVE-2026-76114No exploit5.9 · 0%Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information v
  28. TR-26-1218 · Sep 30, 2026

    (OpenSSL Güvenlik Zafiyeti)

    Open the notice on the agency's page
    • CVE-2026-35189No exploit5.3 · 0%Excessive Memory Allocation in Relative CRLDP Processing
    • CVE-2026-35191No exploit3.7 · 0%QUIC Unvalidated Amplification Credit may be Over Accounted
    • CVE-2026-42772No exploit5.3 · 0%Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC
    • CVE-2026-54873No exploit7.5 · 0%QUIC STREAM Fragment Metadata DoS
    • CVE-2026-54875No exploit3.7 · 0%Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V
    • CVE-2026-72897No exploit7.5 · 0%Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake
    • CVE-2026-75804No exploit5.3 · 0%QUIC Connection-Level Flow Control is Not Enforced for Streams
    • CVE-2026-75805No exploit5.3 · 0%NULL Pointer Dereference in CMP Client Revocation Response Handling
    • CVE-2026-84783No exploit7.5 · 0%Use-After-Free in X.509 Extension Cache Under Concurrent Use
    • CVE-2026-84784No exploit7.5 · 0%QUIC: Unbounded RETIRE_CONNECTION_ID Backlog
  29. TR-26-1217 · Sep 30, 2026

    (Wikimedia Foundation MediaWiki Güvenlik Zafiyeti)

    Open the notice on the agency's page
    • CVE-2026-100240No exploit9.1 · 0%TemplateSandbox does not check read permissions for the page being previewed
    • CVE-2026-100241No exploit7.5 · 0%Private change tags exposed to anonymous users via revision-tags-change events
    • CVE-2026-103046No exploit6.1 · 0%WikifunctionsFragmentRenderer does unsafe string replacements on user-provided HTML
  30. TR-26-1216 · Sep 30, 2026

    (HPE Çoklu Ürün Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-76718No exploit8.2 · 0%HPE OneView - Cross-site scripting vulnerability
    • CVE-2026-76719No exploit8.2 · 0%HPE OneView - Cross-site scripting vulnerability
    • CVE-2026-76720No exploit4.3 · 0%HPE OneView - URL Redirect vulnerability
    • CVE-2026-76721No exploit9.8 · 1%Unauthenticated Buffer Overflow Vulnerability leads to Remote Code Execution in HPE Networking Instant ON APs
    • CVE-2026-76722No exploit9.8 · 1%Uncontrolled Format String Vulnerabilities lead to Remote Code Execution or Denial-of-Service in HPE Networking Instant ON APs
    • CVE-2026-76723No exploit9.6 · 0%Unauthenticated Adjacent Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking Instant ON APS
    • CVE-2026-76724No exploit9.6 · 1%Unauthenticated Adjacent Command Injection Vulnerability in HPE Networking Instant ON APs Command Line Interface (CLI) Accessed by the PAPI Protocol
    • CVE-2026-76725No exploit9.6 · 0%Authentication Bypass in a Management Protocol of HPE Networking Instant ON APs
    • CVE-2026-76726No exploit8.1 · 0%Authentication Bypass Leading to Unauthorized Network Access in HPE Networking Instant ON API Endpoint
    • CVE-2026-76727No exploit7.2 · 1%Authenticated Command Injection Vulnerabilities in HPE Networking Instant ON
    • CVE-2026-76728No exploit7.2 · 1%Authenticated Server-Side Request Forgery Leading to Remote Code Execution in HPE Networking Instant ON APs
    • CVE-2026-76729No exploit6.6 · 0%Authenticated Format String Vulnerability allows Memory Corruption in HPE Networking Instant ON API Endpoint
    • CVE-2026-76730No exploit6.5 · 0%Improper PAPI Packet handling leads to unauthorized access in HPE Networking Instant ON APs
    • CVE-2026-76731No exploit6.5 · 0%Authentication Bypass in the Captive Portal of HPE Networking Instant On
    • CVE-2026-76732No exploit6.4 · 0%Authenticated Local Privilege Escalation Vulnerability in a Daemon of HPE Networking Instant ON
    • CVE-2026-76733No exploit4.9 · 0%Authenticated Denial-of-Service Vulnerability in HPE Networking Instant On API Endpoint
    • CVE-2026-76734No exploit4.8 · 0%Unauthenticated Memory Corruption Vulnerability leads to Denial-of-Service in HPE Networking Instant On
    • CVE-2026-76735No exploit4.1 · 0%Authenticated Local Sensitive Information Disclosure in HPE Networking Instant On
    • CVE-2026-76736No exploit3.3 · 0%Authenticated Local Buffer Overflow Vulnerability leads to Denial-of-Service in HPE Networking Instant On
    • CVE-2026-76737No exploit3 · 0%Authenticated Local Path Traversal Vulnerability Leads to Denial-of-Service in HPE Networking Instant On
    • CVE-2026-76738No exploit2.7 · 0%Authenticated Buffer Overflow Vulnerability in the API Endpoint of HPE Networking Instant On Causes Denial-of-Service
  31. TR-26-1215 · Sep 30, 2026

    (Mozilla Firefox Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-100756No exploit8.1 · 0%Incorrect boundary conditions in the Audio/Video: Playback component
    • CVE-2026-100757No exploit8.8 · 0%Use-after-free in the Widget component
    • CVE-2026-100758No exploit9.6 · 0%Sandbox escape in the DOM: Navigation component
    • CVE-2026-100759No exploit8.1 · 0%Uninitialized memory in the Storage: Quota Manager component
    • CVE-2026-100760No exploit9.6 · 0%Sandbox escape in the Security: Process Sandboxing component
    • CVE-2026-100761No exploit8.8 · 0%Privilege escalation due to use-after-free in the Graphics: WebGPU component
    • CVE-2026-100762No exploit9.6 · 0%Sandbox escape due to use-after-free in the DOM: Content Processes component
    • CVE-2026-100763No exploit9.1 · 0%Incorrect boundary conditions in the Graphics: WebGPU component
    • CVE-2026-100764No exploit8.8 · 0%Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component
    • CVE-2026-100765No exploit8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
    • CVE-2026-100766No exploit4.3 · 0%Information disclosure in the Networking: JAR component
    • CVE-2026-100767No exploit8.8 · 0%Use-after-free in the Networking: Cache component
    • CVE-2026-100768No exploit8.8 · 0%Use-after-free in the Graphics: WebGPU component
    • CVE-2026-100769No exploit8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
    • CVE-2026-100770No exploit9.6 · 0%Sandbox escape due to use-after-free in the DOM: Content Processes component
    • CVE-2026-100771No exploit8.1 · 0%Undefined behavior in the DOM: Streams component
    • CVE-2026-100772No exploit8.8 · 0%Use-after-free in the DOM: Core & HTML component
    • CVE-2026-100773No exploit8.8 · 0%Use-after-free in the Storage: IndexedDB component
    • CVE-2026-100774No exploit8.8 · 0%Use-after-free in the DOM: Core & HTML component
    • CVE-2026-100775No exploit9.6 · 0%Sandbox escape in the Graphics component
    • CVE-2026-100776No exploit8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
    • CVE-2026-100777No exploit8.8 · 0%Use-after-free in the Graphics: Canvas2D component
    • CVE-2026-100778No exploit9.6 · 0%Sandbox escape due to use-after-free in the DOM: Core & HTML component
    • CVE-2026-100779No exploit8.8 · 0%Use-after-free in the XSLT component
    • CVE-2026-100780No exploit8.8 · 0%Use-after-free in the DOM: Core & HTML component
    • CVE-2026-100781No exploit9.6 · 0%Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
    • CVE-2026-100782No exploit8.8 · 0%Privilege escalation due to incorrect boundary conditions in the Graphics component
    • CVE-2026-100783No exploit4.3 · 0%Uninitialized memory in the Audio/Video component
    • CVE-2026-100784No exploit8.8 · 0%Use-after-free in the Layout: Text and Fonts component
    • CVE-2026-100785No exploit8.8 · 0%Use-after-free in the DOM: Core & HTML component
    • CVE-2026-100786No exploit9.6 · 0%Sandbox escape due to use-after-free in the Graphics component
    • CVE-2026-100787No exploit9.6 · 0%Sandbox escape in the XUL component
    • CVE-2026-100788No exploit9.8 · 0%Invalid pointer in the JavaScript: WebAssembly component
    • CVE-2026-100789No exploit8.8 · 0%Use-after-free in the Graphics: Canvas2D component
    • CVE-2026-100790No exploit8.8 · 0%Use-after-free in the XSLT component
    • CVE-2026-100791No exploit8.8 · 0%Use-after-free in the DOM: Core & HTML component
    • CVE-2026-100792No exploit7.1 · 0%JIT miscompilation in the JavaScript: WebAssembly component
    • CVE-2026-100793No exploit6.5 · 0%JIT miscompilation in the JavaScript Engine component
    • CVE-2026-100794No exploit9.6 · 0%Sandbox escape due to incorrect boundary conditions in the Internationalization component
    • CVE-2026-100795No exploit6.5 · 0%Denial-of-service in the Networking component
    • CVE-2026-100796No exploit8.8 · 0%Use-after-free in the JavaScript: WebAssembly component
    • CVE-2026-100797No exploit8.8 · 0%Privilege escalation due to use-after-free in the Graphics: WebRender component
    • CVE-2026-100798No exploit8.1 · 0%Cryptography misuse in Storage: Quota Manager component
    • CVE-2026-100799No exploit4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
    • CVE-2026-100800No exploit9.6 · 0%Sandbox escape due to use-after-free in the Disability Access APIs component
    • CVE-2026-100801No exploit8.8 · 0%Privilege escalation in the DLL Services component
    • CVE-2026-100802No exploit4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
    • CVE-2026-100803No exploit8.1 · 0%Same-origin policy bypass in the WebExtensions component
    • CVE-2026-100804No exploit9.6 · 0%Sandbox escape due to use-after-free in the Preferences: Backend component
    • CVE-2026-100805No exploit7.5 · 0%Race condition, use-after-free in the Audio/Video component
    • CVE-2026-100806No exploit4.3 · 0%Uninitialized memory in the Graphics: WebGPU component
    • CVE-2026-100807No exploit8.8 · 0%Privilege escalation in the DOM: Service Workers component
    • CVE-2026-100808No exploit8.8 · 0%Mitigation bypass in the DOM: Service Workers component
    • CVE-2026-100809No exploit8.1 · 0%Same-origin policy bypass in the DevTools component
    • CVE-2026-100810No exploit9.8 · 0%Other issue in the DevTools component
    • CVE-2026-100811No exploit9.6 · 0%Sandbox escape due to use-after-free in the DOM: Core & HTML component
    • CVE-2026-100812No exploit6.5 · 0%Denial-of-service in the Graphics component
    • CVE-2026-100813No exploit8.8 · 0%Invalid pointer in the JavaScript Engine: JIT component
    • CVE-2026-100814No exploit8.8 · 0%Incorrect boundary conditions in the JavaScript Engine: JIT component
    • CVE-2026-100815No exploit8.8 · 0%Use-after-free in the CSS Parsing and Computation component
    • CVE-2026-100816No exploit8.1 · 0%Site isolation issue in the DOM: Networking component
    • CVE-2026-100817No exploit5.4 · 0%Other issue in the JavaScript: WebAssembly component
    • CVE-2026-100818No exploit9.6 · 0%Sandbox escape due to use-after-free in the Widget: Gtk component
    • CVE-2026-100819No exploit9.6 · 0%Sandbox escape due to incorrect boundary conditions in the XPCOM component
    • CVE-2026-100820No exploit8.8 · 0%Privilege escalation in the Address Bar component
    • CVE-2026-100821No exploit4.7 · 0%Site isolation issue in the Panning and Zooming component
    • CVE-2026-100822No exploit5.4 · 0%Spoofing issue in the Networking: HTTP component
    • CVE-2026-100823No exploit5.4 · 0%Spoofing issue in the Downloads component in Firefox for Android
    • CVE-2026-100824No exploit8.8 · 0%Privilege escalation in the Places component
    • CVE-2026-100825No exploit8.8 · 0%Use-after-free in the JavaScript Engine: JIT component
    • CVE-2026-100826No exploit6.5 · 0%Denial-of-service in the Storage: StorageManager component
    • CVE-2026-100828No exploit9.6 · 0%Mitigation bypass in the Bookmarks & History component
    • CVE-2026-100829No exploit9.6 · 0%Mitigation bypass in the DOM: Security component
    • CVE-2026-100830No exploit8.1 · 0%Mitigation bypass in the DOM: Navigation component
    • CVE-2026-100831No exploit8.8 · 0%Use-after-free in the DOM: UI Events & Focus Handling component
    • CVE-2026-100832No exploit8.8 · 0%Use-after-free in the Graphics: Canvas2D component
    • CVE-2026-96869No exploit4.3 · 0%Information disclosure in the Networking component
  32. TR-26-1214 · Sep 30, 2026

    (Ghostscript Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-19547No exploit7 · 0%Local Privilege Escalation in Ghostscript for Windows
  33. TR-26-1213 · Sep 30, 2026

    (Pexip Infinity Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-103100No exploit7.5 · 0%Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to trig
    • CVE-2026-103101No exploit8.6 · 0%Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to
    • CVE-2026-103102No exploit8.6 · 0%Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigge
    • CVE-2026-103104No exploit7.5 · 0%Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a re
  34. TR-26-1212 · Sep 30, 2026

    (WatchGuard Fireware OS Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-86134No exploit8.7 · 0%Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service
  35. TR-26-1211 · Sep 30, 2026

    (Google Chrome Güvenlik Bildirimi)

    Open the notice on the agency's page
    • CVE-2026-95274No exploit8.3 · 0%Improper output encoding in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proc
    • CVE-2026-95275No exploit6.5 · 0%Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy
    • CVE-2026-95276No exploit8.3 · 0%Improper input validation in Themes in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
    • CVE-2026-95277No exploit9.6 · 0%Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
    • CVE-2026-95278No exploit8.4 · 0%Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
    • CVE-2026-95279No exploit5.4 · 0%UI misrepresentation in Omnibox in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof address bar via a c
    • CVE-2026-95280No exploit7.5 · 0%Race condition in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
    • CVE-2026-95281No exploit9.6 · 1%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
    • CVE-2026-95282No exploit8.8 · 0%Use after free in Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
    • CVE-2026-95283No exploit9.6 · 1%Buffer overflow in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary cod
    • CVE-2026-95284No exploit9.6 · 1%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
    • CVE-2026-95285No exploit8.4 · 0%Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the ren
    • CVE-2026-95286No exploit8.8 · 0%Type confusion in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
    • CVE-2026-95287No exploit5.4 · 0%Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
    • CVE-2026-95288No exploit5.4 · 0%UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafte
    • CVE-2026-95289No exploit4.3 · 0%Incorrect authorization in Scroll in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain
    • CVE-2026-95290No exploit5.4 · 0%Missing authorization in NFC in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to b
    • CVE-2026-95291No exploit5.4 · 0%UI misrepresentation in SecurityIndicators in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof address bar
    • CVE-2026-95292No exploit4.8 · 0%Incorrect authorization in Safebrowsing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictio
    • CVE-2026-95293No exploit4.7 · 0%Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to read memory outside the sandbox via a cra
    • CVE-2026-95294No exploit5.4 · 0%UI misrepresentation in Browser in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI
    • CVE-2026-95295No exploit4.6 · 0%Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via phys
    • CVE-2026-95296No exploit4.3 · 0%Missing authorization in Core in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to o
    • CVE-2026-95297No exploit6.5 · 0%Missing authorization in Contextual Tasks in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via
    • CVE-2026-95298No exploit7.8 · 0%Use after free in Browser in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the
    • CVE-2026-95299No exploit9.6 · 0%Use after free in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a
    • CVE-2026-95300No exploit4.8 · 0%Missing authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass
    • CVE-2026-95301No exploit8.1 · 0%Missing authorization in Extensions in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
    • CVE-2026-95302No exploit2.9 · 0%Incorrect authorization in WebAPKs in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to obtain cross-origin dat
    • CVE-2026-95303No exploit6.5 · 0%Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass sy
    • CVE-2026-95304No exploit8.8 · 0%Out of bounds write in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via
    • CVE-2026-95305No exploit4.8 · 0%UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof
    • CVE-2026-95306No exploit8.8 · 0%Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a cr
    • CVE-2026-95307No exploit5.4 · 0%UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to sp
    • CVE-2026-95308No exploit3.4 · 0%Integer overflow in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to po
    • CVE-2026-95309No exploit5.4 · 0%UI misrepresentation in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafte
    • CVE-2026-95310No exploit9.6 · 0%Use after free in AdFilter in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox v
    • CVE-2026-95311No exploit9.6 · 0%Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentia
    • CVE-2026-95312No exploit3.1 · 0%Information leak in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
    • CVE-2026-95313No exploit9.6 · 0%Use after free in Fullscreen in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside
    • CVE-2026-95314No exploit8.1 · 0%Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
    • CVE-2026-95315No exploit7.8 · 0%Use after free in Aura in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially execute arbitrary code outside the sa
    • CVE-2026-95316No exploit2.9 · 0%Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a loca
    • CVE-2026-95317No exploit3.1 · 0%Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to o
    • CVE-2026-95318No exploit9.6 · 1%Buffer overflow in Video in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
    • CVE-2026-95319No exploit8.3 · 0%Use after free in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to pot
    • CVE-2026-95320No exploit5.4 · 0%Missing authorization in Navigation in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proce
    • CVE-2026-95321No exploit5.4 · 0%UI misrepresentation in Payments in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a
    • CVE-2026-95322No exploit8.3 · 0%Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer
    • CVE-2026-95323No exploit5.4 · 0%UI misrepresentation in Chromium in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering t
    • CVE-2026-95324No exploit3.4 · 0%Uninitialized resource in GPU in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to
    • CVE-2026-95325No exploit9.6 · 0%Use after free in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the
    • CVE-2026-95326No exploit8.4 · 0%Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass sy
    • CVE-2026-95327No exploit6.5 · 0%Information leak in Networking in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to leak sensitive information via a crafted
    • CVE-2026-95328No exploit6.5 · 0%Confused deputy in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker leveraging social engineering to ob
    • CVE-2026-95329No exploit9.6 · 0%Out of bounds write in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrar
    • CVE-2026-95330No exploit6.5 · 0%Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restriction
    • CVE-2026-95331No exploit9.6 · 0%Out of bounds write in ANGLE in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside
    • CVE-2026-95332No exploit4.7 · 0%Use of uninitialized variable in Tint in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to read memory outside
    • CVE-2026-95333No exploit8.1 · 0%Use after free in Metrics in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox vi
    • CVE-2026-95334No exploit8.3 · 0%Incorrect reference resolution in WebProtect in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the rende
    • CVE-2026-95335No exploit8.3 · 0%Use after free in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentia
    • CVE-2026-95336No exploit6.5 · 0%Information leak in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to
    • CVE-2026-95337No exploit5.4 · 0%UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineeri
    • CVE-2026-95338No exploit8.8 · 0%Use after free in PDFium in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via
    • CVE-2026-95339No exploit9.6 · 0%Use after free in ServiceWorker in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sand
    • CVE-2026-95340No exploit4.3 · 0%Incorrect authorization in PictureInPicture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering
    • CVE-2026-95341No exploit8.3 · 0%Improper input validation in Desktop in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer proc
    • CVE-2026-95342No exploit4.3 · 0%Missing authorization in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML
    • CVE-2026-95343No exploit8.8 · 1%Use after free in WebAudio in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
    • CVE-2026-95344No exploit8 · 0%Race condition in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass site is
    • CVE-2026-95345No exploit8.8 · 0%Use after free in Actor in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox via a
    • CVE-2026-95346No exploit4.8 · 0%UI misrepresentation in Chromoting in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via crafted networ
    • CVE-2026-95347No exploit9.6 · 0%Use after free in Updater in Google Chrome on on Mac prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the
    • CVE-2026-95348No exploit8.3 · 0%Use after free in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to po
    • CVE-2026-95349No exploit9.6 · 1%Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary co
    • CVE-2026-95350No exploit9.6 · 1%Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside t
    • CVE-2026-95351No exploit8.3 · 0%Use after free in Views in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to execut
    • CVE-2026-95352No exploit5.4 · 0%Incorrect authorization in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypas
    • CVE-2026-95353No exploit8.8 · 0%Use after free in Bindings in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code inside the sandbox vi
    • CVE-2026-95354No exploit8.3 · 0%Use after free in Verifier in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to pot
    • CVE-2026-95355No exploit8.3 · 0%Incorrect authorization in Navigation in Google Chrome on on iOS prior to 154.0.8037.57 allowed a remote attacker who had compromised the re
    • CVE-2026-95356No exploit9.6 · 0%Use after free in WindowDialog in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentiall
    • CVE-2026-95357No exploit9.6 · 0%Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary
    • CVE-2026-95358No exploit4.4 · 0%Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access res
    • CVE-2026-95359No exploit3.4 · 0%Uninitialized resource in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the render
    • CVE-2026-95360No exploit5.3 · 0%Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitiv
    • CVE-2026-95361No exploit4.3 · 0%Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web or
    • CVE-2026-95362No exploit8.8 · 0%Cross-site request forgery in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to by
    • CVE-2026-95363No exploit5.4 · 0%UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof
    • CVE-2026-95364No exploit5.4 · 0%Improper input validation in Passwords in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to spoof UI elements via a crafted
    • CVE-2026-95365No exploit8.8 · 0%Type confusion in IndexedDB in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code inside t
    • CVE-2026-95366No exploit6.5 · 0%Use of released resource in Core in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
    • CVE-2026-95367No exploit5.3 · 0%Information leak in DataTransfer in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process
    • CVE-2026-95368not in the database yet
    • CVE-2026-95369not in the database yet
    • CVE-2026-95370not in the database yet
    • CVE-2026-95371not in the database yet
    • CVE-2026-95372not in the database yet
    • CVE-2026-95373not in the database yet
    • CVE-2026-95374not in the database yet
    • CVE-2026-95375not in the database yet
    • CVE-2026-95376not in the database yet
    • CVE-2026-95380not in the database yet
    • CVE-2026-95381not in the database yet
    • CVE-2026-95382not in the database yet
    • CVE-2026-95384not in the database yet
    • CVE-2026-95385not in the database yet
  36. TR-26-1210 · Sep 29, 2026

    (Parla Auto - DetaWix Mobile Web Portal Güvenlik Bildirimi)

    Open the notice on the agency's page
  37. TR-26-1209 · Sep 29, 2026

    (Interprobe - Qorela DC Güvenlik Bildirimi)

    Open the notice on the agency's page
  38. TR-26-1208 · Sep 29, 2026

    (Kubernetes kubectl Güvenlik Zafiyeti)

    Open the notice on the agency's page
  39. TR-26-1207 · Sep 29, 2026

    (LiteLLM Güvenlik Zafiyeti)

    Open the notice on the agency's page
  40. TR-26-1206 · Sep 29, 2026

    (Canonical LXD Güvenlik Bildirimi)

    Open the notice on the agency's page

Add your products on the dashboard to be notified when a matching record enters KEV. →